Nullcon Berlin 2023 | (In)Secure Remote Operations: What Sucks, Rocks, And A Super-CLI by Yossi
About this talk
This talk explores the duality of administrative tools in cybersecurity, emphasizing that every admin tool can also serve as an attack tool. The speaker presents insights gained from consulting on role-based remote operations architectures and conducting Red Team assessments across four continents. They demonstrate both offensive and defensive techniques, highlighting effective and ineffective practices within Windows remote administration, including the evaluation of jump server architectures and methods to creatively limit PowerShell. Additionally, the session introduces new research on achieving full token hijacking from network logon-type sessions, advancing the understanding of security measures without the dependence on hashes or Ticket Granting Tickets.
More from this event
See all 17 talks →
Nullcon Berlin 2023 | Server Side Prototype Pollution: Blackbox Detection Without The DoS by Gareth
42:10
Nullcon Berlin 2023 | Why I Write My Own Security Tooling & Why You Should Too! by James Forshaw
41:49
Nullcon Berlin 2023 | SCCI: The Road To Side-Channel Regression Testing In CI Development by Witold
46:39
Nullcon Berlin 2023 | Panel: Securing the Road to Autonomy
36:23