Client Side Fingerprinting in Prep for SE
ID: c90cde44-5084-52ae-b1b1-51707cf023b3
STIX ID: report--c90cde44-5084-52ae-b1b1-51707cf023b3
Feed Name: SensePost Blog
During a phishing-only engagement, testers used OSINT—leveraging a Skype IP disclosure trick and indexed web logs—to identify a target organization’s internal/external IPs and profile user agent distributions (notably many Windows XP/IE6 and Windows 7/IE8 systems) to guide payload selection; while BlackHole and Metasploit’s Browser AutoPwn were blocked by Forefront, a customized Meterpreter launcher ultimately succeeded, with a recommendation to use reverse-HTTP for more reliable session management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
