Domain Borrowing - Catch My C2 Traffic if You Can

Domain Borrowing - Catch My C2 Traffic if You Can

Black Hat via YouTube Direct link

Abusing CDN domain validation

8 of 18

8 of 18

Abusing CDN domain validation

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Domain Borrowing - Catch My C2 Traffic if You Can

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Outline
  3. 3 Domain Fronting - Limitations
  4. 4 Domain Hiding - Limitations
  5. 5 What we want for an ideal C2
  6. 6 The HTTPS CDN workflow
  7. 7 Domian Borrowing Basics - Abandon DNS
  8. 8 Abusing CDN domain validation
  9. 9 When CDN can't find the certificate
  10. 10 Borrow arbitrary domain
  11. 11 Obtain valid HTTPS certificates
  12. 12 CDN domain validation bypass
  13. 13 CDN HTTPS certificates distribution
  14. 14 Borrow valid HTTPS certificates
  15. 15 Domain Borrowing vs. Others
  16. 16 Detection
  17. 17 Mitigation
  18. 18 Bypass Palo Alto Firewall

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.