Sensepost released their JSP/PHP/ASP pivot/covert channel named reDuh :










Basic concept :
  • Glenn has the ability to upload / create a JSP page on the remote server
  • Glenn wishes to make an RDP connection to the server term-serv.victim.com (visible to the web-server behind the firewall)
  • The firewall permits HTTP traffic to the webserver but denies everything else
http://www.sensepost.com/research/reDuh/

0 comments

Post a Comment