DEF CON 27 - Jayson Grace - MOSE Using Configuration Management for Evil @HackersOnBoard
DEF CON 27 - Jayson Grace - MOSE Using Configuration Management for Evil  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 12 hours ago
Configuration Management (CM) tools are used to provision systems in a uniform manner. CM servers are prime targets for exploitation because they are connected with key machines. The tools themselves are powerful from a security standpoint: they allow an attacker to run commands on any and every connected system. Unfortunately, many security professionals do not have CM experience, which prevents them from using these tools effectively. MOSE empowers the user to weaponize an organization’s CM tools without having to worry about implementation-specific details.

MOSE first creates a binary based on user input. Once transferred to the CM server and run, this binary dynamically generates code that carries out the desired malicious behavior on specified systems. This behavior can include running arbitrary system commands, creating or deleting files, and introducing backdoors. MOSE puts the generated code in the proper place so that all targeted systems will run it on their next check-in with the server, removing the need for the user to integrate it manually.

CM tools are a powerful resource, but they have a barrier to entry. MOSE aims to remove this barrier and make post exploitation more approachable by providing a tool to translate the attacker's desired task into commands executable by the CM infrastructure.
DEF CON 27 - Jayson Grace - MOSE Using Configuration Management for EvilDEF CON 27 - Jens Muller - Re Whats up Johnny Covert Content Attacks on Email End-to-End EncryptionBlack Hat USA 2018 - Mainframe [z/OS] Reverse Engineering and Exploit DevelopmentDetecting Malicious Cloud Account Behavior A Look at the New Native Platform CapabilitiesDEF CON 27 - Zombie Ant Farm Practical Tips for Playing Hide and Seek with Linux EDRsDEF CON 27 - State of DNS Rebinding Attack & Prevention Techniques and the Singularity of OriginDEF CON 27 - droogie - Go NULL Yourself or How I Learned to Start Worrying While Getting FinedDEF CON 27 - XiaoHuiHui - All the 4G Modules Could Be HackedDEF CON 27 - Leon Jacobs - Meticulously Modern Mobile ManipulationsDEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On MicrocontrollersDEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac DestructionDEF CON 27 - How You Can Buy ATandT T-Mobile and Sprint Real-Time Location Data on the Black Market
HackersOnBoard |

DEF CON 27 - Jayson Grace - MOSE Using Configuration Management for Evil

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER