Παραμετροποίηση μεθόδων επίθεσης σε συστήματα Windows
Attack paremetrization in Windows systems

View/ Open
Keywords
Penetration testing ; Active directory ; Kerberoasting ; AS-REP roasting ; SQL injection ; Cross-site scripting ; Brute force ; Phishing ; Remote code execution ; Metasploit ; DVWA ; MITRE ATT&CK ; Cyber kill chain ; OWASP ; Windows securityAbstract
This thesis presents a systematic study and practical parameterization of attack methods on Windows systems, through the implementation of four distinct attack scenarios in a controlled laboratory environment. This environment consists of virtual machines interconnected via the Tailscale VPN network and reproduces realistic conditions of a corporate Windows infrastructure.
The first scenario examines an AS-REP Roasting and Kerberoasting attack against a Domain Controller in an Active Directory environment, aiming at the extraction and decryption of service account passwords. The second scenario focuses on the exploitation of web application vulnerabilities through the DVWA platform, covering SQL Injection, Brute Force, and Cross-Site Scripting (XSS). The third scenario analyzes a Phishing-to-Remote Code Execution attack using GoPhish and the Metasploit Framework, highlighting the human factor as a critical point of vulnerability. The fourth scenario examines anonymous access to an IIS FTP Server, highlighting the risks arising from misconfigured network services.
The methodology followed is based on the MITRE ATT&CK and Cyber Kill Chain frameworks, with each scenario analyzed in terms of exploitation logic, execution, and results. The findings demonstrate that complete system compromise is achievable through well-known techniques and open-source tools, underscoring the importance of proper configuration, strong password policies, and continuous user training.

