DEF CON 27 - Infiltrating Corporate Intranet Like NSA _Pre-auth RCE on Leading SSL VPNs @HackersOnBoard
DEF CON 27 - Infiltrating Corporate Intranet Like NSA _Pre-auth RCE on Leading SSL VPNs  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 2 days ago
Computer security is now a public policy issue. Election security, blockchain, "going dark," the vulnerabilities equities debate, IoT safety , data privacy, algorithmic security and fairness, critical infrastructure: these are all important public policy issues with a strong Internet security component. But while an understanding of the technology involved is fundamental to crafting good policy, there is little involvement of technologists in policy discussions. This is not sustainable. We need public-interest technologists: people from our fields helping craft policy, and working to provide security to agencies and groups working in the broader public interest. We need these people in government, at NGOs, teaching at universities, as part of the press, and inside private companies. This is increasingly critical to both public safety and overall social welfare. This talk both describes the current state of public-interest technology, and offers a way forward for us individually and collectively for our field. The defining policy question of the Internet age is this: How much of our lives should be governed by technology, and under what terms? We need to be involved in that debate.SSL VPNs protect corporate assets from Internet exposure, but what if SSL VPNs themselves are vulnerable? They're exposed to the Internet, trusted to reliably guard the only way to intranet. However, we found pre-auth RCEs on multiple leading SSL VPNs, used by nearly half of the Fortune 500 companies and many government organizations. To make things worse, a "magic" backdoor was found to allow changing any user's password with no credentials required! To show how bad things can go, we will demonstrate gaining root shell from the only exposed HTTPS port, covertly weaponizing the server against their owner, and abusing a hidden feature to take over all VPN clients!

In such complicated closed-source systems, gaining root shell from outside the box certainly ain't easy. It takes advanced web and binary exploitation techniques to struggle for a way to root shell, which involves abusing defects in web architectures, hard-core Apache jemalloc exploitation and more. We will cover every detail of all the dirty tricks, crazy bug chains, and the built-in backdoor. After gaining root shell into the box, we then elaborate on post exploitation and how we hack back the clients. In addition, we will share the attack vectors against SSL VPNs to kick start researches on similar targets. On the other hand, from our previous experience, we derive general hardening actions that mitigate not only all the above attacks, but any other potential 0days.

In summary, we disclose practical attacks capable of compromising millions of targets, including tech giants and many industry leaders. These techniques and methodologies are published in the hope that it can inspire more security researchers to think out-of-the-box; enterprises can apply immediate mitigation, and realize that SSL VPN is not merely Virtual Private Network, but also a "Vulnerable Point of your Network".


Talk by Orange Tsai
DEF CON 27 - Infiltrating Corporate Intranet Like NSA _Pre-auth RCE on Leading SSL VPNsDEF CON 27 - Dirk-jan Mollema - Im In Your Cloud Pwning Your Azure EnvironmentBlack Hat USA 2018 - Real Eyes, Realize, Real Lies Beating Deception TechnologiesDEF CON 27 - Roger Dingledine - The Tor Censorship Arms Race The Next ChapterDEF CON 27 - Truman Kain - Surveillance Detection Scout Your Lookout on AutopilotDEF CON 27 - Jmaxxz - Your Car is My CarHow TRITON Disrupted Safety Systems & Changed the Threat Landscape of IndustrialHow can Communities Move Forward After Incidents of Sexual Harassment or AssaultDEF CON 27 - Jacob Baines - Help Me Vulnerabilities Youre My Only HopeDEF CON 27 - Eyal Itkin - Say Cheese How I Ransomwared Your DSLR CameraDEF CON 27 - Bill Demirkapi - Are Your Childs Records at Risk The Current State of School InfosecFor the Love of Money Finding and Exploiting Vulnerabilities in Mobile Point of Sales Systems
HackersOnBoard |

DEF CON 27 - Infiltrating Corporate Intranet Like NSA _Pre-auth RCE on Leading SSL VPNs

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER