Netsec dude who likes PY. Im probably making toast in your kitchen via the Internets. I have a thing for Anime. And the Power Glove. RT != Boom boom in yer room
Tinkered with the RDP bug (CVE-2019-0708) this past weekend and ended up with BSOD. With a good spray, RCE should be straightforward through this vtable call
Btw, I checked out modern RDP internals a few weeks ago. Microsoft is currently working hard on refactoring the entire Terminal Services infrastructure
I am following the RDP 0day saga. I saw lots of PR, teasing pics and videos that imply nothing with respect to knowledge, and a few low quality publications
Thus far this is the only analysis of CVE-2019-0708 that I can recommed to my followers: https://t.co/d54Doln9Mz #BlueKeep
@alisaesage This writeup is excellent. I am working on my exploit dev skills and this helps with understanding a complex flaw. Soon I hope to learn how to get RCE working for this (and not share it publicly for obvious reasons).
I am no expert for RDP and the MS implementation.
How can NIDS/NIPS vendors, whose tweets start popping up prevent an exploitation of CVE-2019-0708 #BlueKeep if the payload is protected by TLS?
So I've posted both Windows and macOS binaries (self-contained, statically linked) for scanning for CVE-2019-0708 bluekeep. Just click on the badge at the top of the readme.
https://t.co/aBA6PRkPD5
"The Hacker's Hardware Toolkit" has been updated twith 10 more gadgets. Get it paperback in Amazon worldwide:
https://t.co/BKk7ECrD7e
or just for free in PDF (more than 8K downloads):
https://t.co/mGwNs2Uf4i
Just waiting for including your new suggestions!