EMZETT.
Login

Exploit

In short: An exploit is code or a method that deliberately uses a security vulnerability.

In more detail: The vulnerability is the weak point, the exploit the way in. Afterwards a payload is executed, for example a back door.

In Depth

Well-known databases and tools

  • CVE: unique number of a known vulnerability (for example CVE-2017-0144).
  • Exploit frameworks: such as Metasploit for testing your own systems.

Examples

EternalBlue used SMBv1 under Windows and powered WannaCry.

Protection

Patches, hardening, segmenting the network, vulnerability scans (for example with nmap). See pentesting.

See also: Zero-Day Vulnerabilities, EternalBlue, Penetration Testing, Nmap