THREAT OPS › Threat News › Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 2
Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 2
<p class="wp-block-paragraph"><em><strong>TL;DR:</strong> When WSUS downloads files for updates, it requires the server to leverage the BITS protocol. WSUS normally requires executables to be digitally signed, however this can be bypassed by appending the <code>.esd</code> or <code>.txt</code> file extensions.</em></p>
<h2 class="wp-block-heading" id="h-introduction">Introduction</h2>
<p cla
Indicators of compromise
- https://www.lrqa.com/en/cyber-labs/introducing-sharpwsus/url
- https://www.lrqa.com/en/cyber-labs/introducing-sharpwsusurl
- s.w.orgdomain