Malware News
15.5K subscribers
1.64K photos
7 videos
130 files
8.05K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
RDP to RCE: When Fragmentation Goes Wrong
πŸ—£digicat

why in the world would you use UDP if you needed the data to arrive fully and in the correct order?
πŸ‘€SirensToGo

UDP is a terrible protocol for RDP, it shouldn't even be considered. One wrong bit and you completely fucked up a server.
πŸ‘€magneticphoton

4 ok bye

1 hi UDP

3 i'm good

2 hi how are you

666 kekekekeke
πŸ‘€society2-com


πŸŽ–@malwr
FBI alerts private industry partners: Microsoft SharePoint server exploits were used by nation-state actors to infiltrate two U.S. municipality networks
πŸ—£ThreshingBee

Share point and DoD reluctance to migrate away from share point, back in 2010, is exactly why I left the government.

you don’t have to be a security expert to follow your gut.
πŸ‘€interactionjackson


πŸŽ–@malwr
Reverse Engineering the BMW Connected Apps Protocol
πŸ—£hufman

Cool, tried to reverse the BMW app but couldn't bypass the cert pinning because of limited time. Thanks for the writeup!

EDIT: Okay the post is not about the actual app, still a good reading :)
πŸ‘€0x00xx

awesome work nicely explained!
πŸ‘€sowbener

Very well written and thoroughly explained. Thanks for sharing!
πŸ‘€15charisnoteno


πŸŽ–@malwr
WinFE 10 (Windows Forensic Environment)
WinFE 10 has been released. The WinFE 10 framework is free to download to build your own WinFE 10.

The biggest update is that WinFE now runs in ARM (still runs in Intel x86 and Intel x64). The ARM version includes its own imaging tool. Build WinFE to ISO, CD/DVD, USB flash drive, or USB hard drive.

I've written more about it here: https://www.dfir.training/dfir-training-blog/winfe10

You can download the framework here: https://www.winfe.net/
πŸ—£bshavers

Hi!

I've been using WinFE during searches for a few months (mostly to run X-Ways if I can't remove the hard drive) and I love it. I'm excited to try to image ARM devices next week. Good job!
πŸ‘€TardisDude


πŸŽ–@malwr
SHA-1 is now fully broken
πŸ—£tausciam

I thought got stopped using sha1? Wasn't there a patch for it like a day after the first collision was found?
πŸ‘€crikeydilehunter

does this mean we should just set GPG to use SHA256 by default?

Do we just use the

> --cipher-algo AES256

to encrypt to 256?
πŸ‘€U5efull

Are the git folks working on this at all?
πŸ‘€aaronbp


πŸŽ–@malwr
I'd like to hear from you! On any opinion, question or feedback ping me at @SirMalware

Partner channel: @cveNotify
Malware News pinned Β«I'd like to hear from you! On any opinion, question or feedback ping me at @SirMalware Partner channel: @cveNotifyΒ»