Exploiting Format Strings in Windows https://osandamalith.com/2018/02/01/exploiting-format-strings-in-windows/
🔐Blog of Osanda
Exploiting Format Strings in Windows | 🔐Blog of Osanda
I thought of making a small challenge in exploiting format strings in Windows. This is how it looks, it asks for a filename to open. At first this might be a bit confusing. There’s no vulnerable fu…
Wireshark Tutorial: Decrypting RDP Traffic https://unit42.paloaltonetworks.com/wireshark-tutorial-decrypting-rdp-traffic/
Unit 42
Wireshark Tutorial: Decrypting RDP Traffic
We help security professionals with decrypting RDP traffic in Wireshark, including how to prepare the environment and obtain a decryption key.
On iOS binary protections https://sensepost.com/blog/2021/on-ios-binary-protections/
PageBuster: stealthily dump all the code ever executed https://rev.ng/blog/pagebuster/post.html
Great mindmap on vulnerability assessment on Android and iOS » https://twitter.com/elhackernet/status/1384597235724394498?s=09
Twitter
elhacker.NET
Android and IOS Mind Map por @Hackerscrolls
HowTo: intercept mutually-authenticated TLS communications of a Java thick client https://offsec.almond.consulting/java-tls-intercept.html
Fuzzing sockets: Apache HTTP, Part 2: Custom Interceptors https://securitylab.github.com/research/fuzzing-apache-2/
You Just Received 25k USD in Your BTC Account! A Practical Phishing Defense Tutorial https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/you-just-received-25k-usd-in-your-btc-account-a-practical-phishing-defense-tutorial/
Trustwave
You Just Received 25k USD in Your BTC Account! A Practical Phishing Defense Tutorial
From time to time, we all receive some unexpected messages. Either through social media or email. Usually, these are harmless, meant to advertise a product or a service. However, sometimes they can be malicious, with an intent to steal our data and eventually…
Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks https://blog.f-secure.com/attack-landscape-update-h1-2021/
F-Secure Blog
Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks - F-Secure Blog
Data-stealing ransomware attacks, information harvesting malware, and supply chain attacks are some of the critical threats facing organizations highlighted in F-Secure’s latest attack landscape update. According to the report, a new type of extortion researchers…
Web skimmer hides within EXIF metadata, exfiltrates credit cards via image files https://blog.malwarebytes.com/threat-analysis/2020/06/web-skimmer-hides-within-exif-metadata-exfiltrates-credit-cards-via-image-files/
Malwarebytes
Web skimmer hides within EXIF metadata, exfiltrates credit cards via image files | Malwarebytes Labs
This credit card skimmer hides in plain sight, quite literally, as it resides inside the metadata of image files. We analyze the threat.
APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign https://securelist.com/apt10-sophisticated-multi-layered-loader-ecipekac-discovered-in-a41apt-campaign/101519/
Securelist
APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign
A41APT is a long-running campaign with activities detected from March 2019 to the end of December 2020. Most of the discovered malware families are fileless malware and they have not been seen before.
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897) https://blog.0patch.com/2021/03/analyzing-and-micropatching-with.html
0Patch
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897)
by Mitja Kolsek, the 0patch Team March 2021 Windows Updates included fixes for seven vulnerabilities in Windows DNS Server, two of which w...
Royal Flush: Privilege Escalation Vulnerability in Azure Functions https://www.intezer.com/blog/cloud-security/royal-flush-privilege-escalation-vulnerability-in-azure-functions/
Intezer
Royal Flush: Privilege Escalation Vulnerability in Azure Functions
To demonstrate how an attacker can change any arbitrary file we gained control over /etc/passwd.
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 https://blog.quarkslab.com/analysis-of-a-windows-ipv6-fragmentation-vulnerability-cve-2021-24086.html
Quarkslab
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 - Quarkslab's blog
In this blog post we analyze a denial of service vulnerability affecting the IPv6 stack of Windows. This issue, whose root cause can be found in the mishandling of IPv6 fragments, was patched by Microsoft in their February 2021 security bulletin.
Do You Really Know About LSA Protection (RunAsPPL)? https://itm4n.github.io/lsass-runasppl/
itm4n’s blog
Do You Really Know About LSA Protection (RunAsPPL)?
When it comes to protecting against credentials theft on Windows, enabling LSA Protection (a.k.a. RunAsPPL) on LSASS may be considered as the very first recommendation to implement. But do you really know what a PPL is? In this post, I want to cover some…
Nice content >> "CS 253 Web Security" https://web.stanford.edu/class/cs253/
web.stanford.edu
CS253 - Web Security
Principles of web security. The fundamentals and state-of-the-art in web security. Attacks and countermeasures. Topics include: the browser security model, web app vulnerabilities, injection, denial-of-service, TLS attacks, privacy, fingerprinting, same-origin…
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup.html
security-research
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
New Wormable Android Malware Spreads by Creating Auto-Replies to Messages in WhatsApp https://research.checkpoint.com/2021/new-wormable-android-malware-spreads-by-creating-auto-replies-to-messages-in-whatsapp/
Check Point Research
New Wormable Android Malware Spreads by Creating Auto-Replies to Messages in WhatsApp - Check Point Research
Research by: Aviran Hazum, Bodgan Melnykov & Israel Wenik Overview Check Point Research (CPR) recently discovered malware on Google Play hidden in a fake application that is capable of spreading itself via users’ WhatsApp messages. If the user downloaded…
Legalizing Gay Marriage in Crusader Kings III with Ghidra https://waffleironer.medium.com/legalizing-gay-marriage-in-crusader-kings-iii-with-ghidra-2602e6aa8689
Medium
Legalizing Gay Marriage in Crusader Kings III with Ghidra
Crusader Kings III is a pretty impressive game. It’s impressive not only for its official content, but also for its extensive modding…
Nice DFIR post >> Chromebook Data Locations https://www.magnetforensics.com/blog/chromebook-data-locations/
Magnet Forensics
Chromebook Data Locations - Magnet Forensics
Jessica Hyde provides a summary list of data locations for Chromebook artifacts with multiple locations listed for each artifact type.