<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Jeffrey Hofmann: Pre-Auth RCE Chains in MDM — Full Compromise of KACE SMA</title>
        <link>https://peertube.eqver.se/videos/watch/c9db5001-b40d-4019-beb8-5880fdc09902</link>
        <description>A DEF CON 30 talk covering three pre-authentication RCE chains in KACE Systems Management Appliance (KACE SMA), a popular MDM solution by Quest. Because an MDM manages devices across an entire organization — including executing tasks with root/system privileges — its compromise effectively means full control over the infrastructure. The talk walks through the research process in detail: from obtaining an initial shell and reversing PHP code to discovering SQL injection vulnerabilities, authentication bypasses, session logic flaws, and command injection. It demonstrates how these issues can be chained together — from an unauthenticated request to root-level code execution and mass command execution across managed endpoints.</description>
        <lastBuildDate>Fri, 24 Jul 2026 11:25:44 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://peertube.eqver.se</generator>
        <image>
            <title>Jeffrey Hofmann: Pre-Auth RCE Chains in MDM — Full Compromise of KACE SMA</title>
            <url>https://peertube.eqver.se/client/assets/images/icons/icon-512x512.png</url>
            <link>https://peertube.eqver.se/videos/watch/c9db5001-b40d-4019-beb8-5880fdc09902</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://peertube.eqver.se/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://peertube.eqver.se/feeds/video-comments.xml?videoId=c9db5001-b40d-4019-beb8-5880fdc09902" rel="self" type="application/rss+xml"/>
    </channel>
</rss>