I was honored to present on Program Analysis with Ghidra for @sergeybratus's @DartmouthCS course, "Basics of Reverse Engineering" yesterday -
Basic program analysis concepts, Ghidra API tour, demo code, SLEIGH, and opinionated takes on RE -
Slides:
๐ฒ๐ป
https://github.com/sergeybratus/RE-basics-W22/blob/main/GHIDRA-For-Dartmouth.pdf
๐ฃ0xAlexei
๐@malwr
Basic program analysis concepts, Ghidra API tour, demo code, SLEIGH, and opinionated takes on RE -
Slides:
๐ฒ๐ป
https://github.com/sergeybratus/RE-basics-W22/blob/main/GHIDRA-For-Dartmouth.pdf
๐ฃ0xAlexei
๐@malwr
GitHub
RE-basics-W22/GHIDRA-For-Dartmouth.pdf at main ยท sergeybratus/RE-basics-W22
Basics of Reverse Engineering Winter 2022. Contribute to sergeybratus/RE-basics-W22 development by creating an account on GitHub.
๐3
ContiLeaks continues to leak data from Conti... they have released source code - the Trickbot Command Dispatcher & Trickbot Data Collector. They have also doxxed one of the developers of Conti.
You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
๐ฃvxunderground
๐@malwr
You can download the Trickbot source code here: https://share.vx-underground.org/Conti/
๐ฃvxunderground
๐@malwr
๐ฅ1
My iOS QEMU fork is just published.
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation
The repo is at https://github.com/TrungNguyen1909/qemu-t8030
Tutorial/status can be found in the wiki section.
It is still very far from a usable device
๐ฃntrung03
๐@malwr
Some notable features:
- iOS Restore
- S8000 SecureROM emulation (always FORCE_DFU)
- USB
- SPRR/GXF emulation
The repo is at https://github.com/TrungNguyen1909/qemu-t8030
Tutorial/status can be found in the wiki section.
It is still very far from a usable device
๐ฃntrung03
๐@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
#CVE-2022-22947 Spring Cloud Gateway SpEL Remote Code Execution
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
๐ฃpyn3rd
๐@malwr
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
๐ฃpyn3rd
๐@malwr
Android Malware Research (aka the team I'm on :) is looking for an experienced Android malware reverse engineer in NYC!
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
๐ฃmaldr0id
๐@malwr
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
๐ฃmaldr0id
๐@malwr
Google
Build for Everyone - Google Careers
Careers at Google - find a job at Google. Look inside engineering jobs at Google.
Announcing Windows 11 Insider Preview Build 22567
https://blogs.windows.com/windows-insider/2022/03/02/announcing-windows-11-insider-preview-build-22567/
๐ฃwindowsblog
๐@malwr
https://blogs.windows.com/windows-insider/2022/03/02/announcing-windows-11-insider-preview-build-22567/
๐ฃwindowsblog
๐@malwr
Windows Insider Blog
Announcing Windows 11 Insider Preview Build 22567
UPDATE 3/7: We are starting to roll out Cumulative Update Build 22567.200 (KB5012432). This update does not include anything new and is designed to test our servicing pipeline for builds in the Dev Channel.
NOTE: Windows Insider
NOTE: Windows Insider
Ghidra for beginners - Pwn Zero To Hero
๐ฃPinkDraconian
Great video as always
๐คnavneetmuffin
๐@malwr
๐ฃPinkDraconian
Great video as always
๐คnavneetmuffin
๐@malwr
YouTube
Ghidra - Pwn Zero To Hero 0x02
Full Pwn Zero To Hero playlist: https://www.youtube.com/playlist?list=PLeSXUd883dhjmKkVXSRgI1nJEZUDzgLf_
Crackmes: https://crackmes.one/
โถ๏ธ YouTube: https://www.youtube.com/c/PinkDraconian
๐ Patreon: https://www.patreon.com/PinkDraconian
๐ฆ Twitter: httโฆ
Crackmes: https://crackmes.one/
โถ๏ธ YouTube: https://www.youtube.com/c/PinkDraconian
๐ Patreon: https://www.patreon.com/PinkDraconian
๐ฆ Twitter: httโฆ
A deep dive into HermeticWiper's internals
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/digging-into-hermeticwiper.html
โน๏ธ Sent from one of our channel members
๐@malwr
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/digging-into-hermeticwiper.html
โน๏ธ Sent from one of our channel members
๐@malwr
Trellix
Digging into HermeticWiper
The HermeticWiper malware aims to destroy the boot sectors of any (removable) disk on the infected machine, with the help of a benign partition manager driver.
๐1
Find out how two flaws in NETGEAR DGND3700v2 devices allow remote unauthenticated attackers to trigger bypass the authentication mechanism and run commands as root
๐ฃSSDisclosure
๐@malwr
๐ฃSSDisclosure
๐@malwr
SSD Secure Disclosure
SSD Advisory โ NETGEAR DGND3700v2 PreAuth Root Access - SSD Secure Disclosure
Find out how a vulnerability in multiple Uniview devices allow remote unauthenticated attackers to trigger a remote code execution vulnerability in the products the company offers.
Reversing embedded device bootloader (U-Boot) & decrypt the firmware - (Part
1 - Shielder ) : https://www.shielder.it/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/ credits
@zi0Black @Th3Zer0
๐ฃbinitamshah
๐@malwr
1 - Shielder ) : https://www.shielder.it/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/ credits
@zi0Black @Th3Zer0
๐ฃbinitamshah
๐@malwr
๐1
http://phishstats.info detected 111 new websites hosting #phishing | new today: 788 | #infosec #cybersecurity #malware
๐ฃPhishStats
๐@malwr
๐ฃPhishStats
๐@malwr
Malfrat's OSINT Map is live on https://map.malfrats.industries !
We forked http://osintframework.com since this is no longer maintained, so you can easily contribute on our repo.
Thanks for their original work.
๐ฃMalfratsInd
๐@malwr
We forked http://osintframework.com since this is no longer maintained, so you can easily contribute on our repo.
Thanks for their original work.
๐ฃMalfratsInd
๐@malwr
If you're looking to practice your #malware #analysis skills, I have several exercises available:
๐ https://github.com/jstrosch/malware-samples
These include challenge tasks and detailed walk-throughs. You'll also find them as CTF challenges at CyberDefenders
๐ https://cyberdefenders.org/blueteam-ctf-challenges/
๐ฃjstrosch
๐@malwr
๐ https://github.com/jstrosch/malware-samples
These include challenge tasks and detailed walk-throughs. You'll also find them as CTF challenges at CyberDefenders
๐ https://cyberdefenders.org/blueteam-ctf-challenges/
๐ฃjstrosch
๐@malwr
Day 78 #100DaysofYARA - fun with the dotnet module
looking for user strings (typically wide strings) that imply command execution. Why look in this way vs just as strings?
Well this rule tells us immediately that the file is a dotnet executable
๐ฃgreglesnewich
๐@malwr
looking for user strings (typically wide strings) that imply command execution. Why look in this way vs just as strings?
Well this rule tells us immediately that the file is a dotnet executable
๐ฃgreglesnewich
๐@malwr
A nice bit of #HermeticWiper reversing by @eln0tyโ
https://eln0ty.github.io/malware%20analysis/HermeticWiper/
๐ฃjuanandres_gs
๐@malwr
https://eln0ty.github.io/malware%20analysis/HermeticWiper/
๐ฃjuanandres_gs
๐@malwr
eln0ty
HermeticWiper/FoxBlade Analysis (in-depth)
The malware which targeting Ukrainian infrastructure (Specially windows devices) has since been observed in the neighboring countries of Latvia and Lithuania and manipulating the MBR resulting in subsequent boot failure.
Full Reverse Engineering of Sony Memory Stick
๐ฃdmitrygr
Is there any easy way to spoof the card serial number?
A MCU acting as man-in-the-middle, or something else?
I need it to unbrick a PSP 2000.
๐คRainyShadow
Nice!
Sony, the king of proprietary mediums. What a nightmare for consumers and devs alike.
๐คusernamenottakenwooh
MagicGate still holding up?
๐คTailSpinBowler
๐@malwr
๐ฃdmitrygr
Is there any easy way to spoof the card serial number?
A MCU acting as man-in-the-middle, or something else?
I need it to unbrick a PSP 2000.
๐คRainyShadow
Nice!
Sony, the king of proprietary mediums. What a nightmare for consumers and devs alike.
๐คusernamenottakenwooh
MagicGate still holding up?
๐คTailSpinBowler
๐@malwr
Dmitry.GR
Sony Memory Stick - Dmitry.GR
Dmitry.GR: The first complete documentation of Sony Memory Stick from HW to DATA
Debugger and analyzer for ELF executables named "donna" made by me . Im still a HS student so any help would be appreciated. Made in C++ btw.
๐ฃsuibex
Writing a debugger in high school? Color me impressed.
๐คjameson71
Suggestion: remove all the random empty lines you have littered throughout the code or just run you code through a formatter.
๐คmagion
๐@malwr
๐ฃsuibex
Writing a debugger in high school? Color me impressed.
๐คjameson71
Suggestion: remove all the random empty lines you have littered throughout the code or just run you code through a formatter.
๐คmagion
๐@malwr
GitHub
GitHub - suibex/donna: Debugger and analyzer for ARM ELF executables.
Debugger and analyzer for ARM ELF executables. Contribute to suibex/donna development by creating an account on GitHub.