Passwordless RDP Session Hijacking Feature All Windows versions

Um... so easy I did it in about 15 minutes in my lab setup at home. HOLY S****!

Attack Vector Details:

- A privileged user, which can gain command execution with NT AUTHORITY/SYSTEM rights can hijack any currently logged in user's session, without any knowledge about his credentials.

- Terminal Services session can be either in connected or disconnected state.

This is high risk vulnerability which allows any local admin to hijack a session and get access to:
1. Domain admin session.
2. Any unsaved documents, that hijacked user works on.
3. Any other systems/applications in which hijacked user previously logged in (May include another Remote Desktop sessions, Network Share mappings, applications which require another credentials, E-mail etc.)
feature 

This was a translated article so some of the wording is a bit off but most of it is more than readable. - Check out the article here.

Da Boss!

Website: www.digitalsmind.com Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Latest Content

  • Bad Rabbit: Ten things you need to know about the latest ransomware outbreak
    Written by

    Da Boss!

    Bad Rabbit: Ten things you need to know about the latest ransomware outbreak Eh... not as bad as some previous ones we have…
    Read more...
  • Taco Bell rolls out Kit Kat-stuffed quesadilla
    Written by

    Da Boss!

    Taco Bell rolls out Kit Kat-stuffed quesadilla In line now. Sounds scrumptious.
    Read more...
  • Snag-It 2018 - Best Screen Capture Tool - PERIOD!
    Written by

    Da Boss!

    Snag-It 2018 - Best Screen Capture Tool - PERIOD! Well, it's almost here but I was graced by the…
    Read more...
  • Windows 10 Fall Creators Update: Lots of small changes—and maybe the revolution
    Written by

    Da Boss!

    Windows 10 Fall Creators Update: Lots of small changes—and maybe the revolution Hopefully this one will go a little smoother than the…
    Read more...
  • VirtualBox 5.1.30
    Written by

    Da Boss!

    VirtualBox 5.1.30 If you are looking for a VM program\utility that can…
    Read more...

Visit the Digitalsmind Video YouTube Page!

Did you know we have a video page on YouTube? 

Well... WE DO! 

Check us out! 

- Our Video page.