Godzilla Vs. Kong Vs … Ghidra? - Ghidra Scripting, PCode Emulation, and Password Cracking on a GBA ROM https://wrongbaud.github.io/posts/kong-vs-ghidra/
Wrongbaud’s Blog
Godzilla Vs. Kong Vs … Ghidra? - Ghidra Scripting, PCode Emulation, and Password Cracking
Godzilla Vs. Kong Vs … Ghidra? - Ghidra Scripting, PCode Emulation and Password Cracking
Designing sockfuzzer, a network syscall fuzzer for XNU https://googleprojectzero.blogspot.com/2021/04/designing-sockfuzzer-network-syscall.html
projectzero.google
Designing sockfuzzer, a network syscall fuzzer for XNU
Posted by Ned Williamson, Project Zero Introduction When I started my 20% project – an in...
A year of Fajan evolution and Bloomberg themed campaigns https://blog.talosintelligence.com/2021/04/a-year-of-fajan-evolution-and-bloomberg.html
Cisco Talos Blog
A year of Fajan evolution and Bloomberg themed campaigns
By Vanja Svajcer.
News summary
* Some malware campaigns are designed to spread malware to as many people as possible — while some others carefully choose their targets. Cisco Talos recently discovered a malware campaign that does not fit in any of the…
News summary
* Some malware campaigns are designed to spread malware to as many people as possible — while some others carefully choose their targets. Cisco Talos recently discovered a malware campaign that does not fit in any of the…
Perun's Fart - yet another unhooking method https://blog.sektor7.net/#!res/2021/perunsfart.md
Run your malicious VBA macros anywhere! https://www.virusbulletin.com/virusbulletin/2021/04/run-your-malicious-vba-macros-anywhere/
Virusbulletin
Virus Bulletin :: Run your malicious VBA macros anywhere!
Kurt Natvig wanted to understand whether it’s possible to recompile VBA macros to another language, which could then easily be ‘run’ on any gateway, thus revealing a sample’s true nature in a safe manner. In this article he explains how he recompiled malicious…
Uncovering and Disclosing a Signature Spoofing Vulnerability in Windows Installer: CVE-2021-26413 https://sec.okta.com/articles/2021/04/uncovering-and-disclosing-signature-spoofing-vulnerability-windows
Okta Security
Uncovering and Disclosing a Signature Spoofing Vulnerability in Windows Installer: CVE-2021-26413
Executive SummaryOkta Security has discovered and disclosed a new bypass in Windows Installer (MSI) Authenticode signature validation that could all
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective https://signal.org/blog/cellebrite-vulnerabilities/?s=09
Signal
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective
Cellebrite makes software to automate physically extracting and indexing data from mobile devices. They exist within the grey – where enterprise branding joins together with the larcenous to be called “digital intelligence.” Their customer list has included…
New event type in Sysmon 13.10 — FileDeleteDetected https://medium.com/falconforce/sysmon-13-10-filedeletedetected-fe2475cb419e
Medium
Sysmon 13.10 — FileDeleteDetected
The Sysinternals team has released Sysmon 13.10 and adds the FileDeleteDetected event
CertStealer: A .NET tool for exporting and importing certificates without touching disk https://github.com/TheWover/CertStealer
GitHub
GitHub - TheWover/CertStealer: A .NET tool for exporting and importing certificates without touching disk.
A .NET tool for exporting and importing certificates without touching disk. - TheWover/CertStealer
CVE-2020-9900 & CVE-2021-1786 - Abusing macOS Crash Reporter https://theevilbit.github.io/posts/macos_crashreporter/
theevilbit blog
CVE-2020-9900 & CVE-2021-1786 - Abusing macOS Crash Reporter
I plan to discuss two symlink attacks in this blog post. The first, more severe one, CVE-2020-9900 was reported by Zhongcheng Li (CK01) of Zero-dayits Team of Legendsec at Qi’anxin Group, and fixed in Catalina 10.15.6. Apple’s advisory said that with a symlink…
Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day https://www.fireeye.com/blog/threat-research/2021/04/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html
Google Cloud Blog
Authentication Bypass Techniques and Pulse Secure Zero-Day | Google Cloud Blog
We examine multiple techniques for bypassing single & multifactor authentication on Pulse Secure VPN devices and maintaining access through webshells.
CVE-2021-30481: Source engine remote code execution via game invites https://secret.club/2021/04/20/source-engine-rce-invite.html
secret club
CVE-2021-30481: Source engine remote code execution via game invites
Steam is the most popular PC game launcher in the world. It gives millions of people the chance to play their favorite video games with their friends using the built in friend and party system, so it’s safe to assume most users have accepted an invite at…
Adversary Dossier: Ryuk Ransomware Anatomy of an Attack in 2021 https://www.advanced-intel.com/post/adversary-dossier-ryuk-ransomware-anatomy-of-an-attack-in-2021
How to analyze mobile malware: a Cabassous/FluBot Case study https://blog.nviso.eu/2021/04/19/how-to-analyze-mobile-malware-a-cabassous-flubot-case-study/
NVISO Labs
How to analyze mobile malware: a Cabassous/FluBot Case study
This blogpost explains all the steps I took while analyzing the Cabassous/FluBot malware. I wrote this while analyzing the sample and I’ve written down both successful and failed attempts at …
Lazarus APT conceals malicious code within BMP image to drop its RAT https://blog.malwarebytes.com/malwarebytes-news/2021/04/lazarus-apt-conceals-malicious-code-within-bmp-file-to-drop-its-rat/
All Your Macs Are Belong To Us: bypassing macOS's file quarantine, gatekeeper, and notarization requirements https://objective-see.com/blog/blog_0x64.html
Objective-See
All Your Macs Are Belong To Us
bypassing macOS's file quarantine, gatekeeper, and notarization requirements
Nice write-up about a XSS challenge » Easter XSS by @terjanq https://easterxss.terjanq.me/writeup.html
easterxss.terjanq.me
Easter XSS challenge by terjanq
Writeup to the Intigriti's 0421 XSS challenge
Volatile Memory Analysis With Volatility : Coreflood Trojan part 2 https://digitalitskills.com/volatile-memory-analysis-with-volatility-coreflood-trojan-part-2/
Volatility | Memory Forensics | Malware| DIGITAL IT SKILLS - Skills that matter
Volatile Memory Analysis With Volatility : Coreflood Trojan part 2 - Volatility | Memory Forensics | Malware| DIGITAL IT SKILLS
In this post we will analyze CoreFlood malware using more advanced concepts of volatile Memory analysis with Volatility Framework.
Discovering Null Byte Injection Vulnerability in GoAhead https://luker983.github.io/blog/2021-04-26-Embedded-Webserver-Null-Byte-Injection/
Luke Rindels
Discovering Null Byte Injection Vulnerability in GoAhead
How I found a zero-day in an embedded web server while testing problems for PlaidCTF 2021.
Nice blog series on reversing mobile apps » https://medium.com/@xplodwild/turning-the-frustration-of-a-mobile-game-into-a-reverse-engineering-training-a9887043efdf https://blog.usejournal.com/reverse-engineering-of-a-mobile-game-part-2-they-updated-we-dumped-memory-27046efdfb85 https://medium.com/@xplodwild/reverse-engineering-of-a-mobile-game-part-3-now-its-obfuscated-9c31e29c386b
Medium
Turning the frustration of a mobile game into a reverse engineering training
Games can be as fun as frustrating, when bugs ruin the fun for half of the player base, and the dev doesn’t care. So, I fixed it myself.