DigiNews

Tech Watch by Johan Denoyer

← Back to articles

A Practical Guide to “Plug&Pwn” for Pentesters and Defenders

Quality: 8/10 Relevance: 9/10

Summary

This SCRT Team Blog post provides a practical, hands-on guide to the Plug&Pwn attack scenarios, focusing on Windows Plug and Play abuse via USB emulation and RDP USB redirection. It documents setup steps, proof-of-concept techniques, and real-world implications, including how vulnerable driver packages can be installed and leveraged for privilege escalation. The article also offers remediation guidance for defenders, such as disabling co-installers, restricting USB device installation, and hardening RDP configurations.

🚀 Service construit par Johan Denoyer