官术网_书友最值得收藏!

Horizontal privilege escalation

Horizontal privilege escalation, on the other hand, is simpler since it allows a user to use the same privileges gained from the initial access.

A good example is where an attacker has been able to steal the login credentials of an administrator of a network. The administrator account already has high privileges that the attacker assumes immediately after accessing it.

Horizontal privilege also occurs when an attacker is able to access protected resources using a normal user account. A good example is where a normal user is erroneously able to access the account of another user. This is normally done through session and cookie theft, cross-site scripting, guessing weak passwords, and logging keystrokes.

At the end of this phase, the attacker normally has well-established remote access entry points into a target system. The attacker might also have access to the accounts of several users. The attacker also knows how to avoid detection from security tools that the target might have. This leads to the next phase, called exfiltration.

主站蜘蛛池模板: 广元市| 新巴尔虎右旗| 墨脱县| 黑山县| 唐山市| 西乡县| 蓬莱市| 沧州市| 那坡县| 延寿县| 仪陇县| 四川省| 海盐县| 中阳县| 锦州市| 万州区| 伊宁市| 富阳市| 曲阜市| 安塞县| 横峰县| 襄垣县| 北安市| 呼和浩特市| 米泉市| 昌邑市| 六枝特区| 璧山县| 武陟县| 正阳县| 枞阳县| 宁阳县| 内江市| 景宁| 山阴县| 桂东县| 保德县| 天台县| 松江区| 屏东市| 鱼台县|