Hackers use fake Windows error logs to hide malicious payload https://www.bleepingcomputer.com/news/security/hackers-use-fake-windows-error-logs-to-hide-malicious-payload/
BleepingComputer
Hackers use fake Windows error logs to hide malicious payload
Hackers have been using fake error logs to store ASCII characters disguised as hexadecimal values that decode to a malicious payload designed to prepare the ground for script-based attacks.
Broken phishing accidentally exploiting Outlook zero-day https://isc.sans.edu/diary.html?storyid=26254
CVE-2020-8163 - Remote code execution of user-provided local names in Rails
https://github.com/sh286/CVE-2020-8163/
https://github.com/sh286/CVE-2020-8163/
GitHub
GitHub - lucasamorimca/CVE-2020-8163: CVE-2020-8163 - Remote code execution of user-provided local names in Rails
CVE-2020-8163 - Remote code execution of user-provided local names in Rails - lucasamorimca/CVE-2020-8163
A glibc heap exploitation tutorial, using a heap buffer overflow in SANE Backends as an example, by @kevin_backhouse https://securitylab.github.com/research/last-orders-at-the-house-of-force
GitHub Security Lab
Last orders at the House of Force
When his prank was thwarted by COVID-19, Kevin Backhouse decided to write a glibc heap exploitation tutorial instead. Learners, you’re in luck, enter the House of Force!
BitterAPT Revisited: the Untold Evolution of an Android Espionage Tool https://labs.bitdefender.com/2020/06/bitterapt-revisited-the-untold-evolution-of-an-android-espionage-tool/
Bitdefender Labs
BitterAPT Revisited: the Untold Evolution of an Android Espionage Tool
In 2016, a sophisticated malware campaign targeting Pakistani nationals made headlines. Dubbed Bitter, the Advanced Persistent Threat group (also... #BitterAPT #targetedattack #ThreatIntelligence
The Art of Packet Crafting with Scapy
https://github.com/0xbharath/art-of-packet-crafting-with-scapy — online workshop notes at https://scapy.disruptivelabs.in/
https://github.com/0xbharath/art-of-packet-crafting-with-scapy — online workshop notes at https://scapy.disruptivelabs.in/
GitHub
GitHub - 0xbharath/art-of-packet-crafting-with-scapy: A workshop on Packet Crafting using Scapy.
A workshop on Packet Crafting using Scapy. Contribute to 0xbharath/art-of-packet-crafting-with-scapy development by creating an account on GitHub.
Binaries, PowerShell scripts and information about Digital Signature Hijacking. https://github.com/netbiosX/Digital-Signature-Hijack
GitHub
GitHub - netbiosX/Digital-Signature-Hijack: Binaries, PowerShell scripts and information about Digital Signature Hijacking.
Binaries, PowerShell scripts and information about Digital Signature Hijacking. - GitHub - netbiosX/Digital-Signature-Hijack: Binaries, PowerShell scripts and information about Digital Signature H...
A DNS view of Lockdown https://www.potaroo.net/ispcol/2020-06/nwfh.html
Password hashing with MD5-crypt in relation to MD5 https://www.vidarholen.net/contents/blog/?p=32
Reversing “V-Alert COVID-19” Android/BankBot https://medium.com/@cryptax/reversing-v-alert-covid-19-android-bankbot-8809c7389f13
Twitter
Axelle Ap. (@cryptax) | Twitter
The latest Tweets from Axelle Ap. (@cryptax). Mainly about security, OS, mobile phones.
The postings on this page are solely my own opinion and do not represent my employer. Sophia Antipolis
The postings on this page are solely my own opinion and do not represent my employer. Sophia Antipolis
Engineering antivirus evasion
https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion/
https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion/
Hackers Using Google Analytics to Bypass Web Security and Steal Credit Cards https://thehackernews.com/2020/06/google-analytics-hacking.html
WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group https://blog.fox-it.com/2020/06/23/wastedlocker-a-new-ransomware-variant-developed-by-the-evil-corp-group/
Fox-IT International blog
WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group
Authors: Nikolaos Pantazopoulos, Stefano Antenucci (@Antelox) Michael Sandee and in close collaboration with NCC’s RIFT. About the Research and Intelligence Fusion Team (RIFT):RIFT leverages our st…
CVE-2020-10665 Docker Desktop Local Privilege Escalation https://github.com/spaceraccoon/CVE-2020-10665
GitHub
GitHub - spaceraccoon/CVE-2020-10665: POC for CVE-2020-10665 Docker Desktop Local Privilege Escalation
POC for CVE-2020-10665 Docker Desktop Local Privilege Escalation - spaceraccoon/CVE-2020-10665
Yesterday we published a new blog entry, regarding the verification of Authenticode signatures with OpenSSL https://reversea.me/index.php/authenticode-ii-verifying-authenticode-with-openssl/
CVE-2020-1170 - Microsoft Windows Defender Elevation of Privilege Vulnerability https://itm4n.github.io/cve-2020-1170-windows-defender-eop/
itm4n’s blog
CVE-2020-1170 - Microsoft Windows Defender Elevation of Privilege Vulnerability
Here is my writeup about CVE-2020-1170, an elevation of privilege bug in Windows Defender. Finding a vulnerability in a security-oriented product is quite satisfying. Though, there was nothing groundbreaking. It’s quite the opposite actually and I’m surprised…