Files
MBCProject-mbc-markdown/execution/exploit-software.md
T
Desiree Beck fb3468f1ed add method
2020-04-13 11:58:03 -04:00

1.6 KiB

ID E1203
Objective(s) Execution, Impact
Related ATT&CK Technique Exploitation for Client Execution

Exploitation for Client Execution

Software is exploited - either because of a vulnerability or through its designed features - to gain access for malware. In general, exploitation may be done by a human attacker, but MBC focuses on software exploits implemented in code. Malware-specific details are below.

See related ATT&CK Technique: Exploitation for Client Execution.

Methods

  • Stack Pivot: a stack pivot (i.e., stack manipulation) can be used to exploit software.
  • Remote Desktop Protocols (RDP):
  • Java-based Web Servers:
  • File Transfer Protocol (FTP) Servers:
  • Red Hat JBoss Enterprise Products:
  • Sysinternals: Use Sysinternals tools for additional command line functionality.

Malware Examples

Name Date Description
SamSam 2015 Attackers associated with SamSam exploit vulnerabilities in remote desktop protocols (RDP), Java-based web servers, or file transfer protocol (FTP) servers. [1]

References

[1] https://blog.malwarebytes.com/cybercrime/2018/05/samsam-ransomware-need-know/