Forwarded from Таверна "Під дубом"
This media is not supported in your browser
VIEW IN TELEGRAM
БЗВП PRO
👍5😁2🔥1
Forwarded from vx-underground
Chat, today is a good day.
Look at this "Grand Theft Auto 6 BETA for FREE" advertisement that fell onto my lap. It delivers a .rar that has a .exe inside.
I am so happy. I am elated. It is free malware.
Look at this "Grand Theft Auto 6 BETA for FREE" advertisement that fell onto my lap. It delivers a .rar that has a .exe inside.
I am so happy. I am elated. It is free malware.
Forwarded from vx-underground
vx-underground
Chat, today is a good day. Look at this "Grand Theft Auto 6 BETA for FREE" advertisement that fell onto my lap. It delivers a .rar that has a .exe inside. I am so happy. I am elated. It is free malware.
Literally shaking, screaming, crying, THROWING UP.
The .exe is bundled with BUN (some Javascript bullshit). I deobfuscated the main goop inside of it, found the C2 configuration (where it downloads cool malware from), and ... it's dead.
Cloudflare KILLED THEIR C2. THE MALWARE IS DEAD. THEY KILLED THE MALWARE CAMPAIGN.
How are we supposed to get malware from fake Grand Theft Auto 6 advertisements if Cloudflare KILLS their infrastructure???
RIP NWHStealer campaign ID 202fdde5193b.
RIP NWHStealer c2 unauth-amper(.)cc
The .exe is bundled with BUN (some Javascript bullshit). I deobfuscated the main goop inside of it, found the C2 configuration (where it downloads cool malware from), and ... it's dead.
Cloudflare KILLED THEIR C2. THE MALWARE IS DEAD. THEY KILLED THE MALWARE CAMPAIGN.
How are we supposed to get malware from fake Grand Theft Auto 6 advertisements if Cloudflare KILLS their infrastructure???
RIP NWHStealer campaign ID 202fdde5193b.
RIP NWHStealer c2 unauth-amper(.)cc
😁13🫡2
Подрубил к ИИшке скилл, она теперь использует маковскую
Это охуенно
say чтобы докладывать о прогрессе или проблемах, пока я чай пью) И не надо смотреть в мониторЭто охуенно
Dolboeb-driven Development
Подрубил к ИИшке скилл, она теперь использует маковскую say чтобы докладывать о прогрессе или проблемах, пока я чай пью) И не надо смотреть в монитор Это охуенно
Девушка правда теперь хочет меня за это отпиздить)
❤5
Forwarded from HN Best Comments
Re: Potential session/cache leakage between workspace instances or consumer accounts
This attack is called "HTTP desync" or "request smuggling". It's often done intentionally by a client to try and spy on other clients' responses.
Every time you multiplex requests from multiple clients onto one upstream connection, you are probably vulnerable to this, because (despite its superficial simplicity) HTTP is just too complex to reliably match the requests and responses to upstream.
For example a desync can be triggered in some systems by having more than one Content-Length header, by mixing Content-Length with chunked encoding, or by passing an HTTP/2 header called Content-Length that doesn't match the actual content length.
Here's a DEF CON talk (6 years ago) on this topic: https://www.youtube.com/watch?v=w-eJM2Pc0KI
The same attack has been applied to SMTP by messing up the line endings surrounding the end-of-message delimiter, where it's called SMTP smuggling. It may also apply to other protocols.
pocksuppet, 1 day ago
This attack is called "HTTP desync" or "request smuggling". It's often done intentionally by a client to try and spy on other clients' responses.
Every time you multiplex requests from multiple clients onto one upstream connection, you are probably vulnerable to this, because (despite its superficial simplicity) HTTP is just too complex to reliably match the requests and responses to upstream.
For example a desync can be triggered in some systems by having more than one Content-Length header, by mixing Content-Length with chunked encoding, or by passing an HTTP/2 header called Content-Length that doesn't match the actual content length.
Here's a DEF CON talk (6 years ago) on this topic: https://www.youtube.com/watch?v=w-eJM2Pc0KI
The same attack has been applied to SMTP by messing up the line endings surrounding the end-of-message delimiter, where it's called SMTP smuggling. It may also apply to other protocols.
pocksuppet, 1 day ago
YouTube
albinowax - HTTP Desync Attacks: Smashing into the Cell Next Door - DEF CON 27 Conference
HTTP requests are traditionally viewed as isolated, standalone entities. In this session, I'll introduce techniques for remote, unauthenticated attackers to smash through this isolation and splice their requests into others, through which I was able to play…
Forwarded from Tech Crimes (Architector #4 (3D comms open))
theregister
Microsoft flips Windows Backup to on by default unless you're in the EU
Everyone else must opt out manually if they don't fancy settings data shipped off-device
>Я тут подумав: міністр оборони в Україні це як викладач захисту від темних мистецтв в Хогварсті
😁10🥴1