<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" 
  xmlns:content="http://purl.org/rss/1.0/modules/content/" 
  xmlns:dc="http://purl.org/dc/elements/1.1/" 
  xmlns:atom="http://www.w3.org/2005/Atom" 
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
  xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>Post-exploitation on Untrusted Network</title>
    <link>https://untrustednetwork.net/en/tag/post-exploitation/</link>
    <description>Recent content in Post-exploitation on Untrusted Network</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>&amp;copy; Jan Kopriva 2015 - {year}</copyright>
    <lastBuildDate>Mon, 30 Mar 2020 07:55:00 +0100</lastBuildDate>
    <sy:updatePeriod>weekly</sy:updatePeriod>
    <sy:updateFrequency>weekly</sy:updateFrequency>
    
        <atom:link href="https://untrustednetwork.net/en/tag/post-exploitation/index.xml" rel="self" type="application/rss+xml" />
    
    
    

      
      <item>
        <title>SANS ISC Diary - Crashing explorer.exe with(out) a click</title>
        <link>https://untrustednetwork.net/en/2020/03/30/sans-isc-diary-crashing-explorer.exe-without-a-click/</link>
        <pubDate>Mon, 30 Mar 2020 07:55:00 +0100</pubDate>
        
        <atom:modified>Mon, 30 Mar 2020 07:55:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2020/03/30/sans-isc-diary-crashing-explorer.exe-without-a-click/</guid>
        <description>A Diary of mine was published today on the SANS Internet Storm Center. In this one, we take a look at a vulnerability in the way Windows handles self-referential links, which makes it possible to use specially crafted URL and LNK files to crash Explorer.</description>
        <content:encoded>&lt;p&gt;A &lt;a href=&#34;https://isc.sans.edu/forums/diary/Crashing+explorerexe+without+a+click/25966/&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt;. In this one, we take a look at a vulnerability in the way Windows handles self-referential links, which makes it possible to use specially crafted URL and LNK files to crash Explorer.&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>Windows</category>
            
          
            
              <category>Vulnerability</category>
            
          
            
              <category>Microsoft</category>
            
          
            
              <category>Post-exploitation</category>
            
          
            
              <category>Red teaming</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2020</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      
      <item>
        <title>SANS ISC Diary - Desktop.ini as a post-exploitation tool</title>
        <link>https://untrustednetwork.net/en/2020/03/16/sans-isc-diary-desktop.ini-as-a-post-exploitation-tool/</link>
        <pubDate>Mon, 16 Mar 2020 07:55:00 +0100</pubDate>
        
        <atom:modified>Mon, 16 Mar 2020 07:55:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2020/03/16/sans-isc-diary-desktop.ini-as-a-post-exploitation-tool/</guid>
        <description>A Diary of mine was published today on the SANS Internet Storm Center. In this one, we take a look at a vulnerability in the way Windows handles desktop.ini files, which makes it possible to use them as an interesting post-exploitation tool.
UPDATE 27. 5. 2020: I put together a shor video demonstrating the vulnerabiltiy while preparing materials for SANSFIRE 2020. You may find it here.</description>
        <content:encoded>&lt;p&gt;A &lt;a href=&#34;https://isc.sans.edu/forums/diary/Desktopini+as+a+postexploitation+tool/25912/&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt;. In this one, we take a look at a vulnerability in the way Windows handles desktop.ini files, which makes it possible to use them as an interesting post-exploitation tool.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;UPDATE 27. 5. 2020: I put together a shor video demonstrating the vulnerabiltiy while preparing materials for &lt;a href=&#34;https://www.sans.org/event/sansfire-2020/&#34;&gt;SANSFIRE 2020&lt;/a&gt;. You may find it &lt;a href=&#34;https://www.youtube.com/watch?v=pVqJiaUnstA&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>Windows</category>
            
          
            
              <category>Vulnerability</category>
            
          
            
              <category>Microsoft</category>
            
          
            
              <category>Post-exploitation</category>
            
          
            
              <category>Red teaming</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2020</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      

    
  </channel>
</rss>