Skyling

CyCraft Technology / Cyber Security Research Intern

Skyling is currently a cybersecurity research intern at CyCraft and a computer science student at National Central University. Skyling is actively learning in the field of network security, received awards in CTF competitions, and were selected as 2024 APNIC Fellow. Skyling also holds an AWS Cloud Practitioner certification, given a talk at the HITCON Elite Forum and served as a speaker for school events.

SPEECH
4/17 (Thu.) 16:15 - 17:00 4F 4B Threat Research Forum Live Translation Session
Sneak Skill 100 - Hidden Attack Surface: SCCM

SCCM (Configuration Manager) is a solution provided by Microsoft to help enterprise centrally manage the configuration and software deployment of Windows computers, servers, and other devices. With the advancement of security research in AD CS, potential security risks in Microsoft's AD-related services have become a focus of attention. SCCM, due to its highly interactive nature with devices, has been found to have more than 20 known security concerns. These risks include, but are not limited to, low-privilege domain users potentially gaining control over Tier 0 assets such as MSSQL, SMS, and AD CS.

This session will focus on the security issues of SCCM, providing an in-depth analysis of its operational principles and common misconfigurations that might serve as entry points for attackers.