Kaseya VSA Exploit POC - Authentication Bypass, Arbitrary File Upload and Command Injection

preview_player
Показать описание
POC created by Caleb Stewart which reproduces the 2 July 2021 REvil attack against 30+ Managed Service Providers. In this demo, we demonstrate how a simple command can be run or a Meterpreter payload from MSFVenom can up uploaded and executed.
Рекомендации по теме
Комментарии
Автор

Would something like an Azure WAF have helped prevent this?

AndrewFarag