THREAT OPS › Threat News › Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1
Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1
<p class="wp-block-paragraph"><em><strong>TL;DR:</strong> This is part 1 of a 2 part blog series sharing what I have discovered in my Windows Service Update Service (WSUS) research. If the WSUS database is configured on a separate server from the upstream WSUS server, we can coerce the WSUS computer account to the WSUS database and establish a SQL session. With this access, we can create custom ma
MITRE ATT&CK techniques
Indicators of compromise
- 0c740de1c2a98ce4cc1c4314fb608392b9f65f02sha1
- 0x0C740DE1C2A98CE4CC1C4314FB608392B9F65F02eth
- http://10.2.10.3:8530>url
- http://PetitPotam.pyurl
- https://blackhat.com/docs/us-17/wednesday/us-17-Coltel-WSUSpendu-Use-WSUS-To-Hang-Its-Clients-wp.pdfurl
- https://specter.local>&lt;/MoreInfoUrl&gt;&lt;SupportUrl&gt;<https://specter.local>&lt;/SupportUrl&gt;&lt;/LocalizedProperties&gturl
- http://198.51.100.1:8000/Specter.exe>url
- http://198.51.100.1:8443/Specter.exe>url
- 198.51.100.1ipv4
- s.w.orgdomain