论文标题
永远不要相信您的受害者:在安全扫描仪中武器武器
Never Trust Your Victim: Weaponizing Vulnerabilities in Security Scanners
论文作者
论文摘要
每次攻击的第一步是侦察,即获取有关目标的信息。一个普遍的信念是,从远程位置扫描目标几乎没有风险。在本文中,我们通过表明扫描仪面临与目标相同的风险来伪造这种信念。我们的方法基于一种新颖的攻击者模型,扫描作者成为反击的受害者。我们开发了一个工作的原型,称为Revok,并将其应用于78个扫描系统。在其中,发现36个容易受到XS的攻击。值得注意的是,Revok还发现了一种主流穿透测试工具Metasploit Pro的严重脆弱性。
The first step of every attack is reconnaissance, i.e., to acquire information about the target. A common belief is that there is almost no risk in scanning a target from a remote location. In this paper we falsify this belief by showing that scanners are exposed to the same risks as their targets. Our methodology is based on a novel attacker model where the scan author becomes the victim of a counter-strike. We developed a working prototype, called RevOK, and we applied it to 78 scanning systems. Out of them, 36 were found vulnerable to XSS. Remarkably, RevOK also found a severe vulnerability in Metasploit Pro, a mainstream penetration testing tool.