Corrupting memory without memory corruption https://github.blog/2022-07-27-corrupting-memory-without-memory-corruption/
The GitHub Blog
Corrupting memory without memory corruption
In this post I’ll exploit CVE-2022-20186, a vulnerability in the Arm Mali GPU kernel driver and use it to gain arbitrary kernel memory access from an untrusted app on a Pixel 6. This then allows me to gain root and disable SELinux. This vulnerability highlights…
Effectively mitigating CSRF https://exact.realty/blog/posts/2022/12/29/csrf-prevention/
This brings me good memories :') » SoftICE-like kernel debugger for Windows 11 https://github.com/vitoplantamura/BugChecker
GitHub
GitHub - vitoplantamura/BugChecker: SoftICE-like kernel debugger for Windows 11
SoftICE-like kernel debugger for Windows 11. Contribute to vitoplantamura/BugChecker development by creating an account on GitHub.
Analyzing CVE-2022-46330 (DLL Hijacking in Squirrel.Windows)
https://archcloudlabs.com/projects/cve-2022-46330/
https://archcloudlabs.com/projects/cve-2022-46330/
Arch Cloud Labs
Analyzing CVE-2022-46330 (DLL Hijacking in Squirrel.Windows)
About The Project In December of 2022, a DLL Hijacking vulnerability with a CVSS score of 7.8 was reported in the Squirrel.Windows auto-install/update utility. This blog post will analyze the vulnerability, and the root cause of said issue with procmon.
Analyzing…
Analyzing…
Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys https://blog.dixitaditya.com/manipulating-aes-traffic-using-a-chain-of-proxies-and-hardcoded-keys
👍1
Unwrapping Ursnifs Gifts https://thedfirreport.com/2023/01/09/unwrapping-ursnifs-gifts/
The DFIR Report
Unwrapping Ursnifs Gifts - The DFIR Report
In late August 2022, we investigated an incident involving Ursnif malware, which resulted in Cobalt Strike being deployed. This was followed by the threat actors moving laterally throughout the environment using an admin account. The Ursnif malware family…
DotDumper - An Automatic Unpacker And Logger For DotNet Framework Targeting Files https://www.kitploit.com/2023/01/dotdumper-automatic-unpacker-and-logger.html
KitPloit - PenTest & Hacking Tools
DotDumper - An Automatic Unpacker And Logger For DotNet Framework Targeting Files
A detailed explanation of Kubernetes architecture principles https://medium.com/@Zard-x/a-detailed-explanation-of-kubernetes-architecture-principles-26abcac29f7c
How to Continuously Detect Vulnerable Jenkins Plugins to Avoid a Software Supply Chain Attack https://www.legitsecurity.com/blog/how-to-continuously-detect-vulnerable-jenkins-plugins-to-avoid-a-software-supply-chain-attack
Legitsecurity
How to Continuously Detect Vulnerable Jenkins Plugins to Avoid a Software Supply Chain Attack
See how attackers used compromised Jenkins plugins to attack the software supply chain and how to continuously detect vulnerable Jenkins plugins at scale.
LuaJIT Sandbox Escape: The Saga Ends https://0xbigshaq.github.io/2022/12/30/luajit-sandbox-escape/
( ͡◕ _ ͡◕)👌
LuaJIT Sandbox Escape: The Saga Ends
👍1
🧐🧐 »The Dark Side of Gmail https://osintmatter.com/the-dark-side-of-gmail/
🥱2
Understanding Windows Lateral Movements https://attl4s.github.io/assets/pdf/Understanding_Windows_Lateral_Movements.pdf
Malicious Macros Adapt to Use Microsoft Publisher to Push Ekipa RAT https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/malicious-macros-adapt-to-use-microsoft-publisher-to-push-ekipa-rat/
👍1
Shc Linux Malware Installing CoinMiner https://asec.ahnlab.com/en/45182/
ASEC
Shc Linux Malware Installing CoinMiner - ASEC
Shc Linux Malware Installing CoinMiner ASEC
CVE-2022-27643 - NETGEAR R6700v3 upnpd Buffer Overflow Remote Code Execution Vulnerability https://blog.relyze.com/2022/03/cve-2022-27643-netgear-r6700v3-upnpd.html
TetCTF 2023: pwn01 https://b6a.black/posts/2023-01-09-tetctf-pwn01/
b6a.black
TetCTF 2023: pwn01
I did not solve it in time (30 minutes late T.T). However, I spent quite of lot of time on this challenge, so I might as well do a write up. Special thanks to Mystiz, fsharp, cire meat pop for helping me on this challenge.
👍1
"Pre-Owned" malware in ROM on T95 Android TV Box (AllWinner H616) https://github.com/DesktopECHO/T95-H616-Malware
GitHub
GitHub - DesktopECHO/T95-H616-Malware: "Pre-Owned" malware in ROM for AllWinner H616/H618 & RockChip RK3328 Android TV Boxes
"Pre-Owned" malware in ROM for AllWinner H616/H618 & RockChip RK3328 Android TV Boxes - DesktopECHO/T95-H616-Malware