Nice intro to SEH exploiting --> The Basics of Exploit Development 2: SEH Overflows https://www.coalfire.com/The-Coalfire-Blog/March-2020/The-Basics-of-Exploit-Development-2-SEH-Overflows
Coalfire.com
The Basics of Exploit Development 2: SEH Overflows
Advanced Windows Malware Analysis - Acquiring Memory Artifacts https://darungrim.com/research/2020-07-10-windows-malware-analysis-process-artifacts.html
HugeDomains
DarunGrim.com is for sale | HugeDomains
Find a domain name today. We make it easy.
Persistence Using Universal Windows Platform https://oddvar.moe/2018/09/06/persistence-using-universal-windows-platform-apps-appx/
Oddvar Moe's Blog
Persistence using Universal Windows Platform apps (APPX)
TL;DR Persistence can be achieved with Appx/UWP apps using the debugger options. This technique will not be visible by Autoruns. Two different approaches exists (registry keys). Listed below are th…
Antimalware Scan Interface Provider for Persistence
https://b4rtik.github.io/posts/antimalware-scan-interface-provider-for-persistence/
https://b4rtik.github.io/posts/antimalware-scan-interface-provider-for-persistence/
Breaking the D-Link DIR3060 Firmware Encryption - Static analysis of the decryption routine - Part 2.1 https://0x434b.dev/breaking-the-d-link-dir3060-firmware-encryption-static-analysis-of-the-decryption-routine-part-2-1/
Low-level adventures
Breaking the D-Link DIR3060 Firmware Encryption - Static analysis of the decryption routine - Part 2.1
Welcome back to part 2 of this series! If you have not checked out part 1 yet, please do so first, as it highlights important reconnaissance steps!
So let us dive right into the IDA adventure to get a better look at how imgdecrypt operates to secure firmware…
So let us dive right into the IDA adventure to get a better look at how imgdecrypt operates to secure firmware…
It Only Takes A Minute to Clone a Credit Card, Thanks to a 50-Year-Old Problem https://www.cyberdlab.com/content/dam/cyberdlab/insights/it-only-takes-a-minute-to-clone-a-credit-card-thanks-to-a-50-year-old-problem/It_Only_Takes_a_Minute_to_Clone_a_Credit_Card_%20Thanks_to_a_50_Year_Old_Problem.pdf
Reversing DexGuard, Part 3 – Code Virtualization
https://www.pnfsoftware.com/blog/reversing-dexguard-virtualization/
https://www.pnfsoftware.com/blog/reversing-dexguard-virtualization/
Detecting Linux memfd_create() Fileless Malware with Command Line Forensics https://www.sandflysecurity.com/blog/detecting-linux-memfd_create-fileless-malware-with-command-line-forensics/
Sandfly Security - Agentless Linux EDR and Incident Response
Linux Malware Detection | Ubuntu, Debian, Redhat, Suse, Fedora, Raspberry Pi etc Malware Detect
How to investigate fileless malware on Linux for different distributions: Ubuntu, Debian, Redhat, Suse, Fedora, Raspberry Pi, Arch Linux, CentOS... using simple command line tools and techniques. Easily find create_memfd() injection attacks and more.
The iPhone Data Recovery Myth: What You Can and Cannot Recover https://blog.elcomsoft.com/2020/07/the-iphone-data-recovery-myth-what-you-can-and-cannot-recover/
ElcomSoft blog
The iPhone Data Recovery Myth: What You Can and Cannot Recover
There is no lack of tools claiming the ability to recover lost or deleted information from the iPhone. These tools’ claims range from “Recover data lost due to water damaged, broken, deletion, device loss, etc.” to the much more reserved “Selectively recovers…
Structured fuzzing Android's NFC
https://securitylab.github.com/research/fuzzing_android_nfc
https://securitylab.github.com/research/fuzzing_android_nfc
GitHub Security Lab
Structured fuzzing Android’s NFC
Man Yue Mo built and open sourced a fuzzer for the Android Near Field Communication (NFC) component. He shares here some design considerations when building the fuzzer.
Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520 https://github.com/patois/winmagic_sd
GitHub
GitHub - patois/winmagic_sd: Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520
Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520 - patois/winmagic_sd
McAfee Total Protection (MTP) < 16.0.R26 Escalation of Privilege (CVE-2020-7283) https://labs.redyops.com/index.php/2020/07/14/mcafee-total-protection-mtp-16-0-r26-escalation-of-privilege-cve-2020-7283/
REDYOPS Labs
McAfee Total Protection (MTP) < 16.0.R26 EoP (CVE-2020-7283)
Exploit Code and WriteUp for McAfee Total Protection (MTP) < 16.0.R26 Escalation of Privilege (CVE-2020-7283)
capa: Automatically Identify Malware Capabilities https://www.fireeye.com/blog/threat-research/2020/07/capa-automatically-identify-malware-capabilities.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Seven 'no log' VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet https://www.theregister.com/2020/07/17/ufo_vpn_database/
The Register
Seven 'no log' VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet
Maybe it was the old Lionel Hutz play: 'No-logging VPN? I meant, No! Logging VPN!'
Welcome Chat as a secure messaging app? Nothing could be further from the truth https://www.welivesecurity.com/2020/07/14/welcome-chat-secure-messaging-app-nothing-further-truth/
WeLiveSecurity
Welcome Chat as a secure messaging app? Nothing could be further from the truth
ESET research uncovers a malicious operation that spies on Android users via Welcome Chat, an app posing as a secure chat service available in Google Play.
SCANdalous! (External Detection Using Network Scan Data and Automation) https://www.fireeye.com/blog/threat-research/2020/07/scandalous-external-detection-using-network-scan-data-and-automation.html
Google Cloud Blog
SCANdalous! (External Detection Using Network Scan Data and Automation) | Mandiant | Google Cloud Blog