RME-DisCo @ UNIZAR [www.reversea.me]
@reverseame
3.4K
subscribers
1
photo
5.55K
links
Telegram channel of RME, part of the DisCo Research Group of the University of Zaragoza (Spain) focused on cybersecurity aspects. "It’s not that I have something to hide. I have nothing I want you to see"
Link to the channel:
https://t.me/reverseame
Download Telegram
Join
RME-DisCo @ UNIZAR [www.reversea.me]
3.4K subscribers
RME-DisCo @ UNIZAR [www.reversea.me]
https://sigpwn.io/blog/2020/5/7/cve-2019-0685-win32k-reference-count-leak
sigpwn
CVE-2019-0685 win32k reference count leak in DirectComposition — sigpwn
About a year have passed since CVE-2019-0685 vulnerability that I reported to MSRC got patched. Initially I planned to write about it sooner but time flies so fast. So here is a long overdue blog post about the vulnerability. CVE-2019-0685 is a reference…
RME-DisCo @ UNIZAR [www.reversea.me]
https://web.archive.org/web/20200127165313/https://www.jakepoz.com/debugging-behind-the-iron-curtain/
The Jake Poz Blog
Debugging Behind the Iron Curtain
Sergei is a veteran of the early days of the computing industry as it was
developing in the Soviet Union. I had the pleasure of working and learning from
him over the past year, and in that time I picked up more important lessons
about both life and embedded…
RME-DisCo @ UNIZAR [www.reversea.me]
👆
👆
Ejemplo real de fallos intermitentes en un sistema, provocados por la radioactividad
RME-DisCo @ UNIZAR [www.reversea.me]
https://medium.com/bugbountywriteup/qnap-pre-auth-root-rce-affecting-450k-devices-on-the-internet-d55488d28a05?source=twitterShare-1f675e5d74e0-1589840458
Medium
QNAP Pre-Auth Root RCE Affecting ~312K Devices on the Internet
~450K QNAP NAS devices were vulnerable to a pre-auth root RCE, which chains multiple CVSS-9.8 vulnerabilities. ALL QNAP models were…
RME-DisCo @ UNIZAR [www.reversea.me]
RME-DisCo @ UNIZAR [www.reversea.me]
https://helpx.adobe.com/security/products/acrobat/apsb20-24.html?idU=1
RME-DisCo @ UNIZAR [www.reversea.me]
not bad
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.qualys.com/2020/05/19/cve-2005-1513/remote-code-execution-qmail.txt
RME-DisCo @ UNIZAR [www.reversea.me]
15 years later: Remote Code Execution in qmail (CVE-2005-1513)
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/trimstray/status/1262985978618281986?s=09
Twitter
trimstray
Ethical hacking platforms/trainings/CTFs: https://t.co/TbfGNmFoSg https://t.co/zPKaCYQCbW https://t.co/ncltAIOMx5 https://t.co/AWpU5v74nw https://t.co/oqBEVuN0ek https://t.co/xqggSRXt4d https://t.co/rSNwdodobS https://t.co/4pX0g44JLQ https://t.co/Z3ZhYiwFvl…
RME-DisCo @ UNIZAR [www.reversea.me]
http://cs.co/6019G8BzU
Talosintelligence
Vulnerability Spotlight: Memory corruption vulnerability in GNU Glibc leaves smart vehicles open to attack
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
RME-DisCo @ UNIZAR [www.reversea.me]
https://jhalon.github.io/utilizing-syscalls-in-csharp-1/
Jack Hacks
Red Team Tactics: Utilizing Syscalls in C# - Prerequisite Knowledge
Over the past year, the security community - specifically Red Team Operators and Blue Team Defenders - have seen a massive rise in both public and private utilization of System Calls in windows malware for post-exploitation activities, as well as for the…
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.zerodayinitiative.com/blog/2020/5/20/cve-2020-8871-privilege-escalation-in-parallels-desktop-via-vga-device
Zero Day Initiative
Zero Day Initiative — CVE-2020-8871: Privilege Escalation in Parallels Desktop via VGA Device
Parallels Desktop for Mac is one of the most popular virtualization programs for macOS, but there hasn’t been much public vulnerability research regarding this product. Last November, Reno Robert ( @renorobertr ) reported multiple bugs in Parallels to the…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.malwarebytes.com/threat-analysis/2020/05/the-silent-night-zloader-zbot/amp/?__twitter_impression=true
Malwarebytes Labs
Shining a light on “Silent Night” Zloader/Zbot - Malwarebytes Labs
In our new paper with HYAS, we dive deep into “Silent Night," a new banking Trojan recently tracked as Zloader/Zbot, and reminiscent of ZeuS.
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/securing-ssh-what-to-do-and-what-not-to-do/
Trustwave
Securing SSH: What To Do and What Not To Do
The SSH service is critical, ensuring its security is key. This blog will describe how best to secure the SSH service from threat actors.
RME-DisCo @ UNIZAR [www.reversea.me]
https://malwareandstuff.com/examining-smokeloaders-anti-hooking-technique/
Malware and Stuff
Examining Smokeloader’s Anti Hooking technique
Hooking is a technique to intercept function calls/messages or events passed between software, or in this case malware. The technique can be used for malicious, as well as defensive cases. Rootkits…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.zecops.com/vulnerabilities/hidden-demons-maildemon-patch-analysis-ios-13-4-5-beta-vs-ios-13-5/
Jamf
Jamf Threat Labs | Blog
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/gannimo/status/1265397262055813127?s=20
Twitter
Mathias Payer
Ever wondered about the security of your USB stack? We've explored it and found 10 CVEs on Linux and several crashes on Windows and MacOS with just a bit of fuzzing. Paper is ready, source will come at #SEC20: https://t.co/RtVcG0sRfi Comments welcome!
RME-DisCo @ UNIZAR [www.reversea.me]
https://volatility-labs.blogspot.com/2020/05/when-anti-virus-engines-look-like.html
Blogspot
When Anti-Virus Engines Look Like Kernel Rootkits
While analyzing real-world systems, memory analysts will often encounter anti-virus (AV) engines, EDRs, and similar products that, at first ...
RME-DisCo @ UNIZAR [www.reversea.me]
https://hakin9.org/fuzzowski-the-network-protocol-fuzzer-that-we-will-want-to-use/
Hakin9 - IT Security Magazine
Fuzzowski - the Network Protocol Fuzzer that we will want to use
The idea behind Fuzzowski, was to create the Network Protocol Fuzzer that we will want to use. The aim of this tool is to assist during...
RME-DisCo @ UNIZAR [www.reversea.me]
https://medium.com/bugbountywriteup/car-hacking-with-python-part-1-data-exfiltration-gps-and-obdii-can-bus-69bc6b101fd1
Medium
Car Hacking with Python — Part 1 Data Exfiltration: GPS and OBDII/CAN Bus
Presented at DEF CON 28 Car Hacking Village.