
DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 42:24
This presentation reveals how attackers can exploit unencrypted network tunnels like GRE and VXLAN to bypass security and gain unauthorized access to internal networks 1:34.
Key Takeaways:
• Attackers can spoof source IP addresses to attack intranet servers from outside, creating a "breakpoint" in attack chains that makes incident response difficult 5:38
• GRE tunnels are vulnerable to spoofing since they're stateless and unencrypted, allowing attackers to send packets that appear to come from trusted sources 17:54
• VXLAN implementations have a dangerous "learning" feature enabled by default that accepts packets from any IP address, not just configured peers 25:25
• After hijacking tunnels, attackers can compromise domain controllers, perform man-in-the-middle attacks, and exploit routing protocols like OSPF for lateral movement 33:40
• Blue teams should eliminate unencrypted tunnels, implement proper firewall filtering, and monitor routing protocols for anomalies 38:15
The presenter demonstrates practical attacks while providing defensive recommendations to prevent these network tunneling exploits 40:55.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Okay, thank you everyone. So, let's start the talk. Um, hi, I'm Suha from Taiwan and this is my first time to present at Defcon and also my first time at Defcon and also my first time at least and not my side in US. Okay, so thank you all for joining my session. So I'm excited excited to share some practical red team networking techniques with you today. So I guess we can get start. Okay. So now let me take you into a typical day in my IT life seeing my internet laps server logs. And there's a login from Frank. And there's a login from Bob. And then wow, there's a invalid login from a public IP 999.99. And how how and why this this can happen? This is a intranet server without no destination NAT. So, okay, I say it. I'll bend it that bad IP. But a second later, there's another IP attacking…