SMB Attacks Through Directory Traversal
netspi.com | 博客 | #smb | #penetration-testing | #directory-traversal | #web-application-security | #hash-capture | #unc-paths
摘要
当 Web 应用存在目录遍历或文件名操控缺陷时,可通过注入 UNC 路径将其升级为 SMB 攻击——捕获身份验证哈希或访问内网文件共享,而不仅限于读取服务器本地敏感文件。
- 发布时间
- 收录时间
Skip to content