Nice write-up » From theory to practice: analysis and PoC development for CVE-2020-28018 (Use-After-Free in Exim) [code in https://github.com/lockedbyte/CVE-Exploits/tree/master/CVE-2020-28018] https://adepts.of0x.cc/exim-cve-2020-28018/
GitHub
CVE-Exploits/CVE-2020-28018 at master · lockedbyte/CVE-Exploits
PoC exploits for software vulnerabilities. Contribute to lockedbyte/CVE-Exploits development by creating an account on GitHub.
Abusing Teams client protocol to bypass Teams security policies https://o365blog.com/post/teams-policies/
Aadinternals
Abusing Teams client protocol to bypass Teams security policies
Administrators can use teams policies for controlling what users can do in Microsoft Teams.
In this blog, I’ll show that these policies are applied only in client and thus can be easily bypassed.
In this blog, I’ll show that these policies are applied only in client and thus can be easily bypassed.
Hacking GraphQL for Fun and Profit — Part 2— Methodology and Examples https://infosecwriteups.com/hacking-graphql-for-fun-and-profit-part-2-methodology-and-examples-5992093bcc24
Medium
Hacking GraphQL for Fun and Profit — Part 2— Methodology and Examples
Hi everyone!!
Exploiting custom protocol handlers for cross-browser tracking in Tor, Safari, Chrome and Firefox https://fingerprintjs.com/blog/external-protocol-flooding/
Fingerprint
Cross-browser tracking vulnerability in Tor, Safari, Chrome, and Firefox
Unveiling a scheme flooding vulnerability across major browsers. Learn how it threatens anonymous browsing.
Counter-Strike Global Offsets: reliable remote code execution https://secret.club/2021/05/13/source-engine-rce-join.html
secret club
Counter-Strike Global Offsets: reliable remote code execution
One of the factors contributing to Counter-Strike Global Offensive’s (herein “CS:GO”) massive popularity is the ability for anyone to host their own community server. These community servers are free to download and install and allow for a high grade of customization.…
Exploit Development: CVE-2021-21551 - Dell ‘dbutil_2_3.sys’ Kernel Exploit Writeup https://connormcgarr.github.io/cve-2020-21551-sploit/
Connor McGarr’s Blog
Exploit Development: CVE-2021-21551 - Dell ‘dbutil_2_3.sys’ Kernel Exploit Writeup
Analysis and writeup on weaponizing CVE-2021-21551 without a data-only attack and the importance of Virtualization-Based Security, Hypervisor-Protected Code Integrity, Kernel Control-Flow Guard, and other modern mitigations.
Transparent Tribe APT expands its Windows malware arsenal https://blog.talosintelligence.com/2021/05/transparent-tribe-infra-and-targeting.html
Cisco Talos
Transparent Tribe APT expands its Windows malware arsenal
Transparent Tribe, also known as APT36 and Mythic Leopard, continues to create fake domains mimicking legitimate military and defense organizations as a core component of their operations. Cisco Talos’ previous research has mainly linked this group to CrimsonRAT…
Analyzing APT19 malware using a step-by-step method https://cybergeeks.tech/analyzing-apt19-malware-using-a-step-by-step-method/
VMProtect 2 - Detailed Analysis of the Virtual Machine Architecture https://back.engineering/17/05/2021/#preamble
Fuzzing iOS code on macOS at native speed https://googleprojectzero.blogspot.com/2021/05/fuzzing-ios-code-on-macos-at-native.html?m=1
Blogspot
Fuzzing iOS code on macOS at native speed
Or how iOS apps on macOS work under the hood Posted by Samuel Groß, Project Zero This short post explains how code compiled for iOS ...
BazarCall Method: Call Centers Help Spread BazarLoader Malware https://unit42.paloaltonetworks.com/bazarloader-malware/
Unit 42
BazarCall Method: Call Centers Help Spread BazarLoader Malware
Call center operators offer to personally guide victims through a process designed to infect vulnerable computers with BazarLoader malware.
A detailed analysis of ELMER Backdoor used by APT16 https://cybergeeks.tech/a-detailed-analysis-of-elmer-backdoor-used-by-apt16/
A skidalicious cheat sheet of webapp exploitation techniques https://blog.oxagast.org/posts/skidalicious-webapp-exploit-cheat-sheet/
blog.oxagast.org
Web app exploitation techniques |
oxasploits
oxasploits
Some popular web application exploitation techniques
Tracking BokBot Infrastructure: Mapping a Vast and Currently Active BokBot Network https://team-cymru.com/blog/2021/05/19/tracking-bokbot-infrastructure/
Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot https://github.com/D3VI5H4/Antivirus-Artifacts
GitHub
GitHub - ethereal-vx/Antivirus-Artifacts: Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes…
Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot. - ethereal-vx/Antivirus-Artifacts
Reverse Engineering & Exploiting Dell CVE-2021-21551 https://voidsec.com/reverse-engineering-and-exploiting-dell-cve-2021-21551/
VoidSec
Reverse Engineering & Exploiting Dell CVE-2021-21551 - VoidSec
Didactic blog post regarding the process and methodology used to Reverse Engineering & Weaponize Dell's CVE-2021-21551.
The Full Story of the Stunning RSA Hack Can Finally Be Told https://www.wired.com/story/the-full-story-of-the-stunning-rsa-hack-can-finally-be-told/
WIRED
The Full Story of the Stunning RSA Hack Can Finally Be Told
In 2011, Chinese spies stole the crown jewels of cybersecurity—stripping protections from firms and government agencies worldwide. Here’s how it happened.
When Intrusions Don’t Align: A New Water Watering Hole and Oldsmar https://www.dragos.com/blog/industry-news/a-new-water-watering-hole/
Dragos
When Intrusions Don't Align: A New Water Watering Hole and Oldsmar
While investigating the Oldsmar water treatment facility breach, Dragos discovered malicious code being hosted on a utility contractor website (a watering hole). Read the threat analysis for more.
What’s new in Android Privacy https://android-developers.googleblog.com/2021/05/android-security-and-privacy-recap.html
Android Developers Blog
What’s new in Android Privacy
Posted by Sara N-Marandi, Product Manager, Android Platform Product People want an OS and apps that they can trust with the...
Vulnerability Spotlight: Heap-based buffer overflow in Google Chrome could lead to code execution https://blog.talosintelligence.com/2021/05/vuln-spotlight-google-chrome-heap.html
Cisco Talos Blog
Vulnerability Spotlight: Heap-based buffer overflow in Google Chrome could lead to code execution
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Google Chrome.
Google Chrome is a cross-platform web browser — and Chromium…
Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Google Chrome.
Google Chrome is a cross-platform web browser — and Chromium…