Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1
specterops.io | research | #supply-chain | #windows-security | #wsus | #lateral-movement | #ntlm-relay | #sql-server | #stored-procedures
Summary
Part 1 of SpecterOps' WSUS research: coercing a WSUS machine account into a relayed SQL session, then abusing stored procedures to forge malicious updates and target specific computers.
- Published
- Collected
Skip to content