RE: https://infosec.exchange/@flomb/116018887867921743
Highly recommend the writeup from our @flomb and congrats on this well-deserved achievement!
| https://twitter.com/codewhitesec | |
| Github | https://github.com/codewhitesec |
| https://www.linkedin.com/company/code-white-gmbh | |
| www | https://code-white.com/ |
RE: https://infosec.exchange/@flomb/116018887867921743
Highly recommend the writeup from our @flomb and congrats on this well-deserved achievement!
RE: https://infosec.exchange/@flomb/116018887867921743
Highly recommend the writeup from our @flomb and congrats on this well-deserved achievement!

NetSupport Manager is a remote control and support software that we find surprisingly often utilized in sensitive *Operational Technology (OT)* environments, such as production plant networks. Besides describing two 0-day vulnerabilities that we found in the client component of the software, we also walk you through an exploit odyssey to finally gain unauthenticated Remote Code Execution.