New research! Unpacking CVE-2021-40444: A Deep Technical Analysis of an Office RCE Exploit
https://billdemirkapi.me/unpacking-cve-2021-40444-microsoft-office-rce
π£BillDemirkapi
π@malwr
https://billdemirkapi.me/unpacking-cve-2021-40444-microsoft-office-rce
π£BillDemirkapi
π@malwr
Bill Demirkapi's Blog
Unpacking CVE-2021-40444: A Deep Technical Analysis of an Office RCE Exploit
In the middle of August 2021, a special Word document was uploaded to VirusTotal by a user from Argentina. Although it was only detected by a single antivirus engine at the time, this sample turned out to be exploiting a zero day vulnerability in Microsoftβ¦
Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.
https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
#hacking #graphql #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
#hacking #graphql #cybersecurity #bughunting
π£0xAsm0d3us
π@malwr
(I know many do this) If you're jamming on YARA locally, I recommend using VS Code & the awesome YARA extension which helps do syntax stuff, highlighting and more. Then use the integrated terminal to test and tweak your rules. Super fun.
#100DaysofYARA
https://marketplace.visualstudio.com/items?itemName=infosec-intern.yara
π£stvemillertime
π@malwr
#100DaysofYARA
https://marketplace.visualstudio.com/items?itemName=infosec-intern.yara
π£stvemillertime
π@malwr
Rook Ransomware https://chuongdong.com/reverse%20engineering/2022/01/06/RookRansomware/
π£ptracesecurity
π@malwr
π£ptracesecurity
π@malwr
MalAPIReader: Python-enabled PE parsing to identify malicious API calls π
@SquiblydooBlog and I collaborated on this project that parses portable executables and looks up API calls on @mrd0x's
https://malapi.io
https://github.com/HuskyHacks/MalAPIReader
π£HuskyHacksMK
π@malwr
@SquiblydooBlog and I collaborated on this project that parses portable executables and looks up API calls on @mrd0x's
https://malapi.io
https://github.com/HuskyHacks/MalAPIReader
π£HuskyHacksMK
π@malwr
GitHub
GitHub - HuskyHacks/MalAPIReader: Reads and prints information from the website MalAPI.io
Reads and prints information from the website MalAPI.io - HuskyHacks/MalAPIReader
RE tip of the day: In malicious RTF docs, there are multiple ways how to obfuscate embedded objects to complicate the payload extraction:
* inserting {\object} in the middle
* inserting \bin[num]
* using spaces between digits
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
* inserting {\object} in the middle
* inserting \bin[num]
* using spaces between digits
#infosec #cybersecurity #malware #reverseengineering
π£re_and_more
π@malwr
π1
Breaking the Nespresso Vertuo Barcodes
π£TBD_electronique
Great work. I use the PCBite for probing, really good kit. Probably that STM32F1 is susceptible to a glitching attack.
π€andreixc
π@malwr
π£TBD_electronique
Great work. I use the PCBite for probing, really good kit. Probably that STM32F1 is susceptible to a glitching attack.
π€andreixc
π@malwr
Reddit
From the nespresso community on Reddit: Breaking the Nespresso Vertuo Barcodes (part 2)
Explore this post and more from the nespresso community
An 'Attack Path' Mapping Approach to CVEs 2021-42287 and 2021-42278. Nice blog post from TrustedSec on detection engineering. Some nice SPL queries.
π£munrobotic
π@malwr
π£munrobotic
π@malwr
TrustedSec
An 'Attack Path' Mapping Approach to CVEs 2021-42287 and 2021-42278
Figure 1 - CVE 2021-42287 and 2021-42278 Attack Path 1 Diagram While each detection strives for high fidelity and may be able stand on its own accord,β¦
π1
Introduction to x64 Linux Binary Exploitation (Part 1)
@mobilesecurity_
https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-1-14ad4a27aeef
π£Ch0pin
π@malwr
@mobilesecurity_
https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-1-14ad4a27aeef
π£Ch0pin
π@malwr
Medium
Introduction to x64 Linux Binary Exploitation (Part 1)
Basic Buffer Overflow (BoF)
RCLocals - Linux Startup Analyzer
http://www.kitploit.com/2022/01/rclocals-linux-startup-analyzer.html
π£Dinosn
π@malwr
http://www.kitploit.com/2022/01/rclocals-linux-startup-analyzer.html
π£Dinosn
π@malwr
KitPloit - PenTest & Hacking Tools
RCLocals - Linux Startup Analyzer
π1
Network Forensics, Part 1: Wireshark Basics #wireshark #networkforensics #cybersecurity #cyberwarrior
https://www.hackers-arise.com/post/2018/09/24/Network-Forensics-Wireshark-Basics-Part-1
#cyberwarrior #wireshark
π£three_cube
π@malwr
https://www.hackers-arise.com/post/2018/09/24/Network-Forensics-Wireshark-Basics-Part-1
#cyberwarrior #wireshark
π£three_cube
π@malwr
π5
Malware News pinned Β«πππPlease forward posts to the other groups πππΒ»
This media is not supported in your browser
VIEW IN TELEGRAM
If you need to dump credentials from lsass.exe on a machine with defender ATP on it, or generally want to execute #mimikatz for another operation on that machine, check out the following POC from @zux0x3a (All creds to him).
https://github.com/0xsp-SRD/mortar
#redteam #pentest #bypass
π£VirtualAllocEx
π@malwr
https://github.com/0xsp-SRD/mortar
#redteam #pentest #bypass
π£VirtualAllocEx
π@malwr
SysmonSimulator - Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules by Blue teams
https://github.com/ScarredMonk/SysmonSimulator
π£netbiosX
π@malwr
https://github.com/ScarredMonk/SysmonSimulator
π£netbiosX
π@malwr
GitHub
GitHub - ScarredMonk/SysmonSimulator: Sysmon event simulation utility which can be used to simulate the attacks to generate theβ¦
Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules by Blue teams. - ScarredMonk/SysmonS...
Our paper on emulating basebands for security analysis has been accepted at NDSS! We found multiple critical pre-auth vulnerabilities in the 2G and 4G implementations on Samsung and MediaTek basebands.
Check out the paper or keep reading to learn moreπ§΅https://hernan.de/research/papers/firmwire-ndss22-hernandez.pdf
π£Digital_Cold
π@malwr
Check out the paper or keep reading to learn moreπ§΅https://hernan.de/research/papers/firmwire-ndss22-hernandez.pdf
π£Digital_Cold
π@malwr