官术网_书友最值得收藏!

Horizontal privilege escalation

Horizontal privilege escalation, on the other hand, is simpler since it allows a user to use the same privileges gained from the initial access.

A good example is where an attacker has been able to steal the login credentials of an administrator of a network. The administrator account already has high privileges that the attacker assumes immediately after accessing it.

Horizontal privilege also occurs when an attacker is able to access protected resources using a normal user account. A good example is where a normal user is erroneously able to access the account of another user. This is normally done through session and cookie theft, cross-site scripting, guessing weak passwords, and logging keystrokes.

At the end of this phase, the attacker normally has well-established remote access entry points into a target system. The attacker might also have access to the accounts of several users. The attacker also knows how to avoid detection from security tools that the target might have. This leads to the next phase, called exfiltration.

主站蜘蛛池模板: 寿宁县| 屏南县| 泾阳县| 山丹县| 涡阳县| 黔江区| 繁峙县| 杭锦旗| 平江县| 克拉玛依市| 宜君县| 沂源县| 兴宁市| 谷城县| 碌曲县| 新乐市| 罗城| 石林| 双柏县| 牟定县| 咸丰县| 建阳市| 茂名市| 高要市| 景德镇市| 武冈市| 黄梅县| 武宁县| 神池县| 巧家县| 石城县| 盈江县| 岢岚县| 平阳县| 前郭尔| 桂东县| 古交市| 文登市| 布尔津县| 三台县| 阳原县|