Runtime Mobile Security provides a web interface that helps you to manipulate Android and iOS Apps at Runtime (relies on FRIDA) https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security
GitHub
GitHub - m0bilesecurity/RMS-Runtime-Mobile-Security: Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps…
Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime - m0bilesecurity/RMS-Runtime-Mobile-Security
Painless Cuckoo Sandbox Installation https://blog.nviso.eu/2018/04/12/painless-cuckoo-sandbox-installation/
NVISO Labs
Painless Cuckoo Sandbox Installation
TLDR: As part of our SANS SEC599 development efforts, we updated (fixed + added some new features) an existing Cuckoo Auto Install script by Buguroo Security to automate Cuckoo sandbox installation…
Writing an iOS Kernel Exploit from Scratch https://secfault-security.com/blog/chain3.html
Let's Learn: In-Depth Reversing of Recent Gozi ISFB Banking Malware Version 2.16/2.17 (portion of ISFB v3) & "loader.dll/client.dll" https://www.vkremez.com/2018/08/lets-learn-in-depth-reversing-of-recent.html
Vkremez
Let's Learn: In-Depth Reversing of Recent Gozi ISFB Banking Malware Version 2.16/2.17 (portion of ISFB v3) & "loader.dll/client.dll"
Goal : Reverse engineer and analyze one of the latest Gozi "ISFB" ( also called "Ursnif'" amongst various researchers) banking malware varia...
Video-tutorial on inspecting Windows Kernel Crash Dumps with Cerbero Suite https://www.youtube.com/watch?v=HcxH0_97taA&feature=youtu.be
YouTube
Inspecting Windows Kernel Crash Dumps with Cerbero Suite - YouTube
Exploiting an Envoy heap vulnerability https://blog.envoyproxy.io/exploiting-an-envoy-heap-vulnerability-96173d41792
Medium
Exploiting an Envoy heap vulnerability
Overview
CVE-2020-1350 - Windows DNS Server Vulnerability - SIGRed https://vrls.ws/posts/cve-2020-1350-windows-dns-server-vulnerability-sigred/
Card Fraud in a PSD2 World: A Few Examples https://www.cyberdlab.com/insights/card-fraud-in-a-psd2-world-a-few-examples
Cyberdlab
Card Fraud in a PSD2 World: A Few Examples
In this research, we share how it’s possible to bypass PSD2 required multi-factor authentication for both MasterCard and Visa cards.
Forwarded from CCN-CERT
Publicada una #vulnerabilidad en un módulo Node.js, que permitiría a un atacante producir una denegación de servicio #DoS. ¡Actualiza! https://t.co/USU7OZkaIr https://t.co/Ax67YLbf9I
www.ccn-cert.cni.es
CCN-CERT AV 66/20 Vulnerabilidad en Node.js
Bienvenido al portal de CCN-CERT
A cheatsheet with commands that can be used to perform kerberos attacks · GitHub
https://gist.github.com/TarlogicSecurity/2f221924fef8c14a1d8e29f3cb5c5c4a
https://gist.github.com/TarlogicSecurity/2f221924fef8c14a1d8e29f3cb5c5c4a
Gist
A cheatsheet with commands that can be used to perform kerberos attacks
A cheatsheet with commands that can be used to perform kerberos attacks - kerberos_attacks_cheatsheet.md
PE Emulation With Code Coverage Using Qiling and Dragon Dance https://pwnage.io/pe-code-coverage-emulation-qiling/
pwnage.io
PE Emulation With Code Coverage Using Qiling and Dragon Dance | infosec4breakfast
Qiling Emulation The Qiling emulation framework was built with the goal of emulating shellcode from various operating systems due to the ever-increasing amou...
Stealthily Access Your Android Phones: Bypass the Bluetooth Authentication https://i.blackhat.com/USA-20/Wednesday/us-20-Xu-Stealthily-Access-Your-Android-Phones-Bypass-The-Bluetooth-Authentication.pdf
List of cybersecurity resources for training, conferences, speaking, labs, reading, etc that are free all the time or during COVID-19 https://github.com/gerryguy311/CyberProfDevelopmentCovidResources/blob/master/README.md
GitHub
Free_CyberSecurity_Professional_Development_Resources/README.md at master · gerryguy311/Free_CyberSecurity_Professional_Development_Resources
An awesome list of FREE resources for training, conferences, speaking, labs, reading, etc that are free. Originally built during COVID-19 for cybersecurity professionals with downtime can take adva...
Nice explanation to capture IP packets on Windows without requiring any extra software or drivers to be installed https://www.nospaceships.com/2018/09/19/packet-capture-on-windows-without-drivers.html
NoSpaceships Ltd
Packet capture on Windows without drivers
Introduction
AVAST SecureLine VPN - Arbitrary File Creation Vulnerability https://nafiez.github.io/security/arbitrary%20file/eop/2020/07/21/avast-secureline-vpn-arb-file-eop.html
Security Research
CVE-2020-25289 - AVAST SecureLine VPN - Arbitrary File Creation Vulnerability
My Personal Security Research
Remembering old stuff :) --> Exploring the MS-DOS Stub https://osandamalith.com/2020/07/19/exploring-the-ms-dos-stub/
🔐Blog of Osanda
Exploring the MS-DOS Stub | 🔐Blog of Osanda
A long time ago when I got my first computer, I accidentally opened a 32-bit demo with a nice chiptune inside MS-DOS and it worked. I was surprised by how this happens. I was curious to find out ho…
MMS Exploit Part 2: Effective Fuzzing of the Qmage Codec https://googleprojectzero.blogspot.com/2020/07/mms-exploit-part-2-effective-fuzzing-qmage.html
projectzero.google
MMS Exploit Part 2: Effective Fuzzing of the Qmage Codec
Posted by Mateusz Jurczyk, Project ZeroThis post is the second of a multi-part series capturing m...
In Memory Cobalt Strike Shellcode Beacon decoding to evade AVs https://shells.systems/in-memory-shellcode-decoding-to-evade-avs/
Shells.Systems
In-Memory shellcode decoding to evade AVs/EDRs - Shells.Systems
Estimated Reading Time: 9 minutesDuring the previous week, I was doing some research about win32 APIs and how we can use them during weaponizing our attack, I already did some work related to process injection in the past, but I was looking for something…
Bypassing MassLogger Anti-Analysis — a Man-in-the-Middle Approach https://www.fireeye.com/blog/threat-research/2020/08/bypassing-masslogger-anti-analysis-man-in-the-middle-approach.html
Google Cloud Blog
Bypassing MassLogger Anti-Analysis — a Man-in-the-Middle Approach | Mandiant | Google Cloud Blog