DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp

DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 42:24

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This presentation reveals how attackers can exploit unencrypted network tunnels like GRE and VXLAN to bypass security and gain unauthorized access to internal networks 1:34.

Key Takeaways:
• Attackers can spoof source IP addresses to attack intranet servers from outside, creating a "breakpoint" in attack chains that makes incident response difficult 5:38
• GRE tunnels are vulnerable to spoofing since they're stateless and unencrypted, allowing attackers to send packets that appear to come from trusted sources 17:54
• VXLAN implementations have a dangerous "learning" feature enabled by default that accepts packets from any IP address, not just configured peers 25:25
• After hijacking tunnels, attackers can compromise domain controllers, perform man-in-the-middle attacks, and exploit routing protocols like OSPF for lateral movement 33:40
• Blue teams should eliminate unencrypted tunnels, implement proper firewall filtering, and monitor routing protocols for anomalies 38:15

The presenter demonstrates practical attacks while providing defensive recommendations to prevent these network tunneling exploits 40:55.

Sources:

  • 1:34 Explains the mystery of how public IPs can attack intranet servers
  • 5:38 Details IP spoofing techniques for red teaming
  • 17:54 Explains how GRE tunneling works and its vulnerabilities
  • 25:25 Describes why VXLAN is vulnerable by default design
  • 33:40

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Okay, thank you everyone. So, let's start the talk. Um, hi, I'm Suha from Taiwan and this is my first time to present at Defcon and also my first time at Defcon and also my first time at least and not my side in US. Okay, so thank you all for joining my session. So I'm excited excited to share some practical red team networking techniques with you today. So I guess we can get start. Okay. So now let me take you into a typical day in my IT life seeing my internet laps server logs. And there's a login from Frank. And there's a login from Bob. And then wow, there's a invalid login from a public IP 999.99. And how how and why this this can happen? This is a intranet server without no destination NAT. So, okay, I say it. I'll bend it that bad IP. But a second later, there's another IP attacking…