DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp

Gaining initial access to an intranet is one of the most challenging parts of red teaming. If an attack chain is intercepted by an incident response team, the entire operation must be restarted. In this talk, we introduce a technique for gaining initial access to an intranet that does not involve phishing, exploiting public-facing applications, or having a valid account. Instead, we leverage the use of stateless tunnels, such as GRE and VxLAN, which are widely used by companies like Cloudflare and Amazon. This technique affects not only Cloudflare's customers but also other companies. Additionally, we will share evasion techniques that take advantage of company intranets that do not implement source IP filtering, preventing IR teams from intercepting the full attack chain. Red teamers could confidently perform password spraying within an internal network without worrying about losing a compromised foothold. Also, we will reveal a nightmare of VxLAN in Linux Kernel and RouterOS. This affects many companies, including ISPs. This feature is enabled by default and allows anyone to hijack the entire tunnel, granting intranet access, even if the VxLAN is configured on a private IP interface through an encrypted tunnel. What's worse, RouterOS users cannot disable this feature. This problem can be triggered simply by following the basic VxLAN official tutorial. Furthermore, if the tunnel runs routing protocols like BGP or OSPF, it can lead to the hijacking of internal IPs, which could result in domain compromises. We will demonstrate the attack vectors that red teamers can exploit after hijacking a tunnel or compromising a router by manipulating the routing protocols. Lastly, we will conclude the presentation by showing how companies can mitigate these vulnerabilities. Red teamers can use these techniques and tools to scan targets and access company intranets. This approach opens new avenues for further research.

DEF CON 33 - Cash, Drugs, and Guns - Why Your Safes Aren't Safe - Mark Omo, James Rowley
▶︎

DEF CON 33 - Cash, Drugs, and Guns - Why Your Safes Aren't Safe - Mark Omo, James Rowley

DEF CON 33 - Gateways to Chaos - How We Proved Modems Are a Ticking Time Bomb - Chiao-Lin  Yu
▶︎

DEF CON 33 - Gateways to Chaos - How We Proved Modems Are a Ticking Time Bomb - Chiao-Lin Yu

Surveilling the Masses with Wi-Fi Positioning Systems
▶︎

Surveilling the Masses with Wi-Fi Positioning Systems

WorstFit: Unveiling Hidden Transformers in Windows ANSI!
▶︎

WorstFit: Unveiling Hidden Transformers in Windows ANSI!

Hacking the Hackers: The Art of Compromising C2 Servers with Vangelis Stykas
▶︎

Hacking the Hackers: The Art of Compromising C2 Servers with Vangelis Stykas

Emulating and Detecting Kerberoasting | Red Canary
▶︎

Emulating and Detecting Kerberoasting | Red Canary

Every Level of Reverse Engineering Explained
▶︎

Every Level of Reverse Engineering Explained

DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame  - James 'albinowax' Kettle
▶︎

DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame - James 'albinowax' Kettle

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh
▶︎

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh

Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
▶︎

Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)

WiFi Calling: Revealing Downgrade Attacks and Not-so-private private Keys
▶︎

WiFi Calling: Revealing Downgrade Attacks and Not-so-private private Keys

#HITB2022SIN EDR Evasion Primer For Red Teamers - Jorge Gimenez & Karsten Nohl
▶︎

#HITB2022SIN EDR Evasion Primer For Red Teamers - Jorge Gimenez & Karsten Nohl

DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini
▶︎

DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini

DEF CON 33 - Unmasking the Snitch Puck: IoT surveillance tech in the school bathroom - Reynaldo, nyx
▶︎

DEF CON 33 - Unmasking the Snitch Puck: IoT surveillance tech in the school bathroom - Reynaldo, nyx

Black Hat USA 2025 | Advanced Active Directory to Entra ID Lateral Movement Techniques
▶︎

Black Hat USA 2025 | Advanced Active Directory to Entra ID Lateral Movement Techniques

DEF CON 33: Journey to the Center of the PSTN
▶︎

DEF CON 33: Journey to the Center of the PSTN

Cybersecurity Lab: How To Investigate PCAPs for SOC Analysts
▶︎

Cybersecurity Lab: How To Investigate PCAPs for SOC Analysts

DEF CON 33 - Browser Extension Clickjacking: One Click and Your Credit Card Is Stolen  - Marek Tóth
▶︎

DEF CON 33 - Browser Extension Clickjacking: One Click and Your Credit Card Is Stolen - Marek Tóth

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
▶︎

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

DEFCON33 - Man-In-The-Malware: Intercepting Adversarial Communications
▶︎

DEFCON33 - Man-In-The-Malware: Intercepting Adversarial Communications