Plug & Pwn:摸清 Windows PnP 自动安装的攻击面
netlas.io | 博客 | #attack-surface | #privilege-escalation | #windows | #rdp | #defcon | #netlas | #plug-and-play
摘要
Netlas 基于 DEF CON「Plug & Pwn」研究测绘 Windows PnP 自动安装攻击面:插入设备即触发系统以 SYSTEM 权限拉取并运行厂商安装包,远程变体仅需已认证的 RDP 会话;文章演示如何从外网定位暴露的 RDP 主机并给出防御建议。
- 发布时间
- 收录时间
Skip to content