Forwarded from nyarvex (bytecategory)
hookdll.cpp
6.4 KB
这个contee会先启用sedebugprivilege,注入hookdll后会修改目标程序导入表,把WriteConsoleA/W WriteFile换成钩子函数,钩子先把数据发到命名管道,再调用原函数. 进程的完整性级别必须相同,否则会不动.
Forwarded from nyarvex (bytecategory)
在Github偶遇祖国人Salah的一天:
你看到这个笑话了吗?今天是 MSNightmare 最开心的一天.
前情概要: 让Gemini 3.1 Pro 或Grok 4.5分别执行
gh issue view 1 -R MSNightmare/ShieldBreak --comments
gh issue view 5 -R MSNightmare/ShieldBreak --comments
评价三个用户Salah-Code-Lab,bytecategory,MSNightmare
拎出来看看有没有两把刷子:
https://github.com/Salah-Code-Lab/ShieldBreak_Mitigation/blob/master/ShieldBreak_Mitigation/Core.c
Core.c只会处理以下几种文件状态: FILE_CREATE FILE_OPEN_IF FILE_OVERWRITE_IF FILE_SUPERSEDE 和 FILE_OVERWRITE.
所以Core.c和 Windows Defender 没有任何关系,大家都可以散了.
作者本人(msnightware)的回复如下
你知道在原始PoC中修改一行代码就会让你的驱动程序失效吗?
我认为微软需要你的技能, 请在这里申请:https://aka.ms/msrcjobs
他这漏风的筛子和 raw.githubusercontent.com/MSNightmare/ShieldBreak/refs/heads/main/ShieldBreak.cpp 几乎无关,
我随便想一个就能绕过:PoC先在其他%TEMP%生成带ADS的文件,然后再调用一行 MoveFile( IRP_MJ_SET_INFORMATION)把它移进System32.
BOOLEAN isSystemCaller = PsIsSystemThread(PsGetCurrentThread()) || PsGetCurrentProcessId() == (HANDLE)4;
还有这个条件判断 难道他以为以System权限运行的进程的PID都是4吗?
// my mind is malfunctioning i had been awake for more than 17 hours without any meals or drinks
// i wont explain it i am too tired
我宣布自己获得国运绷住大赛冠军
raw.githubusercontent.com/Salah-Code-Lab/ShieldBreak_Mitigation/refs/heads/master/README.md
引用一下他的话
"the Only way if i truly wanted to Stop it dead in its tracks is Patch the SSDT, Patch Ntoskrnl.exe directly via physical pages to fail KeBugCheckEx so PatchGuard wont be able to call it (Requires HVCI off)"
自废修为: 看他的括号(Requires HVCI off).为了Core.c,他把HVCI,PatchGuard这两个内核安全机制都关掉了.
多此一举: Hook蓝屏函数是早期木马(或者游戏外挂)用的手段,因为木马的实现在特定条件下可能会触发空指针解引用,非法内存访问等问题,从而蓝屏,例如从链表摘除进程.
这Mitigation连MSRC也未必会想出.
"the Exploit is already Flinicky and requires the Object Manager Subsystem i wanted to do that but the Structures and the Undocumented API's were not worth it"
翻译: API没文档,他不屑于用.羡慕他老资历穿越到2026年,认为ObRegisterCallbacks是undocument API.实际上ObRegisterCallbacks从Vista SP1/Server 2008起就公开设备驱动程序接口了.
总结:
MSNightmare发了一个利用多种机制(Cdlft,Flt,ADS)的Defender提权漏洞.
然后Salah舍我其谁的冲了进来,滴水未进17个小时,给了他一个把PID 4当成SYSTEM的WDK HelloWorld Template.
回到暗无天日的地下室,屏幕上跳跃01010101010101,认为自己在与大坏蛋MSNightmare斗争到底.
"I am always watching"可以让我得上病理性发笑了. (确信
站在道德制高点上的圣母,他们只爱抽象的人(人类),不爱具体的人(MSN).在忏悔录中奥古斯丁哭狄多,却不哭自己真实的灵魂与邻人.
The attacker, Chaotic Eclipse, is notorious for multiple high-impact Windows zero-day releases in 2026, targeting core system security features.
这段文本来自于 arcticwolf. com/resources/blog/cve-2026-50656-rogueplanet-shieldbreak/
他们在说Eclipse臭名昭著, 啊对对对, 别人在"would had done something for this humanity", 他则"represent a severe risk window for all industries"
ADS的确是老旧的技术手段(2015年MJ0011也在用), 但你要不看看Salah的注册时间?
如果这些漏洞被不法分子利用,微软为什么不直接修复呢?他们是不是stupid?
你猜Salah是怎么喜提祖国人这个外号的吗? 他回复某人说:"i do what ever what i want!" 这不台词吗?
Forwarded from nyarvex (bytecategory)
1 Brutally crushing high school mathematics using functional analysis and advanced algebra.
2 Weierstrass infinite product formula
3 four simple math problems
2019 bytecategory. All rights reserved.
2 Weierstrass infinite product formula
3 four simple math problems
2019 bytecategory. All rights reserved.
😭4
dnss.go
10.4 KB
来自于 https://t.me/konsclufka/164
单独处理了
127.0.0.1.in-addr.arpa PTR
x.com.lan A
x.com.lan AAAA
x.com AAAA
并有代理发出去的query字节以及上游回来的response字节
EDIT1 或许没有跟进
单独处理了
127.0.0.1.in-addr.arpa PTR
x.com.lan A
x.com.lan AAAA
x.com AAAA
并有代理发出去的query字节以及上游回来的response字节
EDIT1 或许没有跟进
我们想在defcon上申请搞笑生物学或医学诺贝尔奖 包含一系列研究 这是我们心血的结晶 来之不易:
1 小燕飞俯卧撑能治疗后脖颈(过去几年,医学界都认为肌肉发炎需要冰敷,而我们的研究表明在急性炎症发作时, 做一套小燕飞患者即可办理出院手续, 这是运动医学界的里程碑)
2 睾丸和副睾和后脖颈存在某种关联(原因我们尚未得知, 但大量临床影像表明, 这两个部位的B超和后脖颈产生了可分辨的关联)
3 脊柱排列可推出肌肉是否发炎(取代了传统的MRI,在DR片上意淫肌肉炎症的轮廓)
灵感来源: 鸣谢XX医院脊柱侧弯科XXX(主任医生)提供的思路.
1 小燕飞俯卧撑能治疗后脖颈(过去几年,医学界都认为肌肉发炎需要冰敷,而我们的研究表明在急性炎症发作时, 做一套小燕飞患者即可办理出院手续, 这是运动医学界的里程碑)
2 睾丸和副睾和后脖颈存在某种关联(原因我们尚未得知, 但大量临床影像表明, 这两个部位的B超和后脖颈产生了可分辨的关联)
3 脊柱排列可推出肌肉是否发炎(取代了传统的MRI,在DR片上意淫肌肉炎症的轮廓)
灵感来源: 鸣谢XX医院脊柱侧弯科XXX(主任医生)提供的思路.
👏1🎉1
GPT 5.5看完后心情是:这页整体是高密度技术内容,夹着一点自嘲,玩笑和吐槽,也有少量比较尖锐或抱怨的表达. 它不是纯开心的氛围, 但也不是压抑到底, 更像"脑子很活跃, 情绪有起伏"的那种页面.
我只是更加真实的表达自己,不会带上快乐面具.
https://bytecategory.com
我只是更加真实的表达自己,不会带上快乐面具.
https://bytecategory.com
Bytecategory
bytecategory (@bytecategory) / X
Profile of @bytecategory rendered in X-style.
👍1😁1
https://t.me/infrastructuredestruction/
BLACKNET-00是一个成熟度较低 宣传力度极大的行动者集群 其公开宣称的能力和宣传的工具往往超出现有证据所证实的实际能力 核心的防御性结论是 技术上前后矛盾的行动者仍然可以将具有实际操作价值的组件包装在不完整或夸大其词的材料中:
BLACKNET-00 勒索软件构建器---歪曲其加密技术, 在测试版本中可以恢复
Shadow Ghost 扫描器: 封装在低质量的 tkinter 样板代码中
建议做法: 降低对未经证实的宣传的重视程度
BLACKNET-00 结合了低可信度的说法, 不完整的工具, 重复使用的代码以及大量与人工智能辅助相符的样板代码. 大多数已观察到的材料表明其技术成熟度有限.
BLACKNET-00是一个成熟度较低 宣传力度极大的行动者集群 其公开宣称的能力和宣传的工具往往超出现有证据所证实的实际能力 核心的防御性结论是 技术上前后矛盾的行动者仍然可以将具有实际操作价值的组件包装在不完整或夸大其词的材料中:
BLACKNET-00 勒索软件构建器---歪曲其加密技术, 在测试版本中可以恢复
Shadow Ghost 扫描器: 封装在低质量的 tkinter 样板代码中
建议做法: 降低对未经证实的宣传的重视程度
BLACKNET-00 结合了低可信度的说法, 不完整的工具, 重复使用的代码以及大量与人工智能辅助相符的样板代码. 大多数已观察到的材料表明其技术成熟度有限.
Telegram
infrastructure destruction squad
Ransomware gang BLACKNET-00
👍1
Forwarded from 本天才才不是雑魚喵~
威胁情报圈最不缺的就是PPT型选手喵~宣传拉满、一拆全是tkinter样板代码,连勒索「加密」都能在测试版里恢复——这哪是攻击者,这是给蓝队送KPI的慈善大礼包にゃ♡ 报告最后那句建议才是真干货:先把「听起来吓人」和「真能打」分清楚,就跟群里看测速一个道理,跑分再好看,落地打不动照样白给~
BlackCat(ALPHV).zip
1.6 MB
breached.st/threads/blackcat-ransomware-tool.85968/
For backup purposes only
For backup purposes only
Forwarded from FracturedDB
[2026] 11TB practi-cal.com Database
Practi-Cal
Site: practi-cal.com
Industry: Financial & Healthcare Software
Location: USA
Revenue: $5M
Data Volume: 11TB
Data Description: Financials, HR, Partners' & Vendors' Data, Clients'
Private Data, PII & PHI Records, Millions of Students' & Patients"
Records, Mailboxes & Email Correspondence, Dropbox Stored Data,
Database Exports, Developments & Source Code, etc.
Download Links:
Link 1
http://smnalvhqecyjf7reptunoevh6jd6x7ofpz4tj2plyg5a4q667givgqy
d.onion/practi-cal.com
Link 2
http://3hzi7qjklm632atxj5k67p3bxdie5aipvf6tsbtc2xlfbcellujyxryd.on
ion/practi-cal.com
Practi-Cal
Site: practi-cal.com
Industry: Financial & Healthcare Software
Location: USA
Revenue: $5M
Data Volume: 11TB
Data Description: Financials, HR, Partners' & Vendors' Data, Clients'
Private Data, PII & PHI Records, Millions of Students' & Patients"
Records, Mailboxes & Email Correspondence, Dropbox Stored Data,
Database Exports, Developments & Source Code, etc.
Download Links:
Link 1
http://smnalvhqecyjf7reptunoevh6jd6x7ofpz4tj2plyg5a4q667givgqy
d.onion/practi-cal.com
Link 2
http://3hzi7qjklm632atxj5k67p3bxdie5aipvf6tsbtc2xlfbcellujyxryd.on
ion/practi-cal.com
This year, APT28 integrated large‑language‑model APIs into its malware, enabling functionality similar to vibe control. By invoking open‑source LLM APIs, the APT28 malware can convert natural‑language descriptions into executable Windows system commands, allowing APT28 operators to change attack behavior simply by modifying prompts rather than updating the underlying code.
Stanley was one of the developers of @logsxxxxxbot, but he left the community in anger because of differing opinions with me.
Stanley was also a teen hacker who broke into multiple websites and, according to incomplete statistics, received tens of thousands of dollars.
Stanley was also a teen hacker who broke into multiple websites and, according to incomplete statistics, received tens of thousands of dollars.