University CTF 2023: "You've been Conned!" by Sebh24

University CTF 2023: "You've been Conned!" by Sebh24

Source: YouTube · Hack The Box · published Dec 7, 2023 · 35:44

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates a security incident response analysis of Confluence vulnerability CVE-2023-22515, showing how attackers created malicious admin accounts and accessed sensitive credentials 0:01.

Key Takeaways:
• CVE-2023-22515 is a critical broken access control vulnerability affecting Confluence that allows attackers to re-enable setup processes and create malicious admin accounts 0:36.
• The investigation reveals evidence of compromise through specific URL requests like "server-info.action" with suspicious parameters, found in access logs 10:00.
• Attackers created a user account "pwned" with admin privileges, confirmed through audit logs showing creation by anonymous user at same time as malicious requests 19:03.

The walkthrough illustrates how proper forensic analysis of logs can reconstruct an attack chain from initial exploitation to lateral movement 35:26.

Sources:

  • 0:01 Introduction to Confluence vulnerability CVE-2023-22515
  • 0:36 Details about the CVE vulnerability
  • 10:00 Detection opportunities in logs
  • 19:03 Confirmation of malicious account creation

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

um good afternoon welcome to University ETF talk for 2023 this talk is being named you've being con as I'm sure some of you have probably guessed the reason for that is we're going to be covering the the very recent conference cve um we built a Sherlock called cond around the cve and I think we released it kind of within the week so it's quite a fast turnaround so essentially the goal today will be a walkr talk through um through as much of the Sherlock as I can get through time for meting as I only have 30 minutes um the CV itself was CV 2023 22515 which is a critical broken access cont control varability um AFF affecting a variety of Confluence versions um we get we get a variety of artifacts today we'll do a quick walk through of the platform a talk through how Sherlocks looks and then …