Speculating the entire x86-64 Instruction Set In Seconds with This One Weird Trick https://blog.can.ac/2021/03/22/speculating-x86-64-isa-with-one-weird-trick/
Can.ac
Speculating the entire x86-64 Instruction Set In Seconds with This One Weird Trick
As cheesy as the title sounds, I promise it cannot beat the cheesiness of the technique I’ll be telling you about in this post. The morning I saw Mark …
Simple utlity for sniffing decrypted HTTP/HTTPS traffic on a jailbroken iOS device into an HAR format https://github.com/doronz88/harlogger
GitHub
GitHub - doronz88/harlogger: Simple utlity for sniffing decrypted HTTP/HTTPS traffic on an macOS/iOS device (either jailbroken…
Simple utlity for sniffing decrypted HTTP/HTTPS traffic on an macOS/iOS device (either jailbroken or not) - doronz88/harlogger
Very good material here » Materials for Windows Malware Analysis training (volume 1) by @hasherezade https://github.com/hasherezade/malware_training_vol1
GitHub
GitHub - hasherezade/malware_training_vol1: Materials for Windows Malware Analysis training (volume 1)
Materials for Windows Malware Analysis training (volume 1) - hasherezade/malware_training_vol1
Triaging modern Android devices (aka android_triage bash script) https://blog.digital-forensics.it/2021/03/triaging-modern-android-devices-aka.html
blog.digital-forensics.it
Triaging modern Android devices (aka android_triage bash script)
DFIR research
Zero click vulnerability in Apple’s macOS Mail https://mikko-kenttala.medium.com/zero-click-vulnerability-in-apples-macos-mail-59e0c14b106c
Medium
Zero click vulnerability in Apple’s macOS Mail
Zero-Click Zip TL;DR
Executing Shellcode via Callbacks https://osandamalith.com/2021/04/01/executing-shellcode-via-callbacks/
🔐Blog of Osanda
Executing Shellcode via Callbacks | 🔐Blog of Osanda
What is a Callback Function? In simple terms, it’s a function that is called through a function pointer. When we pass a function pointer to the parameter where the callback function is required, on…
New vulnerabilities discovered [in QNAP devices] allow access to user data and complete takeover https://securingsam.com/new-vulnerabilities-allow-complete-takeover/
SAM Seamless Network
New Vulnerabilities Discovered Allow Access to User Data and Complete Takeover - SAM Seamless Network
SAM’s security research team is actively looking for vulnerabilities in IoT devices that have yet to be discovered in order to ensure our network security coverage is as accurate and up to date as possible.
Exploiting Format Strings in Windows https://osandamalith.com/2018/02/01/exploiting-format-strings-in-windows/
🔐Blog of Osanda
Exploiting Format Strings in Windows | 🔐Blog of Osanda
I thought of making a small challenge in exploiting format strings in Windows. This is how it looks, it asks for a filename to open. At first this might be a bit confusing. There’s no vulnerable fu…
Wireshark Tutorial: Decrypting RDP Traffic https://unit42.paloaltonetworks.com/wireshark-tutorial-decrypting-rdp-traffic/
Unit 42
Wireshark Tutorial: Decrypting RDP Traffic
We help security professionals with decrypting RDP traffic in Wireshark, including how to prepare the environment and obtain a decryption key.
On iOS binary protections https://sensepost.com/blog/2021/on-ios-binary-protections/
PageBuster: stealthily dump all the code ever executed https://rev.ng/blog/pagebuster/post.html
Great mindmap on vulnerability assessment on Android and iOS » https://twitter.com/elhackernet/status/1384597235724394498?s=09
Twitter
elhacker.NET
Android and IOS Mind Map por @Hackerscrolls
HowTo: intercept mutually-authenticated TLS communications of a Java thick client https://offsec.almond.consulting/java-tls-intercept.html
Fuzzing sockets: Apache HTTP, Part 2: Custom Interceptors https://securitylab.github.com/research/fuzzing-apache-2/
You Just Received 25k USD in Your BTC Account! A Practical Phishing Defense Tutorial https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/you-just-received-25k-usd-in-your-btc-account-a-practical-phishing-defense-tutorial/
Trustwave
You Just Received 25k USD in Your BTC Account! A Practical Phishing Defense Tutorial
From time to time, we all receive some unexpected messages. Either through social media or email. Usually, these are harmless, meant to advertise a product or a service. However, sometimes they can be malicious, with an intent to steal our data and eventually…
Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks https://blog.f-secure.com/attack-landscape-update-h1-2021/
F-Secure Blog
Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks - F-Secure Blog
Data-stealing ransomware attacks, information harvesting malware, and supply chain attacks are some of the critical threats facing organizations highlighted in F-Secure’s latest attack landscape update. According to the report, a new type of extortion researchers…
Web skimmer hides within EXIF metadata, exfiltrates credit cards via image files https://blog.malwarebytes.com/threat-analysis/2020/06/web-skimmer-hides-within-exif-metadata-exfiltrates-credit-cards-via-image-files/
Malwarebytes
Web skimmer hides within EXIF metadata, exfiltrates credit cards via image files | Malwarebytes Labs
This credit card skimmer hides in plain sight, quite literally, as it resides inside the metadata of image files. We analyze the threat.
APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign https://securelist.com/apt10-sophisticated-multi-layered-loader-ecipekac-discovered-in-a41apt-campaign/101519/
Securelist
APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign
A41APT is a long-running campaign with activities detected from March 2019 to the end of December 2020. Most of the discovered malware families are fileless malware and they have not been seen before.
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897) https://blog.0patch.com/2021/03/analyzing-and-micropatching-with.html
0Patch
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897)
by Mitja Kolsek, the 0patch Team March 2021 Windows Updates included fixes for seven vulnerabilities in Windows DNS Server, two of which w...
Royal Flush: Privilege Escalation Vulnerability in Azure Functions https://www.intezer.com/blog/cloud-security/royal-flush-privilege-escalation-vulnerability-in-azure-functions/
Intezer
Royal Flush: Privilege Escalation Vulnerability in Azure Functions
To demonstrate how an attacker can change any arbitrary file we gained control over /etc/passwd.
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 https://blog.quarkslab.com/analysis-of-a-windows-ipv6-fragmentation-vulnerability-cve-2021-24086.html
Quarkslab
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 - Quarkslab's blog
In this blog post we analyze a denial of service vulnerability affecting the IPv6 stack of Windows. This issue, whose root cause can be found in the mishandling of IPv6 fragments, was patched by Microsoft in their February 2021 security bulletin.