New Advisory: Find out how a vulnerability in DD-WRT allows an unauthenticated attacker to overflow an internal buffer used by UPNP and trigger a code execution vulnerability
🗣SSDisclosure
🎖@malwr
🗣SSDisclosure
🎖@malwr
SSD Secure Disclosure
SSD Advisory – DD-WRT UPNP Buffer Overflow - SSD Secure Disclosure
TL;DR Find out how a vulnerability in DD-WRT allows an unauthenticated attacker to overflow an internal buffer used by UPNP and trigger a code execution vulnerability. Vulnerability Summary DD-WRT is “is Linux-based firmware for wireless routers and access…
Old School RuneScape Steam version - Finding all things 3D
🗣alcohol_enthusiast_
Awesome series! Regarding part 2, is there any benefit to reimplementing the w2s function rather than calling the function with 3d coordinates directly? Or are you just doing it like this since you're not injected into the game?
Also, are you using Ghidra in the screenshot where you find what references are writing to the text pos arrays?
Thanks for the great content!
👤micaww
Part 3 of my series. It refers back to the older posts a lot so feel free to read them all if you got the time, it's a long series though!
👤alcohol_enthusiast_
🎖@malwr
🗣alcohol_enthusiast_
Awesome series! Regarding part 2, is there any benefit to reimplementing the w2s function rather than calling the function with 3d coordinates directly? Or are you just doing it like this since you're not injected into the game?
Also, are you using Ghidra in the screenshot where you find what references are writing to the text pos arrays?
Thanks for the great content!
👤micaww
Part 3 of my series. It refers back to the older posts a lot so feel free to read them all if you got the time, it's a long series though!
👤alcohol_enthusiast_
🎖@malwr
Analyzing And Micropatching CVE-2021-26897
🗣m2r3t1
would be interesting to know how many users this service has...
👤tansim
🎖@malwr
🗣m2r3t1
would be interesting to know how many users this service has...
👤tansim
🎖@malwr
0Patch
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897)
by Mitja Kolsek, the 0patch Team March 2021 Windows Updates included fixes for seven vulnerabilities in Windows DNS Server, two of which w...
Introduction to format string vulnerabilities - Introduction to Binary Exploitation - Hack The Box Leet Test
🗣PinkDraconian
🎖@malwr
🗣PinkDraconian
🎖@malwr
YouTube
Hack The Box - Introduction to Binary Exploitation - Leet Test - Format Strings [Walkthrough]
▶️ YouTube: https://www.youtube.com/c/PinkDraconian
🎁 Patreon: https://www.patreon.com/PinkDraconian
🐦 Twitter: https://twitter.com/PinkDraconian
🎵 TikTok: https://www.tiktok.com/@pinkdraconian
ℹ️ LinkedIn: https://www.linkedin.com/in/robbe-van-roey-365666195/…
🎁 Patreon: https://www.patreon.com/PinkDraconian
🐦 Twitter: https://twitter.com/PinkDraconian
🎵 TikTok: https://www.tiktok.com/@pinkdraconian
ℹ️ LinkedIn: https://www.linkedin.com/in/robbe-van-roey-365666195/…
Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks - F-Secure Blog
🗣c0r3dump3d
🎖@malwr
🗣c0r3dump3d
🎖@malwr
F-Secure Blog
Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks - F-Secure Blog
Data-stealing ransomware attacks, information harvesting malware, and supply chain attacks are some of the critical threats facing organizations highlighted in F-Secure’s latest attack landscape update. According to the report, a new type of extortion researchers…
Cheating the cheater: How adversaries are using backdoored video game cheat engines and modding tools
🗣malware_bender
🎖@malwr
🗣malware_bender
🎖@malwr
Cisco Talos
Cheating the cheater: How adversaries are using backdoored video game cheat engines and modding tools
By Nick Lister and Holger Unterbrink, with contributions from Vanja Svajcer. News summary * Cisco Talos recently discovered a new campaign targeting video game players and other PC modders. * Talos detected a new cryptor used in several different malware…
Exfiltrate files using the DNS
🗣w8rbt
In reality, how would this be protected against? I'm still nub when it comes to the net sec side of this business. Would using a limited private recursive server that prevented lookups for any but a whitelist be the most secure? Not all DNS servers will respond with the complete zone file to allow for the recursive server to do the lookup so that doesn't seem like a viable option.
👤notdedicated
For additional information and practical application, you can refer to the TryHackMe Room - DNS Manipulation
For information on a likely hijacked reddit account, you can refer to w8rbt's profile which was registered 6 years ago yet only started posting 2 months ago, and has posted nothing aside from article promotion.
👤Reelix
So as long as enclave rule sets are defined specifically to only allow the DNS port to appropriate upstream DNS, this would fail.
👤Jon2109
🎖@malwr
🗣w8rbt
In reality, how would this be protected against? I'm still nub when it comes to the net sec side of this business. Would using a limited private recursive server that prevented lookups for any but a whitelist be the most secure? Not all DNS servers will respond with the complete zone file to allow for the recursive server to do the lookup so that doesn't seem like a viable option.
👤notdedicated
For additional information and practical application, you can refer to the TryHackMe Room - DNS Manipulation
For information on a likely hijacked reddit account, you can refer to w8rbt's profile which was registered 6 years ago yet only started posting 2 months ago, and has posted nothing aside from article promotion.
👤Reelix
So as long as enclave rule sets are defined specifically to only allow the DNS port to appropriate upstream DNS, this would fail.
👤Jon2109
🎖@malwr
Go350
Exfiltrate files using the DNS
yes you can
FAST FLUX
https://www.blueliv.com/cyber-security-and-cyber-threat-intelligence-blog-blueliv/fast-flux/
ℹ️ Sent from one of our members
🎖@malwr
https://www.blueliv.com/cyber-security-and-cyber-threat-intelligence-blog-blueliv/fast-flux/
ℹ️ Sent from one of our members
🎖@malwr
Outpost24
Fast flux | Outpost 24 blog
In this post we want to share details about a study that we have carried out on a Fast Flux network operated by the creators of the Ursnif malware. Our main objective is to shed some light on this type of network and what kind of activities are developed…
Investigating a unique "form" of email delivery for IcedID malware - Microsoft Security
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
Microsoft Security Blog
Investigating a unique "form" of email delivery for IcedID malware | Microsoft Security Blog
Microsoft threat analysts have been tracking activity where contact forms published on websites are abused to deliver malicious links to enterprises using emails with fake legal threats. The emails instruct recipients to click a link to review supposed evidence…
Justice Department Announces Court-Authorized Effort to Disrupt Exploitation of Microsoft Exchange Server Vulnerabilities | OPA
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
www.justice.gov
Justice Department Announces Court-Authorized Effort to Disrupt
The Justice Department today announced a court-authorized operation to copy and remove malicious web shells from hundreds of vulnerable computers in the United States running on-premises versions of Microsoft Exchange Server, software used to provide enterprise…
Exploit for pwn2own Chrome zeroday released by third party researcher
🗣digicat
this is a patch gap risk..
👤digicat
🎖@malwr
🗣digicat
this is a patch gap risk..
👤digicat
🎖@malwr
[Video Makop Ransomware - Decrypting the Encrypted Section](https://youtu.be/mlIRoGrxrmA)
🗣Struppigel
Cool stuff. Thanks for the info and please post more!
👤skully_kiddo
🎖@malwr
🗣Struppigel
Cool stuff. Thanks for the info and please post more!
👤skully_kiddo
🎖@malwr
YouTube
Makop Ransomware - Decrypting the Encrypted Section
SHA256: bc0ed3e73b8d1fdc839f2e8ed3578ca3221dba4eb984e581cb00dfb4cdfb7d49
Complete Malware Analysis VM Image
Complete Malware Analysis VM Image
is there a complate malware analysis vm image that contains most of the decompilers, PE analysers, debuggers, monitoring tools, etc..
thanks!!
p.s. i know that there is flare VM that is free to install but it seems not complete.
🗣darkalimdor18
There’s no “complete” and “most perfect” image, new tools and plugins are published every day and no one can keep up with them all.
You should be able to customize your own image based on your own needs and most importantly skills, there’s no need to downloaded tons of tools and you barely know anything about most of them.
👤MO12400
I would do two things: install something like Remnux and use it as a “wall”. Then install something like Flare to start learning what you like. Eventually either tweak it to your liking, or build an image with your own stuff. Knowing how to install it and configure it is invaluable knowledge. Plus you can then learn other apps to auto-build VMs of your choice with customizations you need for types of malware you are analyzing.
Route all traffic through Remnux. You can then drop traffic outbound but still capture traffic, use Burpe Suite and other tools to dynamically identify C2 and communications safely.
👤FlaccidKraken
Yeah I second REMnux, it’s native Linux but there’s also a Windows version if you can find someone who has taken the GREM. The Windows one is called REMnux Workstation.
👤Th3_Pr0f3ss0r
🎖@malwr
Complete Malware Analysis VM Image
is there a complate malware analysis vm image that contains most of the decompilers, PE analysers, debuggers, monitoring tools, etc..
thanks!!
p.s. i know that there is flare VM that is free to install but it seems not complete.
🗣darkalimdor18
There’s no “complete” and “most perfect” image, new tools and plugins are published every day and no one can keep up with them all.
You should be able to customize your own image based on your own needs and most importantly skills, there’s no need to downloaded tons of tools and you barely know anything about most of them.
👤MO12400
I would do two things: install something like Remnux and use it as a “wall”. Then install something like Flare to start learning what you like. Eventually either tweak it to your liking, or build an image with your own stuff. Knowing how to install it and configure it is invaluable knowledge. Plus you can then learn other apps to auto-build VMs of your choice with customizations you need for types of malware you are analyzing.
Route all traffic through Remnux. You can then drop traffic outbound but still capture traffic, use Burpe Suite and other tools to dynamically identify C2 and communications safely.
👤FlaccidKraken
Yeah I second REMnux, it’s native Linux but there’s also a Windows version if you can find someone who has taken the GREM. The Windows one is called REMnux Workstation.
👤Th3_Pr0f3ss0r
🎖@malwr
reddit
Complete Malware Analysis VM Image
**Complete Malware Analysis VM Image** is there a complate malware analysis vm image that contains most of the decompilers, PE analysers,...