Automating COM/DCOM vulnerability research
文章探讨了Windows中的COM和DCOM组件在安全方面的复杂性及历史漏洞,并介绍了利用模糊测试自动化安全研究的方法及其面临的挑战。 2025-10-30 20:24:7 Author: www.reddit.com(查看原文) 阅读量:2 收藏

COM (Component Object Model) and DCOM (Distrubuted COM) have been interesting components in Windows from a security perspective for many years. In the past, COM has been a target for many purposes. Not only have many vulnerabilities been discovered in COM, but it is also used for lateral movement or bypassing techniques.

This white paper describes how COM/DCOM works and what complications it has. In the next chapters, the white paper will describe how security research can be automated using the fuzzing approach. Since this approach comes with some problems, it describes how these problems were overcome (at least partially).


文章来源: https://www.reddit.com/r/netsec/comments/1okanf4/automating_comdcom_vulnerability_research/
如有侵权请联系:admin#unsafe.sh