Taking Action Against Hackers in Palestine - Facebook
๐ฃdarronofsky
And hereby a more detailed report on one of the groups they tracked, named Arid Viper: https://about.fb.com/wp-content/uploads/2021/04/Technical-threat-report-Arid-Viper-April-2021.pdf
๐คdarronofsky
๐@malwr
๐ฃdarronofsky
And hereby a more detailed report on one of the groups they tracked, named Arid Viper: https://about.fb.com/wp-content/uploads/2021/04/Technical-threat-report-Arid-Viper-April-2021.pdf
๐คdarronofsky
๐@malwr
Meta Newsroom
Taking Action Against Hackers in Palestine
Weโre sharing actions we took against two separate groups of hackers โ removing their ability to abuse our platform, distribute malware and hack peopleโs accounts across the internet.
.E01 (bootable) converted to .VMDK with Virtual Box was successful, however the bootup sits on this screen and Im not sure could be keeping it from finishing a boot up of Windows. The VM spec is about 26GB RAM, dynamic sizing, and the E01 was a functioning Win machine. Why wont it finish booting?
๐ฃmattisha
I feel like you are doing too many steps. As others have said, use Arsenal or even FTK Imager. Mount the E01 as a Physical Disk. Then using VMWare or Hyper-V just make a new VM, and the only disk you should add is this new PhysicalDisk. The most important thing is matching BIOS or UEFI of the host, that's really about it. If it's Windows 10 it should fix itself and boot.
Or, just pay for Arsenal and it will boot a VM in one click and bypass the bitlocker and lock screen for ya. Def worth it.
๐คFunkeDope
We usually mount the E01 using Arsenal Image Mounter and create a VM with VMware giving the mounted physical drive as VM hdd.
๐คwalker1993
I've never had success with this method...I always just restore the image to another disk.
๐คkstewart0x00
๐@malwr
๐ฃmattisha
I feel like you are doing too many steps. As others have said, use Arsenal or even FTK Imager. Mount the E01 as a Physical Disk. Then using VMWare or Hyper-V just make a new VM, and the only disk you should add is this new PhysicalDisk. The most important thing is matching BIOS or UEFI of the host, that's really about it. If it's Windows 10 it should fix itself and boot.
Or, just pay for Arsenal and it will boot a VM in one click and bypass the bitlocker and lock screen for ya. Def worth it.
๐คFunkeDope
We usually mount the E01 using Arsenal Image Mounter and create a VM with VMware giving the mounted physical drive as VM hdd.
๐คwalker1993
I've never had success with this method...I always just restore the image to another disk.
๐คkstewart0x00
๐@malwr
I built a free tool to assess IT security risks, objectively, unbiased and visually presented. It is specially targeted at SME's who don't have the resources for deep dives but want an overview of their risk landscape. Would love your feedback.
๐ฃZhongTr0n
What's the outcome you're looking for? Mostly practice creating an app? UI looks good. Could be useful for bootstrapped startups.
Looking to make a profit? Eventually a bootstrapped startup will lose business if they don't have a SOC2, and they'll leverage something like Vanta to make it easier. Long way to go to reach feature parity with Vanta. Check out the book Zero to One by Peter Theil.
๐คericalexander303
I'll be trying this out today.
๐คwormhole360
You can check it out for free on https://riskbull.app . I've worked for 10 months on this tool with u/CoolingSoup and incorporated reddit feedback from previous versions. It assesses your IT security risk based on a survey and a rule engine based on ISO2700x.
The idea is to help people without sufficient in-house infosec expertise get an overview of their risk landscape.This is still an early version, as many other features and insights will be added later.
Currently it is not mobile friendly,
Would love your feedback.
๐คZhongTr0n
๐@malwr
๐ฃZhongTr0n
What's the outcome you're looking for? Mostly practice creating an app? UI looks good. Could be useful for bootstrapped startups.
Looking to make a profit? Eventually a bootstrapped startup will lose business if they don't have a SOC2, and they'll leverage something like Vanta to make it easier. Long way to go to reach feature parity with Vanta. Check out the book Zero to One by Peter Theil.
๐คericalexander303
I'll be trying this out today.
๐คwormhole360
You can check it out for free on https://riskbull.app . I've worked for 10 months on this tool with u/CoolingSoup and incorporated reddit feedback from previous versions. It assesses your IT security risk based on a survey and a rule engine based on ISO2700x.
The idea is to help people without sufficient in-house infosec expertise get an overview of their risk landscape.This is still an early version, as many other features and insights will be added later.
Currently it is not mobile friendly,
Would love your feedback.
๐คZhongTr0n
๐@malwr
CVE-2021-20226: A reference-counting bug in the Linux kernel io_uring subsystem that can be leveraged for local privilege escalation
๐ฃRedmondSecGnome
๐@malwr
๐ฃRedmondSecGnome
๐@malwr
Zero Day Initiative
Zero Day Initiative โ CVE-2021-20226: A Reference-Counting Bug in the Linux Kernel io_uring Subsystem
Conclusion New features mean new attack surfaces, and new attack surfaces often lead to new bugs being discovered. It will be interesting to see if any other vulnerabilities are found in this subsystem. Regardless, it was a great find by Ryota, and we appreciateโฆ
Dutch government release a Windows event logging and collection baseline focused on finding balance between forensic value and optimising retention.
๐ฃdigicat
๐@malwr
๐ฃdigicat
๐@malwr
GitHub
GitHub - JSCU-NL/logging-essentials: A Windows event logging and collection baseline focused on finding balance between forensicโฆ
A Windows event logging and collection baseline focused on finding balance between forensic value and optimising retention. - JSCU-NL/logging-essentials
Avaddon RaaS | Breaks Public Decryptor, Continues On Rampage
๐ฃdarronofsky
Honestly I always wonder what type of software these people could make to benefit the world. Instead they are forced to make this type of software due to where they live.
A beautiful front end on the .Onion? Hell Iโd love at least 1 of my vendors to make a usable front end for my tool sets that didnโt suck.
๐คredvelvet92
๐@malwr
๐ฃdarronofsky
Honestly I always wonder what type of software these people could make to benefit the world. Instead they are forced to make this type of software due to where they live.
A beautiful front end on the .Onion? Hell Iโd love at least 1 of my vendors to make a usable front end for my tool sets that didnโt suck.
๐คredvelvet92
๐@malwr
SentinelOne
Avaddon RaaS | Breaks Public Decryptor, Continues On Rampage - SentinelLabs
Unbreakable encryption, a data leak site and threats of DDoS attacks, Avaddon has all the tricks of a modern RaaS. And now version 2 is on the way.
An Undersea Royal Road: Exploring Malicious Documents and Associated Malware
๐ฃdarronofsky
๐@malwr
๐ฃdarronofsky
๐@malwr
DomainTools | Start Here. Know Now.
An Undersea Royal Road: Exploring Malicious Documents and Associated Malware - DomainTools | Start Here. Know Now.
DomainTools researchers have identified a phishing campaign targeting underwater research and weapon development organizations in the Russian Federation.
What is SELinux exactly and what networking ports or protocols rely on it?
Hi,
What is SELinux exactly? My understanding was that it was a security module in Linux responsible for hardening the system kernel.
Also, what networking ports or protocols rely on it?
Thanks
๐ฃsecurm0n
I discovered this video while taking a class on Linux. https://www.youtube.com/watch?v=JFjXvIwAeVI It's really great about explaining the concepts you're researching and the speaker's other videos are honestly life changing.
๐คcorbanmonoxide
So you know how Linux has discretionary access control (DAC)? For example User: root has access to user: rootโs files. group: securmon has access to any files that belong to group: securmon. Itโs kinda like that but itโs called media access control (MAC) and uses labels to isolate and limit processes. Itโs a labeling system that dictates what process can interact with each other. Iโm applying a label to allow My process: X to interact with my other process: Y. For example if someone finds an exploit for a process youโre running (like your web server: Apache), they wonโt be able to access other resources (like your ftp server) unless you apply the label that says that it can. This video series, although dated, does a really good job of explaining it:
https://youtube.com/playlist?list=PLXEcKYHTGBdRyWWz8rqP9rYtMvS4VqlRR
Anyone feel free to jump in and expand on my input.
๐คMrLexDiamondz
Google is your friend: https://www.redhat.com/en/topics/linux/what-is-selinux
๐คSo0ver1t83
๐@malwr
Hi,
What is SELinux exactly? My understanding was that it was a security module in Linux responsible for hardening the system kernel.
Also, what networking ports or protocols rely on it?
Thanks
๐ฃsecurm0n
I discovered this video while taking a class on Linux. https://www.youtube.com/watch?v=JFjXvIwAeVI It's really great about explaining the concepts you're researching and the speaker's other videos are honestly life changing.
๐คcorbanmonoxide
So you know how Linux has discretionary access control (DAC)? For example User: root has access to user: rootโs files. group: securmon has access to any files that belong to group: securmon. Itโs kinda like that but itโs called media access control (MAC) and uses labels to isolate and limit processes. Itโs a labeling system that dictates what process can interact with each other. Iโm applying a label to allow My process: X to interact with my other process: Y. For example if someone finds an exploit for a process youโre running (like your web server: Apache), they wonโt be able to access other resources (like your ftp server) unless you apply the label that says that it can. This video series, although dated, does a really good job of explaining it:
https://youtube.com/playlist?list=PLXEcKYHTGBdRyWWz8rqP9rYtMvS4VqlRR
Anyone feel free to jump in and expand on my input.
๐คMrLexDiamondz
Google is your friend: https://www.redhat.com/en/topics/linux/what-is-selinux
๐คSo0ver1t83
๐@malwr
Reddit
From the netsecstudents community on Reddit
Explore this post and more from the netsecstudents community