Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

利用域前置Cobalt Strike逃避IDS | 剑胆琴心 #15

Open
shuai06 opened this issue Jun 23, 2022 · 0 comments
Open

利用域前置Cobalt Strike逃避IDS | 剑胆琴心 #15

shuai06 opened this issue Jun 23, 2022 · 0 comments

Comments

@shuai06
Copy link
Owner

shuai06 commented Jun 23, 2022

http://www.xpshuai.cn/2022/06/14/%E5%88%A9%E7%94%A8%E5%9F%9F%E5%89%8D%E7%BD%AECobalt-Strike%E9%80%83%E9%81%BFIDS/

域前置(Domain Fronting)原理 CND分发 原理: 通过CDN节点将流量转发到真实的C2服务器,其中CDN节点IP通过识别请求的HOST头进行流量转发,利用我们配置域名的高可信度,如我们可以设置一个微软的子域名,可以有效的躲避DLP、agent等流量检测。域前置的核心是CDN 在某 cdn 服务商开通 cdn 加速服务,并将想要伪造的域名与 c2 的 ip 进行绑定(阿里云和 cl

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant