Gitpod remote code execution 0-day vulnerability via WebSockets https://snyk.io/blog/gitpod-remote-code-execution-vulnerability-websockets/
Snyk Labs
Gitpod remote code execution 0-day vulnerability via WebSockets | Snyk Labs
Using compilation units for binary diffing https://github.com/joxeankoret/diaphora/blob/master/doc/articles/compilation_units.md
GitHub
diaphora/doc/articles/compilation_units.md at master · joxeankoret/diaphora
Diaphora, the most advanced Free and Open Source program diffing tool. - joxeankoret/diaphora
Persistence Techniques That Persist https://www.cyberark.com/resources/threat-research-blog/persistence-techniques-that-persist
Cyberark
Persistence Techniques That Persist
Abstract Once threat actors gain a foothold on a system, they must implement techniques to maintain that access, even in the event of restarts, updates in credentials or any other type of change...
Linux Rootkits Part 3: A Backdoor to Root https://xcellerator.github.io/posts/linux_rootkits_03/
Linux Rootkits Part 3: A Backdoor to Root
Linux Rootkits Part 3: A Backdoor to Root :: TheXcellerator
Now that you know how to make a Linux kernel module that can hook any exposed function in kernel memory (Part 1 and Part 2), let’s get down to writing a hook that does something interesting!
In this first example, we’re going to make a rootkit that intercepts…
In this first example, we’re going to make a rootkit that intercepts…
Lord Of The Ring0 - Part 4 | The call back home https://idov31.github.io/2023/02/24/lord-of-the-ring0-p4.html
Understanding the Context of Cyber Threats: Lessons from the Kimsuky Group Attack https://sp4rk.medium.com/understanding-the-context-of-cyber-threats-lessons-from-the-kimsuky-group-attack-3d026c5629bc
Medium
Understanding the Context of Cyber Threats: Lessons from the Kimsuky Group Attack
Kimsuky is the most active cyber threat actor who consistently targets North Korean-related institutions, companies, media, academia, and…
Acronis gets embarrassed by 'bored' hacker https://www.hackwatcher.com/p/acronis-gets-embarrassed-by-bored-hacker
Root Cause Analysis of the in the wild JIT bug (CVE-2022-42856) https://voidistaff.github.io/safari/2023/02/20/CVE-2022-42856.html
A New Vector For “Dirty” Arbitrary File Write to RCE https://blog.doyensec.com//2023/02/28/new-vector-for-dirty-arbitrary-file-write-2-rce.html
Doyensec
A New Vector For “Dirty” Arbitrary File Write to RCE
Arbitrary file write (AFW) vulnerabilities in web application uploads can be a powerful tool for an attacker, potentially allowing them to escalate their privileges and even achieve remote code execution (RCE) on the server. However, the specific tactics…
🔥1
DNSMonitor: Leveraging Apple's Network Extension Framework, this utility monitors DNS requests and responses https://objective-see.org/products/utilities.html#DNSMonitor
objective-see.org
Commandline Utilities
CLI utilities to facilate system monitoring and malware analysis.
👍1
Smart Contracts Security: Exploring Common Bugs https://playground.zero-defense.com/blog/smart-contracts-security/
Decoding BlazorPack https://sensepost.com/blog/2023/decoding-blazorpack/
Pwning the Dlink 850L routers and abusing the MyDlink Cloud protocol https://pierrekim.github.io/blog/2017-09-08-dlink-850l-mydlink-cloud-0days-vulnerabilities.html
CVE-2023-1112 - Drag and Drop Multiple File Uploader PRO - Contact Form 7 v5.0.6.1 Path Traversal https://github.com/Nickguitar/Drag-and-Drop-Multiple-File-Uploader-PRO-Path-Traversal
GitHub
GitHub - Nickguitar/Drag-and-Drop-Multiple-File-Uploader-PRO-Path-Traversal: Drag and Drop Multiple File Uploader PRO - Contact…
Drag and Drop Multiple File Uploader PRO - Contact Form 7 v5.0.6.1 Path Traversal (CVE-2023-1112) - Nickguitar/Drag-and-Drop-Multiple-File-Uploader-PRO-Path-Traversal
The Blitz Tutorial Lab on Fuzzing with AFL++ https://research.checkpoint.com/2023/the-blitz-tutorial-lab-on-fuzzing-with-afl/
🔥2👍1
PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749 https://mahaloz.re/2023/02/25/pwnagent-netgear.html
mahaloz.re
PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749
A breakdown of a bug SEFCOM T0 and I exploited to achieve a WAN-side RCE in some Netgear RAX routers for pwn2own 2022. The bug is a remotely accessible comma...
Akuvox Smart Intercom Vulnerabilities Leave Privacy Ajar https://claroty.com/team82/blog/akuvox-smart-intercom-vulnerabilities-leave-privacy-ajar
Claroty
Akuvox Smart Intercom Vulnerabilities Leave Privacy Ajar
Recovering a full PEM Private Key when half of it is redacted https://blog.cryptohack.org/twitter-secrets
CryptoHack
Recovering a full PEM Private Key when half of it is redacted
The @CryptoHack__ account was pinged today by ENOENT, with a CTF-like challenge found in the wild: Source tweet. Here’s a write-up covering how given a partially redacted PEM, the whole private key can be recovered.