DEF CON 33 - Win-DoS Epidemic - Abusing RPC for Win-DoS & Win-DDoS - Or  Yair, Shahak Morag

DEF CON 33 - Win-DoS Epidemic - Abusing RPC for Win-DoS & Win-DDoS - Or Yair, Shahak Morag

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 37:17

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The presentation reveals critical Windows RPC vulnerabilities that allow unauthenticated denial of service attacks against domain controllers and Windows endpoints, demonstrating how developers' blind spots in network transport abstraction and client code can be exploited 1:19.

Key Takeaways:
• LDUP Nightmare vulnerability allows attackers to crash any domain controller without authentication by turning it into a CLDUP client and sending invalid values 3:56.
• WinDOS attack leverages domain controllers as bots in a distributed denial of service by using valid LDUP referrals to target a victim server 10:07.
• WinDOS 2 causes memory exhaustion by sending huge referral lists that aren't released until processing completes, potentially crashing systems 14:12.
• Researchers developed "stateless RPC" technique to send bind and call in single packet, dramatically increasing attack efficiency 20:42.
• TorpedOS technique allows single computers to overwhelm targets by pre-binding thousands of connections before flooding with RPC calls 25:35.

Their research identified four new remote-triggered denial of service vulnerabilities, all fixed by Microsoft, highlighting the critical need for proper resource management in network-facing Windows components 36:04.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hi everyone and thank you very much for coming to our talk Windows epidemic a crash course in abusing RPC for Windos and Win DOS. The theme for our talk today is going to be dumb ways to die for those of you who know it. So I really hope that you'll appreciate the connection between the technical details and this uh funny little uh mobile game. My name is Orya. I'm the security research team lead at SafeBache. I have more than seven years of experience in security research with uh past research on Linux embedded and Android systems and for more year for more than four years now. My main focus lies in vulnerability research in the Windows operating system and third party apps on it and it's also my second defcon talk here today. Hi everyone, my name is Shahak Morag currently serving as rese…