Do loop back in anger
2024-12-14 , Rookie track 2

The tale of stumbling across the registry key which reverts MS08-068, permitting SMB reflection attacks.


In this session, I'll walk through the lesser-known MS08-068 vulnerability and explore the potential for SMB reflection attacks in 2024, uncovering a root cause hidden in plain sight within Microsoft's documentation. The talk will include a demonstration of the attack, and you'll receive a script to set up your own lab environment for hands-on practice at home!


Please confirm that I am a first time speaker and have not spoken in public and will not be before the Bsides London event date (14th December 2024).:

Yes

Shane has been a penetration tester for just over ten years, working in a wide range of environments. In recent years, he has worked for an internal security team, building deeper knowledge of Active Directory and Windows Internals.