Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat (Youtube)
iOS Kernel PAC, One Year Later
In February 2019, I reported to Apple five ways to bypass kernel Pointer Authentication on the iPhone XS . My impression was that the design, while a dramatic improvement on the ARMv8.3 standard, had some fundamental issues when defending kernel control flow against attackers with kernel memory access. This talk will look at how PAC has (and hasn't) improved in the subsequent year, once again concluding with five new ways to bypass kernel PAC to obtain arbitrary kernel code execution on iOS 13.3.
By Brandon Azad
Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#ios-kernel-pac-one-year-later-19726
iOS Kernel PAC, One Year Later
In February 2019, I reported to Apple five ways to bypass kernel Pointer Authentication on the iPhone XS . My impression was that the design, while a dramatic improvement on the ARMv8.3 standard, had some fundamental issues when defending kernel control flow against attackers with kernel memory access. This talk will look at how PAC has (and hasn't) improved in the subsequent year, once again concluding with five new ways to bypass kernel PAC to obtain arbitrary kernel code execution on iOS 13.3.
By Brandon Azad
Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#ios-kernel-pac-one-year-later-19726
Media is too big
VIEW IN TELEGRAM
Black Hat (Youtube)
A Decade After Stuxnet's Printer Vulnerability: Printing is Still the Stairway to Heaven
In 2010, Stuxnet, the most powerful malware in the world revealed itself, causing physical damage to Iranian nuclear enrichment centrifuges. In order to reach Iran's centrifuges, it exploited a vulnerability in the Windows Print Spooler service to gain code execution as NT AUTHORITY\SYSTEM. Due to the hype around this critical vulnerability, we (and probably everyone else) were pretty sure that this attack surface would no longer exist a decade later. We were wrong…
By Peleg Hadar and Tomer Bar
Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#a-decade-after-stuxnets-printer-vulnerability-printing-is-still-the-stairway-to-heaven-19685
A Decade After Stuxnet's Printer Vulnerability: Printing is Still the Stairway to Heaven
In 2010, Stuxnet, the most powerful malware in the world revealed itself, causing physical damage to Iranian nuclear enrichment centrifuges. In order to reach Iran's centrifuges, it exploited a vulnerability in the Windows Print Spooler service to gain code execution as NT AUTHORITY\SYSTEM. Due to the hype around this critical vulnerability, we (and probably everyone else) were pretty sure that this attack surface would no longer exist a decade later. We were wrong…
By Peleg Hadar and Tomer Bar
Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#a-decade-after-stuxnets-printer-vulnerability-printing-is-still-the-stairway-to-heaven-19685
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Finding Hidden Login Endpoint Exposing Secret
1 minutes read
[Finding Hidden Login Endpoint Exposing Secret
Client ID](https://medium.com ``````...1 minutes read
Medium
Medium: Read and write stories.
On Medium, anyone can share insightful perspectives, useful knowledge, and life wisdom with the world.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Winja 2021 — Bad API — writeup](https://medium.com/@vinicius-fiorentino/winja
1 minutes read
[Winja 2021 — Bad API — writeup](https://medium.com/@vinicius-fiorentino/winja
```...
1 minutes read
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[What is a man-in-the-middle attack? How MITM attacks work](https://medium.com ``````...
1 minutes read
[What is a man-in-the-middle attack? How MITM attacks work](https://medium.com ``````...
1 minutes read
Medium
Medium: Read and write stories.
On Medium, anyone can share insightful perspectives, useful knowledge, and life wisdom with the world.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Hacking Series Part 16](https://medium.com/@alisyakainth/hacking-series-part- ``````...
1 minutes read
[Hacking Series Part 16](https://medium.com/@alisyakainth/hacking-series-part- ``````...
1 minutes read
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Directory Traversal Zafiyeti](https://medium.com/@erensagdicc/directory-trave ``````...
1 minutes read
[Directory Traversal Zafiyeti](https://medium.com/@erensagdicc/directory-trave ``````...
1 minutes read
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Deep Dive into Cover Protocol’s December 28, 2020 Exploit](https://medium.com
1 minutes read
[Deep Dive into Cover Protocol’s December 28, 2020 Exploit](https://medium.com
```...
1 minutes read
Medium
Medium: Read and write stories.
On Medium, anyone can share insightful perspectives, useful knowledge, and life wisdom with the world.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[HackTheBox Writeup — Passage](https://medium.com/@arkanoidctf/hackthebox-writ ``````...
1 minutes read
[HackTheBox Writeup — Passage](https://medium.com/@arkanoidctf/hackthebox-writ ``````...
1 minutes read
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Gaara 1 : VulnHub : Write-Up](https://medium.com/@ashanperera442a/gaara-1-vul ``````...
1 minutes read
[Gaara 1 : VulnHub : Write-Up](https://medium.com/@ashanperera442a/gaara-1-vul ``````...
1 minutes read
Media is too big
VIEW IN TELEGRAM
Black Hat (Youtube)
An Unauthenticated Journey to Root: Pwning Your Company's Enterprise Software Servers
Often Fortune 1000 companies consist of a plethora of software, hardware, vendors, and solutions all operating to keep the business running and alive. With all this complexity, there is often a single vendor that's common amongst them all: SAP.
SAP's software relationship with the enterprise is well established, often responsible for processing billions of dollars, but with such a vital role in business, what would the impact be if serious flaws were exploited?
By Pablo Artuso and Yvan Genuer
Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#an-unauthenticated-journey-to-root-pwning-your-companys-enterprise-software-servers-19964
An Unauthenticated Journey to Root: Pwning Your Company's Enterprise Software Servers
Often Fortune 1000 companies consist of a plethora of software, hardware, vendors, and solutions all operating to keep the business running and alive. With all this complexity, there is often a single vendor that's common amongst them all: SAP.
SAP's software relationship with the enterprise is well established, often responsible for processing billions of dollars, but with such a vital role in business, what would the impact be if serious flaws were exploited?
By Pablo Artuso and Yvan Genuer
Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#an-unauthenticated-journey-to-root-pwning-your-companys-enterprise-software-servers-19964