Check Your Senses. Software Based Data Transfer In Captive Portals Over Light and Sound.

Presented at THOTCON 0x9 (2018), May 5, 2018, 2 p.m. (50 minutes)

As offensive Red Team operator have you ever found yourself in a locked down remote terminal session, staring at the data unable to exfiltrate it to the local system. Or maybe you were not able to transfer data into the remote host. It's frustrating, we know. But not all is lost. In this talk we will walk through a few scenarios and create tools to remedy the situation. Together we will look at exfiltration and infiltration opportunities over Light and Sound mediums. We will gradually build a collection of tools created with the goal of overcoming restrictions placed by enterprise captive portals in the form of screen remote sessions, terminal services and kiosks. We will do so following principles of utilization (aka living off the land), avoiding detection, maximizing operational security, all while pushing our bytes in and out of the enterprise. And while we love the hardware, we will do this all entirely in software. Along our journey together there will be failure, there will be success, but most of all - there will be fun. So, Blue Team - prepare to check your senses!


Presenters:

  • Dimitry Snezhkov / Op_Nomad as D.Snezhkov
    Dimitry Snezhkov, X-Force Red @IBM. Offensive security testing, code hacking and tool building.

Similar Presentations: