DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp @DEFCONConference
DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp  @DEFCONConference
Uploaded October 2025 | Updated September 2026, 3 weeks ago
Gaining initial access to an intranet is one of the most challenging parts of red teaming. If an attack chain is intercepted by an incident response team, the entire operation must be restarted. In this talk, we introduce a technique for gaining initial access to an intranet that does not involve phishing, exploiting public-facing applications, or having a valid account. Instead, we leverage the use of stateless tunnels, such as GRE and VxLAN, which are widely used by companies like Cloudflare and Amazon. This technique affects not only Cloudflare's customers but also other companies.

Additionally, we will share evasion techniques that take advantage of company intranets that do not implement source IP filtering, preventing IR teams from intercepting the full attack chain. Red teamers could confidently perform password spraying within an internal network without worrying about losing a compromised foothold. Also, we will reveal a nightmare of VxLAN in Linux Kernel and RouterOS. This affects many companies, including ISPs. This feature is enabled by default and allows anyone to hijack the entire tunnel, granting intranet access, even if the VxLAN is configured on a private IP interface through an encrypted tunnel. What's worse, RouterOS users cannot disable this feature. This problem can be triggered simply by following the basic VxLAN official tutorial. Furthermore, if the tunnel runs routing protocols like BGP or OSPF, it can lead to the hijacking of internal IPs, which could result in domain compromises. We will demonstrate the attack vectors that red teamers can exploit after hijacking a tunnel or compromising a router by manipulating the routing protocols.

Lastly, we will conclude the presentation by showing how companies can mitigate these vulnerabilities. Red teamers can use these techniques and tools to scan targets and access company intranets. This approach opens new avenues for further research.
DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojpDEF CON 33 - Recording PCAPs from Stingrays With a $20 Hotspot - Cooper Quintin, oopsbagelDEF CON 21 - Charlie Miller and Chris Valasek - Adventures in Automotive Networks and Control UnitsDEF CON 32 - The Interplay between Safety and Security in Aviation Systems - Lillian Ash BakerDEF CON 33 Recon Village - Autonomous Video Hunter AI Agents for Real Time OSINT - Kevin Dela RosaDEF CON 32 - On Your Oceans 11 Team, Im the AI Guy (technically Girl) - Harriet FarlowDEF CON 33 - BiC Village - Cyber Game Changers Women Who Lead, Secure and Inspire - PanelDEF CON 33 - Help! Linux in my Webcam! (•_•) - Mickey Shkatov, Jesse MichaelFlipping Locks - Remote Badge Cloning with the Flipper Zero and More - Langston Clements & Dan GogaDEF CON 33 - Voting Village - CARVER Vuln Analysis & US Voting System - Moore, Young, BaggettDEF CON 32 - Bug Hunting In VMware Device Virtualization - JiaQing Huang, Hao Zheng, Yue LiuDEF CON 32 - The Past, Present, and Future of Bioweapons - Panel
DEFCONConference |

DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER