Skip to main content

Success Rates for Client Side Vulnerabilities

The user is the weakest link in the computer security chain. From clicking on links that they shouldn't, to having weak passwords, it generally comes down to the end user doing something they should't. If the user runs a piece of malware or opens an infected file, will it always lead to a compromise? This paper plans to test if client-side exploits will always function or if there are additional factors to consider when dealing with these vulnerabilities and associated exploits. Is the Common Vulnerability Scoring System (CVSS) score enough to determine if a particular vulnerability is more critical than another and should be remediated sooner than another? This testing will be accomplished through the use of freely available exploitation software (e.g. Social Engineering Toolkit, Metasploit) in a closed testing environment.

37057 (PDF, 9.00MB)

14 Jun 2016
ByJonathan Risto
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.