Analyzing And Micropatching CVE-2021-26897
🗣m2r3t1
would be interesting to know how many users this service has...
👤tansim
🎖@malwr
🗣m2r3t1
would be interesting to know how many users this service has...
👤tansim
🎖@malwr
0Patch
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897)
by Mitja Kolsek, the 0patch Team March 2021 Windows Updates included fixes for seven vulnerabilities in Windows DNS Server, two of which w...
Introduction to format string vulnerabilities - Introduction to Binary Exploitation - Hack The Box Leet Test
🗣PinkDraconian
🎖@malwr
🗣PinkDraconian
🎖@malwr
YouTube
Hack The Box - Introduction to Binary Exploitation - Leet Test - Format Strings [Walkthrough]
▶️ YouTube: https://www.youtube.com/c/PinkDraconian
🎁 Patreon: https://www.patreon.com/PinkDraconian
🐦 Twitter: https://twitter.com/PinkDraconian
🎵 TikTok: https://www.tiktok.com/@pinkdraconian
ℹ️ LinkedIn: https://www.linkedin.com/in/robbe-van-roey-365666195/…
🎁 Patreon: https://www.patreon.com/PinkDraconian
🐦 Twitter: https://twitter.com/PinkDraconian
🎵 TikTok: https://www.tiktok.com/@pinkdraconian
ℹ️ LinkedIn: https://www.linkedin.com/in/robbe-van-roey-365666195/…
Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks - F-Secure Blog
🗣c0r3dump3d
🎖@malwr
🗣c0r3dump3d
🎖@malwr
F-Secure Blog
Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks - F-Secure Blog
Data-stealing ransomware attacks, information harvesting malware, and supply chain attacks are some of the critical threats facing organizations highlighted in F-Secure’s latest attack landscape update. According to the report, a new type of extortion researchers…
Cheating the cheater: How adversaries are using backdoored video game cheat engines and modding tools
🗣malware_bender
🎖@malwr
🗣malware_bender
🎖@malwr
Cisco Talos
Cheating the cheater: How adversaries are using backdoored video game cheat engines and modding tools
By Nick Lister and Holger Unterbrink, with contributions from Vanja Svajcer. News summary * Cisco Talos recently discovered a new campaign targeting video game players and other PC modders. * Talos detected a new cryptor used in several different malware…
Exfiltrate files using the DNS
🗣w8rbt
In reality, how would this be protected against? I'm still nub when it comes to the net sec side of this business. Would using a limited private recursive server that prevented lookups for any but a whitelist be the most secure? Not all DNS servers will respond with the complete zone file to allow for the recursive server to do the lookup so that doesn't seem like a viable option.
👤notdedicated
For additional information and practical application, you can refer to the TryHackMe Room - DNS Manipulation
For information on a likely hijacked reddit account, you can refer to w8rbt's profile which was registered 6 years ago yet only started posting 2 months ago, and has posted nothing aside from article promotion.
👤Reelix
So as long as enclave rule sets are defined specifically to only allow the DNS port to appropriate upstream DNS, this would fail.
👤Jon2109
🎖@malwr
🗣w8rbt
In reality, how would this be protected against? I'm still nub when it comes to the net sec side of this business. Would using a limited private recursive server that prevented lookups for any but a whitelist be the most secure? Not all DNS servers will respond with the complete zone file to allow for the recursive server to do the lookup so that doesn't seem like a viable option.
👤notdedicated
For additional information and practical application, you can refer to the TryHackMe Room - DNS Manipulation
For information on a likely hijacked reddit account, you can refer to w8rbt's profile which was registered 6 years ago yet only started posting 2 months ago, and has posted nothing aside from article promotion.
👤Reelix
So as long as enclave rule sets are defined specifically to only allow the DNS port to appropriate upstream DNS, this would fail.
👤Jon2109
🎖@malwr
Go350
Exfiltrate files using the DNS
yes you can
FAST FLUX
https://www.blueliv.com/cyber-security-and-cyber-threat-intelligence-blog-blueliv/fast-flux/
ℹ️ Sent from one of our members
🎖@malwr
https://www.blueliv.com/cyber-security-and-cyber-threat-intelligence-blog-blueliv/fast-flux/
ℹ️ Sent from one of our members
🎖@malwr
Outpost24
Fast flux | Outpost 24 blog
In this post we want to share details about a study that we have carried out on a Fast Flux network operated by the creators of the Ursnif malware. Our main objective is to shed some light on this type of network and what kind of activities are developed…
Investigating a unique "form" of email delivery for IcedID malware - Microsoft Security
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
Microsoft Security Blog
Investigating a unique "form" of email delivery for IcedID malware | Microsoft Security Blog
Microsoft threat analysts have been tracking activity where contact forms published on websites are abused to deliver malicious links to enterprises using emails with fake legal threats. The emails instruct recipients to click a link to review supposed evidence…
Justice Department Announces Court-Authorized Effort to Disrupt Exploitation of Microsoft Exchange Server Vulnerabilities | OPA
🗣digicat
🎖@malwr
🗣digicat
🎖@malwr
www.justice.gov
Justice Department Announces Court-Authorized Effort to Disrupt
The Justice Department today announced a court-authorized operation to copy and remove malicious web shells from hundreds of vulnerable computers in the United States running on-premises versions of Microsoft Exchange Server, software used to provide enterprise…
Exploit for pwn2own Chrome zeroday released by third party researcher
🗣digicat
this is a patch gap risk..
👤digicat
🎖@malwr
🗣digicat
this is a patch gap risk..
👤digicat
🎖@malwr
[Video Makop Ransomware - Decrypting the Encrypted Section](https://youtu.be/mlIRoGrxrmA)
🗣Struppigel
Cool stuff. Thanks for the info and please post more!
👤skully_kiddo
🎖@malwr
🗣Struppigel
Cool stuff. Thanks for the info and please post more!
👤skully_kiddo
🎖@malwr
YouTube
Makop Ransomware - Decrypting the Encrypted Section
SHA256: bc0ed3e73b8d1fdc839f2e8ed3578ca3221dba4eb984e581cb00dfb4cdfb7d49
Complete Malware Analysis VM Image
Complete Malware Analysis VM Image
is there a complate malware analysis vm image that contains most of the decompilers, PE analysers, debuggers, monitoring tools, etc..
thanks!!
p.s. i know that there is flare VM that is free to install but it seems not complete.
🗣darkalimdor18
There’s no “complete” and “most perfect” image, new tools and plugins are published every day and no one can keep up with them all.
You should be able to customize your own image based on your own needs and most importantly skills, there’s no need to downloaded tons of tools and you barely know anything about most of them.
👤MO12400
I would do two things: install something like Remnux and use it as a “wall”. Then install something like Flare to start learning what you like. Eventually either tweak it to your liking, or build an image with your own stuff. Knowing how to install it and configure it is invaluable knowledge. Plus you can then learn other apps to auto-build VMs of your choice with customizations you need for types of malware you are analyzing.
Route all traffic through Remnux. You can then drop traffic outbound but still capture traffic, use Burpe Suite and other tools to dynamically identify C2 and communications safely.
👤FlaccidKraken
Yeah I second REMnux, it’s native Linux but there’s also a Windows version if you can find someone who has taken the GREM. The Windows one is called REMnux Workstation.
👤Th3_Pr0f3ss0r
🎖@malwr
Complete Malware Analysis VM Image
is there a complate malware analysis vm image that contains most of the decompilers, PE analysers, debuggers, monitoring tools, etc..
thanks!!
p.s. i know that there is flare VM that is free to install but it seems not complete.
🗣darkalimdor18
There’s no “complete” and “most perfect” image, new tools and plugins are published every day and no one can keep up with them all.
You should be able to customize your own image based on your own needs and most importantly skills, there’s no need to downloaded tons of tools and you barely know anything about most of them.
👤MO12400
I would do two things: install something like Remnux and use it as a “wall”. Then install something like Flare to start learning what you like. Eventually either tweak it to your liking, or build an image with your own stuff. Knowing how to install it and configure it is invaluable knowledge. Plus you can then learn other apps to auto-build VMs of your choice with customizations you need for types of malware you are analyzing.
Route all traffic through Remnux. You can then drop traffic outbound but still capture traffic, use Burpe Suite and other tools to dynamically identify C2 and communications safely.
👤FlaccidKraken
Yeah I second REMnux, it’s native Linux but there’s also a Windows version if you can find someone who has taken the GREM. The Windows one is called REMnux Workstation.
👤Th3_Pr0f3ss0r
🎖@malwr
reddit
Complete Malware Analysis VM Image
**Complete Malware Analysis VM Image** is there a complate malware analysis vm image that contains most of the decompilers, PE analysers,...
Open Source Archive of Legal Threats Made Against Genuine Security Researchers (Creative Commons!)
🗣docker-osx
Add Steam to that list for the recent issue brought up.
👤drimgere
Let this be a wakeup call to everyone to always keep in mind that companies can and might screw you over despite your good intentions and protect yourselves accordingly.
👤267aa37673a9fa659490
This list has to be taken with a huge grain of salt as researcher sometimes try to paint themselves in a much nicer way that what really happened. The Skytech entry is a pretty example of this as I know a little bit the inside of it. The "researcher" received threat from the company not because he disclosed a vulnerability, but because he DoSed the company system from the Dawson network connection. The fact that he disclosed a vulnerability before had nothing to do with the threat he received. Also a lot of the threat he received where not from Skytech, but from Dawson. The reason ? He continued to "test" the school internal system (that didn't belong to Skytech) after being told to stop.
👤Cold-Mix357
🎖@malwr
🗣docker-osx
Add Steam to that list for the recent issue brought up.
👤drimgere
Let this be a wakeup call to everyone to always keep in mind that companies can and might screw you over despite your good intentions and protect yourselves accordingly.
👤267aa37673a9fa659490
This list has to be taken with a huge grain of salt as researcher sometimes try to paint themselves in a much nicer way that what really happened. The Skytech entry is a pretty example of this as I know a little bit the inside of it. The "researcher" received threat from the company not because he disclosed a vulnerability, but because he DoSed the company system from the Dawson network connection. The fact that he disclosed a vulnerability before had nothing to do with the threat he received. Also a lot of the threat he received where not from Skytech, but from Dawson. The reason ? He continued to "test" the school internal system (that didn't belong to Skytech) after being told to stop.
👤Cold-Mix357
🎖@malwr
GitHub
GitHub - disclose/research-threats: Collection of legal threats against good faith Security Researchers; vulnerability disclosure…
Collection of legal threats against good faith Security Researchers; vulnerability disclosure gone wrong. A continuation of work started by @attritionorg - disclose/research-threats