CrackCodes 🇮🇳
15.9K subscribers
1.89K photos
386 videos
722 files
3.67K links
Official Websites: https://crackcodes.in | https://system32.in |
For Bug Hunters: https://system32.ink

Admin: @MynK0x00
Admin Math: prapattimynk.crackcodes.in


Be Secure~
जय श्री राम
Download Telegram
1
👍1
🔥🔥🔥nRF52 Debug Resurrection (APPROTECT Bypass)

💾Part1
This security investigation presents a way to bypass the APPROTECT on a protected nRF52840, in order to reactivate the Serial Wire Debug Interface (SWD), offering full debug capabilities on the target (R/W access to Flash/RAM/Registers, Code Exec and reprogramming). All the nRF52 versions are impacted.

💾Part2
In this post author presents how to:
💥exploit a real product based on nRF52840 to extract the Firmware and reactivate the SWD interface.
💥reproduce the attack on others nRF52 SoCs to confirm the vulnerability in all the nRF52 versions

⚠️Due to its intrinsic characteristics, the vulnerability cannot be patched without Silicon redesign, leading to a countless number of vulnerable devices on the field forever.
👍2
#Malware_analysis
1. ViperSoftX: Hiding in System Logs and Spreading VenomSoftX
https://decoded.avast.io/janrubin/vipersoftx-hiding-in-system-logs-and-spreading-venomsoftx
2. DUCKTAIL: An infostealer malware targeting Facebook Business accounts (.pdf)
https://ift.tt/yrkLdsi
3. Aurora: a rising stealer flying under the radar
https://blog.sekoia.io/aurora-a-rising-stealer-flying-under-the-radar
antimalware_scan_interface_bypasses_det.pdf
721.4 KB
#Red_Team_Tactics
"Antimalware Scan Interface Bypasses: Evading Detection to Perform Post Exploitation Activities", 2022.
FReD.pdf
288.3 KB
#Research
#Sec_code_review
"FRED: Identifying File Re-Delegation in Android System Services", 2022.
]-> Tool: https://github.com/wspr-ncsu/fred
CVE-2020-1349.pdf
1.7 MB
CVE-2020-16947.pdf
70.6 KB
CVE-2020-1493.pdf
75.9 KB
#Whitepaper
1. MS Outlook 2019 16.0.13231 - RCE (CVE-2020-16947);
2. MS Outlook 2019 16.0.12624 - Out-Of-Bounds Read (CVE-2020-1493);
3. MS Outlook 2019 16.0.12624 - RCE (CVE-2020-1349).
WebView_sec.pdf
740.3 KB
#Threat_Research
"Identity Confusion in WebView-based Mobile App-in-app Ecosystems", 2022.
RTFM_v2.epub
247.4 KB
#Tech_book
"Red Team Field Manual, Version 2.0", 2022.