Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Bypassing CSP & Iframe Sandbox in Android Webview
Just published a blog post around why sensitive pages should not be loaded inside a webview - nuckingfoob on android webviews

Have tried to discuss how CSP & iframe sandbox, in a webview, can be bypassed by the underlying app. Critics welcome, feedback appreciated, expert advice would have me humbled.
πŸ—£qre0ct


πŸŽ–@malwr
safe-mail: A Docker service used by analysts to extract and inspect suspicious .MSG, .EML, and documents
Everyone, I would like to introduce a new utility for Security Analysts that I built called safe-mail. You can find the repository here: https://github.com/swimlane/safe-mail


safe-mail is a Docker service used by analysts to upload, extract, and inspect suspicious .MSG, .EML, and documents. safe-mail can be used locally on your workstation or can be deployed for shared (or dedicated) use.

safe-mail has an API and a (limited) UI which allows a user to upload and retrieve artifacts generated by safe-mail.

safe-mail has the following features and functionality:

Message Features

β€’ Upload EML and MSG mail messages as well as Microsoft Office documents themselves
β€’ .MSG mail messages are Microsoft binary email format messages - typically from Microsoft Outlook clients
β€’ Generates a PNG of the message itself named {filename}.png
β€’ Extracts all embedded & attached images/attachments within the email message
β€’ Provides a OCR text file of the generated mail message
β€’ Generates a JSON file representing the mail message headers

Attachment/Document Features

β€’ Extracts attachments of mail messages
β€’ Generates an image & PDF of each attachment
β€’ Attempts to extract any identified Macros within attachments and creates a JSON file representing the Macro code base
β€’ PDF Documents will generate output from pdfid & pdfparser  tools
β€’ ZIP attachments will extract the zip and return any files within the zip

Enjoy! I hope this helps you all on a daily basis!
πŸ—£[
Unas](https://www.reddit.com/r/blueteamsec/comments/ftynlo/safemailadockerserviceusedbyanalyststo/)


πŸŽ–@malwr
I discovered a vulnerability in Safari that allowed unauthorized websites to access your camera on iOS and macOS
πŸ—£ga-vu

Nice write up and it's cool to see the Apple program finally paying out bounties to non-blessed researchers!
πŸ‘€SirensToGo

Nice
πŸ‘€morrislesterszyslak

And this is why I use an adblocker. Though recently, I have stepped up my game with a PiHole as well.
πŸ‘€thatvhstapeguy


πŸŽ–@malwr
Common Ports to Remember (credits: packetlife.net)
πŸ—£ATTACKERSA

This very same printout follows me from desk-to-desk. Very good reference point to the not-so-easy-to-remember ports.
πŸ‘€native_rooted

All u need to know is 20,22,21,25,389,3389,80,53
πŸ‘€Calvimn

What about WhatsApp?
πŸ‘€wthinastix


πŸŽ–@malwr