A writable share is a staging ground for attacks on everyone who uses it. Three families matter: icon-loading files (SCF, LNK, URL) that coerce a browsing user's machine to authenticate to the attacker, Office documents and templates that run code when a user opens them, and executables and DLLs that users or services on the share run directly.
Subtopics#
- SCF and LNK coercion: coerce authentication on browse.
- Office and template poisoning: run code on open.
- Executable and DLL planting: replace or sideload binaries.