Malware News
12.8K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
RE tip of the day: Here is an example of using standard structures in IDA to quickly find the meaning of the MZ-PE header fields used to dynamically resolve imports. Just add IMAGE_EXPORT_DIRECTORY structure and apply it!
#infosec #cybersecurity #malware #reverseengineering
🗣re_and_more


🎖@malwr
📺 Tips for learning RE

How to maximize your time and avoid mind traps when learning how to reverse engineer with #OALABS

https://youtu.be/JzhpTLe8Vg4
🗣herrcore


🎖@malwr
3
Android Root Detection Bypass using Frida (Part 1 – OWASP Uncrackable 1)
https://pentest.co.uk/labs/android-root-detection-bypass-using-frida-1/
🗣androidmalware2


🎖@malwr
2
👍1
Hacking Auto-GPT and escaping its docker container
🗣albinowax

> The docker-compose.yml file present in the repo mounts itself into the docker

I mean this is just fucking stupid so...
👤1esproc

This is the biggest issue with AI in my opinion and why it's not going to take over everyone's jobs just yet. It's too much of a black box
👤UnacceptableUse


🎖@malwr
Process Mockingjay: Echoing RWX In Userland To Achieve Code Execution
🗣thewatcher_

Do industrial attackers not know about ROP compilers? This whole silly arms race about process injection vs EDRs could be ended by simply using an existing free tools. Maybe most do and all the vendors are just fighting everyone who hasn't yet made the jump.
👤SirensToGo


🎖@malwr
New Malware Analysis/RE plugin is now available!🚨
IAT-Tracer is an offline automation plugin for the Tiny-Tracer framework (by @hasherezade) to trace and watch functions directly out of the executable's import table.
https://github.com/YoavLevi/IAT-Tracer

ℹ️ Thanks Levi, for such a nice tool.

🎖@malwr
2
Biden-⁠Harris Administration Announces Cybersecurity Labeling Program for Smart Devices to Protect American Consumers
🗣digicat

A) this will result in another new unnecessary government agency
B) the list of companies voluntarily committing to the program are all massive orgs, smaller agile and innovative orgs won't be able to compete
C) do the basics better, there's no need for this
👤crawdad101

I think this is a great idea but who's going to be in charge of this?

The Gov doesn't have enough people to independently review every single smart device that comes to market. So is it left on companies to self certify that they meet the requirements?

If it's self certification then what happens if a company fraudulently claims they meet the requirements when they don't? Are there penalties?
👤AnApexBread


🎖@malwr