All Roads Lead to OpenVPN Pwning Industrial Remote Access Clients - Sharon Brizinov - Hack in Paris - 2021
Hack in Paris via YouTube
Overview
Syllabus
Intro
Agenda
Work From Home: The Industrial Version
Programmable Logic Controller
Remote Access Solution
Under the Hood: OpenVPN
OpenVPN Traffic
So What's the Problem?
Example to a Very Loose Backend Parser
But What About SOP and CORS?
Recap
OK. We Can Start VPN Tunnel, SO WHAT?
But the Config File Must Be Present on the Machine!
PerFact OpenVPN - Backend
Perfact OpenVPN - Architecture
Prepare Our Exploit - Step 1
HMS Networks
SEH 101
mbDIALUP launcher
Taught by
Hack in Paris