Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Signal: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective
πŸ—£qw1ks1lv3r

Moxie rocking?
πŸ‘€mepher

I value privacy as much as the next guy, but this post and the previous one the author links to both come off as kind of immature. I get it that Cellebrite is a shady company, but publicly insulting them is quite unprofessional. "Amateur hour" may not look good for Cellebrite, but it sure doesn't look good for Signal either.
πŸ‘€IndependenceNo7975

that last paragraph...
πŸ‘€hacksauce


πŸŽ–@malwr
.E01 (bootable) converted to .VMDK with Virtual Box was successful, however the bootup sits on this screen and Im not sure could be keeping it from finishing a boot up of Windows. The VM spec is about 26GB RAM, dynamic sizing, and the E01 was a functioning Win machine. Why wont it finish booting?
πŸ—£mattisha

I feel like you are doing too many steps. As others have said, use Arsenal or even FTK Imager. Mount the E01 as a Physical Disk. Then using VMWare or Hyper-V just make a new VM, and the only disk you should add is this new PhysicalDisk. The most important thing is matching BIOS or UEFI of the host, that's really about it. If it's Windows 10 it should fix itself and boot.

Or, just pay for Arsenal and it will boot a VM in one click and bypass the bitlocker and lock screen for ya. Def worth it.
πŸ‘€FunkeDope

We usually mount the E01 using Arsenal Image Mounter and create a VM with VMware giving the mounted physical drive as VM hdd.
πŸ‘€walker1993

I've never had success with this method...I always just restore the image to another disk.
πŸ‘€kstewart0x00


πŸŽ–@malwr
I built a free tool to assess IT security risks, objectively, unbiased and visually presented. It is specially targeted at SME's who don't have the resources for deep dives but want an overview of their risk landscape. Would love your feedback.
πŸ—£ZhongTr0n

What's the outcome you're looking for? Mostly practice creating an app? UI looks good. Could be useful for bootstrapped startups.


Looking to make a profit? Eventually a bootstrapped startup will lose business if they don't have a SOC2, and they'll leverage something like Vanta to make it easier. Long way to go to reach feature parity with Vanta. Check out the book Zero to One by Peter Theil.
πŸ‘€ericalexander303

I'll be trying this out today.
πŸ‘€wormhole360

You can check it out for free on https://riskbull.app . I've worked for 10 months on this tool with u/CoolingSoup and incorporated reddit feedback from previous versions. It assesses your IT security risk based on a survey and a rule engine based on ISO2700x.

The idea is to help people without sufficient in-house infosec expertise get an overview of their risk landscape.This is still an early version, as many other features and insights will be added later.

Currently it is not mobile friendly,

Would love your feedback.
πŸ‘€ZhongTr0n


πŸŽ–@malwr
Avaddon RaaS | Breaks Public Decryptor, Continues On Rampage
πŸ—£darronofsky

Honestly I always wonder what type of software these people could make to benefit the world. Instead they are forced to make this type of software due to where they live.

A beautiful front end on the .Onion? Hell I’d love at least 1 of my vendors to make a usable front end for my tool sets that didn’t suck.
πŸ‘€redvelvet92


πŸŽ–@malwr