DNS Remote Code Execution: Finding the Vulnerability 👾 (Part 1)
Learn tricks and techniques like these, with us, in our amazing training courses!
In 2019 and 2020, we DOMINATED the router Wide Area Network or WAN category in the Pwn2Own hacker competition. In this category, hackers attack network devices with previously unknown vulnerabilities, from external networks such as the Internet.
Unfortunately, by 2021 our competitors reversed engineered our techniques, and the game was up.
Today, we are starting a video series where we will show you our tips, tricks and techniques to find and exploit WAN vulnerabilities in network devices. And we’re starting with a beautiful DNS exploit that got us $20,000 in prizes.
Let’s get ready to PWN!
In this video, we will tell you the story of how we found CVE-2020-10881 in the Pwn2Own Tokyo 2019 hacking competition and present our Game Plan for exploiting it :-)
00:00 - Intro
00:50 - WAN vs LAN
03:12 - Target Introduction and Recon
05:23 - Finding an Open Port and Fuzzing It
07:48 - Quick Look in Ghidra for Crash Investigation
10:38 - What is conn-indicator Doing?
12:30 - DNS Protocol
17:50 - A Deeper Look in Ghidra
20:33 - DNS Packet Parsing and the Vulnerability
24:51 - Radek’s Evil Game Plan
28:03 - Our Training
Did you enjoy this video? Then follow us on Twitter, and subscribe to our channel for more awesome hacking videos.
~ Flashback Team
Background track: “Hackers“ by Karl Casey @WhiteBatAudio
1 view
2959
990
7 months ago 01:08:51 1
SERVER - CLIENT CONFIGURATION (WINDOWS SERVER 2008 R2 - WINDOWS 7) COMPLETE GUIDE
7 months ago 00:04:22 1
Best VPN For Netflix 🔥 Is Surfshark any good for Netflix?
7 months ago 00:09:04 1
Сервер RPC недоступен
8 months ago 00:39:50 1
Off The Record - Weaponizing DHCP DNS Dynamic Updates
9 months ago 00:05:57 1
ForkPlayer для SmartTV Samsung и LG -Новый и Самый легкий способ установки в 2021 году.Работает 100%
9 months ago 23:09:50 1
CompTIA Network+ Full Course FREE [23+ Hours] #comptia
9 months ago 00:09:35 2
Смена региона, Прошивка, Разблокировка Smart TV в Телевизорах Samsung
10 months ago 01:13:21 1
DNS.4 Кэширующий (локальный) DNS-сервер
11 months ago 00:17:27 1
Cisco - CCNA Certification 200-301 - OSI Model Part 2. 06
11 months ago 00:19:11 1
Cisco - CCNA Certification 200-301 - TCP Vs UDP .08
1 year ago 00:01:18 1
Reolink 4K 8CH Human/Car Detecion NVR for 4MP/5MP IP Security Camera 24/7 Video Recorder 12MP
1 year ago 00:05:14 1
How to install Google Chrome on TCL Android TV
1 year ago 00:33:01 1
Deep News October 2023 Jaimi Harrison and the DNC
1 year ago 00:29:31 1
DNS Remote Code Execution: Finding the Vulnerability 👾 (Part 1)
1 year ago 00:07:18 1
Как подключить пульт к телевизору LG. Не работает пульт Magic Remote LG.
2 years ago 00:42:02 1
Gerald Doussot - State of DNS Rebinding Attacks & Singularity of Origin - DEF CON 27 Conference
2 years ago 00:06:59 1
14 Эксполоиты в Metasploit track1 h264 muxed
2 years ago 00:07:35 1
Samsung Smart TV Tips & Tricks -Smart DNS Proxy
2 years ago 00:53:17 3
Linux Essentials for DevOps | ifconfig, ping, netstat, traceroute Commands | Shell Script Tutorial
2 years ago 00:04:30 1
Как очистить память в SmartTV? Что делать если завис SmartTV? Не работает приложение в SmartTV?
2 years ago 00:00:30 12
Introducing the Backbone One – PlayStation® Edition
4 years ago 00:03:29 9
MATE Russia-Far East ROV Competition 2019
4 years ago 00:00:39 23
ИИ Татьяна пытается объяснить как закрыть уязвимость CVE-2020-1350 Windows DNS Server Remote...
4 years ago 00:00:33 17
SIGRed: Windows DNS Server Remote Code Execution | Check Point Research