Brute Ratel - Scandinavian Defence https://protectedmo.de/brute.html
Harvesting Logs for Fun and Profit https://beny23.github.io/posts/harvesting_logs_for_fun_and_profit/
beny23.github.io
Harvesting Logs for Fun and Profit
From a security point of view, application logs are two-sided. On the one hand, it is really important to have good observability, to find out what is happening and what has happened. On the other hand, we don’t want to leak sensitive information. In this…
Joomla! CVE-2023-23752 to Code Execution https://vulncheck.com/blog/joomla-for-rce
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Exploring iOS Applications with Frida and Objection: Basic Commands for Pentesting https://medium.com/@mk2011sharma/exploring-ios-applications-with-frida-and-objection-basic-commands-for-pentesting-4c637dbeb9fd
Medium
Exploring iOS Applications with Frida and Objection: Basic Commands for Pentesting
Mobile application Pentesting is an essential part of securing any organization’s mobile assets. To perform thorough penetration testing, a…
👍1
A story about tampering EDRs https://redops.at/en/blog/a-story-about-tampering-edrs
RedOps - English
A story about tampering EDRs - RedOps
Most EDRs generally use a combination of user space and kernel space components, or the kernel components often form the basis for implementing user space protection mechanisms. A good example of this is the interaction between callback routines and user…
👍1
ChinaZ DDoS Bot Malware Distributed to Linux SSH Servers https://asec.ahnlab.com/en/50316/
ASEC BLOG
ChinaZ DDoS Bot Malware Distributed to Linux SSH Servers - ASEC BLOG
AhnLab Security Emergency response Center (ASEC) has recently discovered the ChinaZ DDoS Bot malware being installed on inadequately managed Linux SSH servers. As one of the Chinese threat groups that were first discovered around 2014, the ChinaZ group installs…
👍1
ChinaZ DDoS Bot Malware Distributed to Linux SSH Servers https://asec.ahnlab.com/en/50316/
ASEC BLOG
ChinaZ DDoS Bot Malware Distributed to Linux SSH Servers - ASEC BLOG
AhnLab Security Emergency response Center (ASEC) has recently discovered the ChinaZ DDoS Bot malware being installed on inadequately managed Linux SSH servers. As one of the Chinese threat groups that were first discovered around 2014, the ChinaZ group installs…
👍2
CVE-2022-42845: 20-Year-Old XNU Use After Free Vulnerability in ndrv.c https://adamdoupe.com/blog/2022/12/13/cve-2022-42845-xnu-use-after-free-vulnerability-in-ndrv-dot-c/
Adamdoupe
CVE-2022-42845: 20-Year-Old XNU Use After Free Vulnerability in ndrv.c - Adam Doupé
I’ve been on a sabbatical this academic year, and my goal is to understand the state-of-the art in exploitation and vulnerability analysis by …
How we broke PHP, hacked Pornhub and earned $20,000 https://www.evonide.com/how-we-broke-php-hacked-pornhub-and-earned-20000-dollar/
Evonide
How we broke PHP, hacked Pornhub and earned $20,000 | Bug Bounties - Evonide
We audited Pornhub, then PHP and broke both. In particular, we have gained remote code execution on pornhub.com and have earned a $20,000 bug bounty.
How scammers employ IPFS for email phishing https://securelist.com/ipfs-phishing/109158/
Securelist
Use of IPFS in mass and targeted phishing campaigns
Attackers put phishing HTML files in IPFS thus cutting back on web hosting costs. IPFS is used in both mass phishing and targeted (spearphishing) campaigns.
Breaking Pedersen Hashes in Practice https://research.nccgroup.com/2023/03/22/breaking-pedersen-hashes-in-practice/
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
👍1
Exploiting: Buffer overflow in Xiongmai DVRs https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/
ret2.me
Exploiting: Buffer overflow in Xiongmai DVRs | ret2.me
As part of my work at FortNet I’ve had the chance to research some embedded devices. This provided a good chance to learn more about the ARM architecture and the differences between ARM and x86 exploitation.
Often, IoT is overlooked in threat assessments…
Often, IoT is overlooked in threat assessments…
OneNote Embedded URL Abuse https://blog.nviso.eu/2023/03/27/onenote-embedded-url-abuse/
NVISO Labs
OneNote Embedded URL Abuse
Whilst Microsoft is fixing the embedded files feature in OneNote I decided to abuse a whole other feature. Embedded URLs. Turns out this is something they may also have to fix.
Malware AV/VM evasion - part 14: encrypt/decrypt payload via A5/1. Bypass Kaspersky AV. Simple C++ example https://cocomelonc.github.io/malware/2023/03/24/malware-av-evasion-14.html
cocomelonc
Malware AV/VM evasion - part 14: encrypt/decrypt payload via A5/1. Bypass Kaspersky AV. Simple C++ example.
﷽
👍1
BlackGuard stealer extends its capabilities in new variant https://cybersecurity.att.com/blogs/labs-research/blackguard-stealer-extends-its-capabilities-in-new-variant
LevelBlue
BlackGuard stealer extends its capabilities in new variant
Explore the extended capabilities of the new BlackGuard Stealer variant, a growing threat in cybersecurity.
Malicious Actors Use Unicode Support in Python to Evade Detection https://blog.phylum.io/malicious-actors-use-unicode-support-in-python-to-evade-detection
Phylum Research | Software Supply Chain Security
Malicious Actors Use Unicode Support in Python to Evade Detection
Phylum uncovers a threat actor taking advantage of how the Python interpreter handles Unicode to obfuscate their malware.
Guidance for investigating attacks using CVE-2023-23397 https://www.microsoft.com/en-us/security/blog/2023/03/24/guidance-for-investigating-attacks-using-cve-2023-23397/
Microsoft News
Guidance for investigating attacks using CVE-2023-23397
This guide provides steps to assess whether users have been targeted or compromised by threat actors exploiting CVE-2023-23397.
Bypassing Email Filter which leads to SQL Injection https://dimazarno.medium.com/bypassing-email-filter-which-leads-to-sql-injection-e57bcbfc6b17
Medium
Bypassing Email Filter which leads to SQL Injection
Akhirnya nulis lagi, soalnya temuan ini menurut saya lumayan menarique jadi pengen sharing, maaf yang pakai google translate, artikel ini…
The Case For Improving Crypto Wallet Security https://blog.doyensec.com/2023/03/28/wallet-info.html
Doyensec
The Case For Improving Crypto Wallet Security
A large number of today’s crypto scams involve some sort of phishing attack, where the user is tricked into visiting a shady/malicious web site and connecting their wallet to it. The main goal is to trick the user into signing a transaction which will ultimately…