Загрузка видео...
Не удалось загрузить видео
The MOVEit Transfer exploitation is not just SQL injection(👀) We uncovered the very last stage of the attack chain to drop human2.aspx ultimately ends up gaining remote code execution ‼ We fully recreated the attack chain with a demo achieving a reverse shell & ransomware!
236,636 просмотров • 3 лет назад •via X (Twitter)
Комментарии: 9

Check out all that we've been digging into:

Awesome work. If you can share, approximately how many research hours were required to recreate this? I think it's important for people to understand that an attack chain like this really requires a lot of time to understand even though a blog post/video seems "easy".

Very well-done folks!! 👌

John Hammond does it again.

The remote code execution is scary but why is SQL injection still a thing in 2023? We know how to prevent it and have done for years.

I think the targets got so wide they decided their focus on stealing data rather than ransom

Thanks for all the outstanding work!

Congratulations, excellent work! 👏👏👏👏 Thank you

So you are behind Cl0p then this whole time!!..

