DEF CON 32 - Why are you still using my server for your internet access - Thomas Boejstrup Johansen

DEF CON 32 - Why are you still using my server for your internet access - Thomas Boejstrup Johansen

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 39:11

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video exposes a critical security flaw in Microsoft's 25-year-old "vpad" protocol, which enables clients to automatically configure proxy settings via DNS-resolved JavaScript scripts—leading to unsecured traffic routing, data exfiltration, and credential leaks. 0:58

Key Takeaways:
• The vpad system resolves domains like "vpad.company.com" and downloads a JavaScript script that redirects all traffic to a proxy server, often without user awareness 2:50.
• This script can be exploited to route traffic through malicious servers, leak internal data, and execute payloads—such as from Cobalt Strike or ad-tracking scripts—without consent 19:10.
• Real-world monitoring revealed over 1.1 billion DNS requests and 200 GB of log data, exposing clear-text credentials, user agents, internal IPs, and outdated software versions 14:44.
• The vpad protocol remains active across Windows, macOS, and Android, and is vulnerable when not disabled at the system level 38:49.
• The domain "vpad.dk" was purchased and used to host a rogue proxy, demonstrating the protocol's continued exploitability despite being deprecated 8:07.

Organizations must disable the vpad function at the system level—by adding vpad domains to the host file and disabling the associated proxy service—to prevent unauthorized traffic routing and data exposure.

Sources:

  • 0:58 Protocol background and initial discovery
  • 2:50 vpad mechanism and traffic redirection
  • 19:10 Exploitation of JavaScript scripts a

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

yeah my name is Thomas and um my daily work is incident response and forensics uh I had done some red team so in red team engagements I often use responder where there's a function to set up a rogue proxy server with the double vpad function so monitoring the network to see the traffic seeing that clients is asking for the vpad domain uh in the company but it is also sometimes asking for vpad dold so who is having this domain is it in use is it free can I buy it what are they using it for so at the time I looked at this I looked up and discovered it was a German guy that had this Danish domain uh don't know what he was using it for two years later I looked again discovered this summon in Israel having the Danish domain and in 2020 the Danish register for Deco DK domains added at a function…