3 ms·
I wonder if this will be abused by malware authors in some way.
by fariss 5y ago
I wonder if this will be abused by malware authors in some way.
- feldrim 5y agoNot "if", but "when".
- AnIdiotOnTheNet 5y agoEh, why bother? This is basically just a pure-PowerShell VNC-like as far as I can tell. If an attacker wants that a reverse VNC shellcode is readily available and small.
- feldrim 5y agoFirst of all, it's not a VNC protocol implementation but RDP. Second, it's PowerShell so it's easy to use as a payload in any exploitation tool, e.g. Metasploit, Cobalt Strike and such. If you have information about RDP, you have probably heard it's the first stop when you want to exploit any Windows device. If it doesn't work, you go for SMB, etc. So yes, it's valuable in that sense.
- AnIdiotOnTheNet 5y agoIt doesn't appear to be RDP. All this seems to be doing is taking screenshots of the Desktop, which is similar to how VNC works. RDP is a vastly more complicated protocol. Last I checked the reverse VNC shellcode was literally part of the Metasploit suite, so not really any easier there either.