Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Extracting Prefetch from Memory
Good morning,


Iโ€™ve just released a new Introduction to Memory Forensics episode. This is an excerpt from the upcoming premiere of a new 13Cubed series called Deep Dives. We'll take a look at how to extract Windows Prefetch data from memory. There are a number of things you'll need to know to get the Volatility prefetchparser plugin to work correctly, especially with Windows 10 Prefetch files since they are compressed. We'll walk through the entire process, including installation of Volatility, the prefetchparser plugin, and of an open source implementation of the Microsoft compression algorithms.

Episode:
https://www.youtube.com/watch?v=6y9Wxch7NKk

Episode Guide:
https://www.13cubed.com/episodes

Channel:
https://www.youtube.com/13cubed

Patreon (Help support 13Cubed):
https://www.patreon.com/13cubed
๐Ÿ—ฃ13Cubed


๐ŸŽ–@malwr
How We Found Another XSS in Google with Acunetix
Some time ago, Russian security researchers Andrey Leonov and Link found an XSS in Google Cloud with the help of Acunetix. Recently they found another XSS vulnerability. Here is how it happened. Read on ยป



https://preview.redd.it/8k5mfavrfnh41.png?width=910&format=png&auto=webp&s=9f163a59304f45574a3b17b591d48170411d1926
๐Ÿ—ฃAcunetixLtd


๐ŸŽ–@malwr
Purpose of `mov edi, edi`?
I was debugging a Windows' built in program and notices that almost all subroutines starts with mov edi, edi. e.g.

subsomething proc near
mov edi, edi
push ebp
mov ebp, esp
;do something...
leave
retn
sub
something endp

AFAIU, that mov edi, edi practically does nothing and affect nothing, and it only wastes space and computing time.

It seems like it's specific to Microsoft based C language compiled modules, cause I also use Delphi to create Windows programs, and none of their functions has such asm code pattern.

So, what's the purpose of that instruction?
๐Ÿ—ฃjcunews1

It's a nop. It's there for patching. Intel doesn't actually have formal nop instructions! For nops people often write xchg eax, eax, or something like this if they want a longer nop.
๐Ÿ‘คchrisgseaton

It's a no-op, on purpose, that can be overwritten.

Raymond Chen explains it, here: https://devblogs.microsoft.com/oldnewthing/20110921-00/?p=9583
๐Ÿ‘คchunkyks

https://devblogs.microsoft.com/oldnewthing/20110921-00/?p=9583
๐Ÿ‘คjedwardsol


๐ŸŽ–@malwr
SonicWall SRA and SMA vulnerabilties
๐Ÿ—ฃcyberg0100


๐ŸŽ–@malwr