π5π2π€―1
frida typescript trick : if you want to hook functions with reserverd names such as toString(), encode the string and get function with [""]
Instead of jsonObj.toString.implementation
use jsonObj[b64decode("dG9TdHJpbmc=")]
:D
π£0xabc0
π@malwr
Instead of jsonObj.toString.implementation
use jsonObj[b64decode("dG9TdHJpbmc=")]
:D
π£0xabc0
π@malwr
My write up for CVE-2021-43893, a vulnerability that allowed a remote attacker to upload files to a Domain Controller, just got posted π
https://www.rapid7.com/blog/post/2022/02/14/dropping-files-on-a-domain-controller-using-cve-2021-43893/
π£Junior_Baines
π@malwr
https://www.rapid7.com/blog/post/2022/02/14/dropping-files-on-a-domain-controller-using-cve-2021-43893/
π£Junior_Baines
π@malwr
Rapid7
Dropping Files on a Domain Controller Using CVE-2021-43893 | Rapid7 Blog
BigQuery SQL Injection Cheat Sheet
https://ozguralp.medium.com/bigquery-sql-injection-cheat-sheet-65ad70e11eac
π£tbbhunter
π@malwr
https://ozguralp.medium.com/bigquery-sql-injection-cheat-sheet-65ad70e11eac
π£tbbhunter
π@malwr
Medium
BigQuery SQL Injection Cheat Sheet
Last year, we (My researcher partner on this topic, Anil and me) and found a SQL injection vulnerability on a target at Synack which wasβ¦
dronesploit : Drone pentesting framework console : https://github.com/dhondta/dronesploit credits @alex_dhondt
π£binitamshah
π@malwr
π£binitamshah
π@malwr
Interesting awesome list about PE/ELF/... packing
: credits @alex_dhondt
https://github.com/dhondta/awesome-executable-packing
π£binitamshah
π@malwr
: credits @alex_dhondt
https://github.com/dhondta/awesome-executable-packing
π£binitamshah
π@malwr
GitHub
GitHub - packing-box/awesome-executable-packing: A curated list of awesome resources related to executable packing
A curated list of awesome resources related to executable packing - packing-box/awesome-executable-packing
π1
We have a Valentineβs Day surprise for everyone - The first Kali Linux release of 2022 is posted and ready for download!
https://www.kali.org/blog/kali-linux-2022-1-release/
Included in this release is:
Visual Refresh
New Kali Everything Image
Legacy SSH support
Accessibility Features
& More!
π£kalilinux
π@malwr
https://www.kali.org/blog/kali-linux-2022-1-release/
Included in this release is:
Visual Refresh
New Kali Everything Image
Legacy SSH support
Accessibility Features
& More!
π£kalilinux
π@malwr
π1
Have Linux dev skills and want to work on Sysinternals tools for Linux?
https://careers.microsoft.com/us/en/job/1260200
π£markrussinovich
π@malwr
https://careers.microsoft.com/us/en/job/1260200
π£markrussinovich
π@malwr
π r2-5.6.2 is out! This is a security-focused release! π Checkout the changes as it may be important ^^. All binary builds are available and distros will be eventually updating. https://github.com/radareorg/radare2/releases/tag/5.6.2
π£radareorg
π@malwr
π£radareorg
π@malwr
Well, Sentinel1 is the first EDR I've seen doing this. The whole Export Address Table (EAT) is modified in memory for kernel32.dll and not just the WinAPI calls. So, if you are trying to parse kernel32 to find any export function, you will be forever stuck in a loop... lol! π€£π€£
π£NinjaParanoid
π@malwr
π£NinjaParanoid
π@malwr
Sharing something I have written lately.
#redteam #maldev
https://captmeelo.com/redteam/maldev/2022/02/16/libraries-for-maldev.html
π£CaptMeelo
π@malwr
#redteam #maldev
https://captmeelo.com/redteam/maldev/2022/02/16/libraries-for-maldev.html
π£CaptMeelo
π@malwr
Hack.Learn.Share
Useful Libraries for Malware Development
A list of some easy-to-use libraries and how to use them for malware development.
Had some free time lately due to covid isolation, so I thought why not write something?
This is my new article about #BazarLoader. Similar to my previous articles, this writeup is a hybrid between a presentation and a step-by-step tutorial.
https://elis531989.medium.com/highway-to-conti-analysis-of-bazarloader-26368765689d
π£elisalem9
π@malwr
This is my new article about #BazarLoader. Similar to my previous articles, this writeup is a hybrid between a presentation and a step-by-step tutorial.
https://elis531989.medium.com/highway-to-conti-analysis-of-bazarloader-26368765689d
π£elisalem9
π@malwr
Medium
Highway to Conti: Analysis of Bazarloader
As we look back to summarize the year 2021 we observe that the biggest threat in the cybersecurity landscape is still ransomware. A largeβ¦
You can now install and run latest r2, rax2 and rasm2 in your browser or terminal thanks to webassembly! (no disk or network access, it's a sandbox! (use pc* and terminal paste to load binaries) https://wapm.io/package/pancake/r2#shell
π£radareorg
π@malwr
π£radareorg
π@malwr
Analyzing an IDA Pro anti-decompilation code
https://antonioparata.blogspot.com/2022/01/analyzing-ida-pro-anti-decompilation.html
π£reverseame
π@malwr
https://antonioparata.blogspot.com/2022/01/analyzing-ida-pro-anti-decompilation.html
π£reverseame
π@malwr
Blogspot
Analyzing an IDA Pro anti-decompilation code
Twitter: @s4tan GitHub: https://github.com/enkomio/ In this post I'll analyze a piece of code that induces IDA Pro to decompile t...
IDA Free has been upgraded to the latest IDA version 7.7SP1!
This light but powerful tool can quickly analyze the binary code samples and allow users to take a closer look at the results.
Try it out for free https://hex-rays.com/ida-free/
#IDAFreeware #Binaryanalysis #HexRays
π£HexRaysSA
π@malwr
This light but powerful tool can quickly analyze the binary code samples and allow users to take a closer look at the results.
Try it out for free https://hex-rays.com/ida-free/
#IDAFreeware #Binaryanalysis #HexRays
π£HexRaysSA
π@malwr
π₯1
Woop Woop, good day for #CTI. @MISPProject released v2.4.153 with a lot of fixes and extra features. These new taxonomies are very interesting for state attribution ( and intrusion modeling ( See ππ―
https://www.misp-project.org/taxonomies.html#_state_responsibility
π£digihash
π@malwr
https://www.misp-project.org/taxonomies.html#_state_responsibility
π£digihash
π@malwr
Fuzzing sockets: Apache HTTP, Part 3: Results
https://securitylab.github.com/research/fuzzing-apache-3/
π£kmkz_security
π@malwr
https://securitylab.github.com/research/fuzzing-apache-3/
π£kmkz_security
π@malwr