官术网_书友最值得收藏!

Horizontal privilege escalation

Horizontal privilege escalation, on the other hand, is simpler since it allows a user to use the same privileges gained from the initial access.

A good example is where an attacker has been able to steal the login credentials of an administrator of a network. The administrator account already has high privileges that the attacker assumes immediately after accessing it.

Horizontal privilege also occurs when an attacker is able to access protected resources using a normal user account. A good example is where a normal user is erroneously able to access the account of another user. This is normally done through session and cookie theft, cross-site scripting, guessing weak passwords, and logging keystrokes.

At the end of this phase, the attacker normally has well-established remote access entry points into a target system. The attacker might also have access to the accounts of several users. The attacker also knows how to avoid detection from security tools that the target might have. This leads to the next phase, called exfiltration.

主站蜘蛛池模板: 保定市| 兴文县| 安西县| 江津市| 长汀县| 九龙县| 策勒县| 福州市| 旌德县| 曲靖市| 忻州市| 太白县| 政和县| 卓尼县| 鹤峰县| 阳江市| 辉县市| 临澧县| 上思县| 高青县| 兴宁市| 翁牛特旗| 砚山县| 灵山县| 铜山县| 金秀| 布拖县| 皮山县| 濉溪县| 潮州市| 疏附县| 旅游| 宁安市| 长沙市| 梅河口市| 成都市| 蒲江县| 沂水县| 尼勒克县| 平度市| 乳山市|