Forwarded from CCN-CERT
Un binario sospechoso que no conecta con su C2. Nuevo reto de reversing en #AteneaCCNCERT para este viernes. https://t.co/ZZCAE8sDpl https://t.co/CZDZYEvhMI
Si no la conocéis, la plataforma ATENEA es una especie de "CTF" para aprender a analizar binarios
básico para algunos, seguro, pero para poder correr hay que saber andar ;)
THE FIX FOR CVE-2020-9859 AND THE LIGHTSPEED VULNERABILITY https://www.synacktiv.com/posts/exploit/the-fix-for-cve-2020-9859-and-the-lightspeed-vulnerability.html
From zero to tfp0 - A Walkthrough of the voucher_swap exploit http://highaltitudehacks.com/2020/06/01/from-zero-to-tfp0-part-1-prologue/ and http://highaltitudehacks.com/2020/06/01/from-zero-to-tfp0-part-2-a-walkthrough-of-the-voucher-swap-exploit/
Prateekg147
From zero to tfp0 - Part 1: Prologue
On Jan 22, 2019, Google Project Zero researcher @_bazad tweeted the following.
Understanding and Abusing Process Tokens https://medium.com/@seemant.bisht24/understanding-and-abusing-process-tokens-part-i-ee51671f2cfa
Medium
Understanding and Abusing Process Tokens — Part I
Introduction
Anti-Debugging Technique based on Memory Protection https://isc.sans.edu/diary/rss/26200
SANS Internet Storm Center
Anti-Debugging Technique based on Memory Protection
Anti-Debugging Technique based on Memory Protection, Author: Xavier Mertens
CVE-2020-4450: WebSphere Remote Code Execution Vulnerability Alert https://meterpreter.org/cve-2020-4450-websphere-remote-code-execution-vulnerability-alert
InfoTech News
CVE-2020-4450: WebSphere Remote Code Execution Vulnerability Alert • InfoTech News
Recently, IBM officially issued a notice to fix the remote code execution (CVE-2020-4450) vulnerability in...
A C implementation of tic-tac-toe in a single call to printf https://github.com/carlini/printf-tac-toe —> printf oriented programming becomes a reality!
GitHub
GitHub - carlini/printf-tac-toe: tic-tac-toe in a single call to printf
tic-tac-toe in a single call to printf. Contribute to carlini/printf-tac-toe development by creating an account on GitHub.
ELF file structure: an in-depth look onto the Linux binary format https://metabytezero.blogspot.com/2019/10/elf-file-structure.html
Blogspot
Elf file structure
An in depth-look at the ELF file format. Elf file format tutorial.
Security Scenario Generator (SecGen) creates vulnerable virtual machines to learn security penetration testing techniques https://github.com/cliffe/SecGen
GitHub
GitHub - cliffe/SecGen: Create randomly insecure VMs
Create randomly insecure VMs. Contribute to cliffe/SecGen development by creating an account on GitHub.