Critical Bug Identified in 88mph Awarded with $42,069 Bounty https://iosiro.com/blog/88mph-bug-bounty-post-mortem
Iosiro
Critical Bug Identified in 88mph Awarded with $42,069 Bounty | iosiro
iosiro identified a critical bug in the fixed-interest-rate lending protocol 88mph. The bug was reported to 88mph through Immunefi for a bounty of $42,069. This blog post details the bug and the disclosure process.
Bludit 3.9.2 - Auth Bruteforce Bypass CVE-2019-17240 https://spyx.github.io/Bludit/
Amit Merchant - Software Engineer
Bludit 3.9.2 - Auth Bruteforce Bypass CVE-2019-17240
When self study for OSCP certification,I stumble upon HTB machine that have CVE-2019-17420 vulnerability. I look for public exploit and there was one written in python. As challenge for me self was to recreate this exploit in golang. So lets get started.
Fully Homomorphic Encryption (FHE) libraries and tools from Google https://github.com/google/fully-homomorphic-encryption
GitHub
GitHub - google/fully-homomorphic-encryption: An FHE compiler for C++
An FHE compiler for C++. Contribute to google/fully-homomorphic-encryption development by creating an account on GitHub.
Unit 42 Discovers First Known Malware Targeting Windows Containers https://www.paloaltonetworks.com/blog/2021/06/siloscape-malware-windows-containers/
Palo Alto Networks Blog
Unit 42 Discovers First Known Malware Targeting Windows Containers
The Unit 42 cybersecurity consulting group published research on Siloscape, the first known malware targeting Windows containers.
[SSTIC 2021] Solving the 5-Part SSTIC Challenge https://www.robertxiao.ca/hacking/sstic-2021/
Robert Xiao
[SSTIC 2021] Solving the 5-Part SSTIC Challenge
tl;dr: I solved the annual SSTIC Challenge solo, an epic 5-part challenge involving USB protocol forensics, Windows binary exploitation, whitebox cryptography, reversing an unknown instruction set,…
Technical descriptions of 0days found - EC-CUBE, SoyCMS, BaserCMS https://flattsecurity.hatenablog.com/entry/2020/11/02/124807
GMO Flatt Security Blog
Technical descriptions of 0days found - EC-CUBE, SoyCMS, BaserCMS - GMO Flatt Security Blog
Hi, I’m stypr (@stereotype32) from Flatt Security Inc. As I mentioned earlier in the previous article「Flatt Securityは“自分のやりたいことが実現できる”場所/セキュリティエンジニア stypr - Fla…
USENIX LISA2021 BPF Internals (eBPF) https://brendangregg.com/blog/2021-06-15/bpf-internals.html
Hacking the dlink DIR-615 for fun and no profit https://noob3xploiter.medium.com/hacking-the-dlink-dir-615-for-fun-and-no-profit-a2f1689f9920
Medium
Hacking the dlink DIR-615 for fun and no profit
Hello . In this writeup, i will show you how i found a potential remote code execution (CVE-2019–13561) in the dlink dir-615 firmware.
Microsoft finds new NETGEAR firmware vulnerabilities that could lead to identity theft and full system compromise https://www.microsoft.com/security/blog/2021/06/30/microsoft-finds-new-netgear-firmware-vulnerabilities-that-could-lead-to-identity-theft-and-full-system-compromise/
Microsoft News
Microsoft finds new NETGEAR firmware vulnerabilities that could lead to identity theft and full system compromise
We discovered vulnerabilities in NETGEAR DGN-2200v1 series routers that can compromise a network's security—opening the gates for attackers to roam untethered through an entire organization. We shared our findings with NETGEAR through coordinated vulnerability…
remember this for your next paper >> Opening sentences of research papers:
How academics defeat the blinking cursor https://medium.com/madiba-security-group/opening-sentences-of-research-papers-35d0ef5d0241
How academics defeat the blinking cursor https://medium.com/madiba-security-group/opening-sentences-of-research-papers-35d0ef5d0241
Medium
Opening sentences of research papers
How academics defeat the blinking cursor
few detection tricks for the existing CVE-2021-1675 POCs: https://twitter.com/mvelazco/status/1410291741241102338?s=09
Twitter
Mauricio Velazco
Detection opportunity #1 for the existing CVE-2021-1675 POCs: spoolsv.exe writing (Sysmon Event 11) and deleting (Sysmon Event 23) .dll files on C:\Windows\System32\spool\drivers\x64\* #printspooler
Zero day for every supported Windows OS version in the wild — PrintNightmare https://doublepulsar.com/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c
Medium
Zero day for every supported Windows OS version in the wild — PrintNightmare
zhiniang peng tweeted out a proof of concept exploit and explainer recently, and then quickly deleted it. This exploit and discussion…
From Lares Labs: Detection & Remediation Information for CVE-2021-1675 & CVE-2021-34527 https://github.com/LaresLLC/CVE-2021-1675
GitHub
GitHub - LaresLLC/CVE-2021-1675: CVE-2021-1675 Detection Info
CVE-2021-1675 Detection Info. Contribute to LaresLLC/CVE-2021-1675 development by creating an account on GitHub.
Free Micropatches for PrintNightmare Vulnerability (CVE-2021-34527) https://blog.0patch.com/2021/07/free-micropatches-for-printnightmare.html
0Patch
Free Micropatches for PrintNightmare Vulnerability (CVE-2021-34527)
by Mitja Kolsek, the 0patch Team Update 8/11/2021: August 2021 Windows Updates brought a fix for PrintNightmare that has the same default ef...
More details on CVE-2021-1675 >> https://twitter.com/gentilkiwi/status/1410621282446495749?s=20
Twitter
🥝 Benjamin Delpy
Thanks to @_f0rgetting_ we have an explanation about why we have an Elevated Token (allowing #PrintNightmare on patched domain controllers): legacy If you remove "Authenticated users" from "Builtin\Pre-Windows 2000 Compatible Access", the original Microsoft…
Interested in writing plugins in Volatility 3 for memory forensics? Read our latest blog post, where @RicardoJRdez explains how to do it. Do not miss it! https://reversea.me/index.php/writing-a-volatility-3-plugin/
ManuFuzzer: Binary code-coverage fuzzer for macOS, based on libFuzzer and LLVM https://github.com/ant4g0nist/ManuFuzzer
GitHub
ant4g0nist/ManuFuzzer
Binary code-coverage fuzzer for macOS, based on libFuzzer and LLVM - ant4g0nist/ManuFuzzer
Thousands of Vulnerable VMWare vCenter Servers Still Publicly Exposed (CVE-2021-21985, CVE-2021-21986) https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/thousands-of-vulnerable-vmware-vcenter-servers-still-publicly-exposed-cve-2021-21985-cve-2021-21986/
Trustwave
Thousands of Vulnerable VMWare vCenter Servers Still Publicly Exposed (CVE-2021-21985, CVE-2021-21986)
On May 25th, 2021, VMWare released patches to address VMSA-2021-0010, a critical security advisory for VMWare vCenter Server addressing two vulnerabilities. One of them was a remote code execution (RCE) in the vSphere Client (CVE-2021-21985) that exists due…