How to Unpack Protected Android APK with Frida https://www.youtube.com/watch?v=PLX8_z0EmGw
YouTube
How to Unpack Protected Android APK with Frida
#androidpentest #dexdump #frida #apkunpacking #memdump
In this video we unpacked an APK file named AntiSplit-G2. All the classes in this application are protected using some kind of protector and the classes gets extracted into the memory as a de file by…
In this video we unpacked an APK file named AntiSplit-G2. All the classes in this application are protected using some kind of protector and the classes gets extracted into the memory as a de file by…
Windows LAPS - New Group Policy Settings https://www.kaidojarvemets.com/windows-laps-new-group-policy-settings/
Kaido Järvemets - Fuelled By Passion. Driven by Tech.
Windows LAPS – New Group Policy Settings - Kaido Järvemets
Explore the new Group Policy settings for Windows LAPS, providing IT admins with increased control over local administrator account passwords.
[Responsible Disclosure] How we could have deleted any Linkedin post https://www.pingsafe.com/blog/linkedin-vulnerability-delete-any-post
PingSafe
PingSafe
SentinelOne
Cloud
Protecting your cloud workloads from malicious attacks is critical to keep your business up and running. The Singularity Cloud Workload Security is a complete runtime protection solution for multi-cloud workloads that offers comprehensive security controls…
A Practical, AI-Generated Phishing PoC With ChatGPT https://curtbraz.medium.com/a-practical-ai-generated-phishing-poc-f81d3c3da76b
Medium
A Practical, AI-Generated Phishing PoC With ChatGPT
Intro
Memory corruption in JCRE: An unpatchable HSM may swallow your private key https://hardenedvault.net/blog/2023-04-18-java-card-runtime-memory-corruption/
hardenedvault.net
Memory corruption in JCRE: An unpatchable HSM may swallow your private key
Background The key has always been a core target of security protection.
Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2 https://www.cyberark.com/resources/threat-research-blog/breaking-docker-named-pipes-systematically-docker-desktop-privilege-escalation-part-2
Cyberark
Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2
In the previous blog post, we described how the Docker research started and showed how we could gain a full privilege escalation through a vulnerability in Docker Desktop. In this follow-up blog...
Threat Actors Rapidly Adopt Web3 IPFS Technology https://unit42.paloaltonetworks.com/ipfs-used-maliciously/
Unit 42
Threat Actors Rapidly Adopt Web3 IPFS Technology
Web3 technologies are seeing widespread adoption — including by TAs. We discuss Web3 technology InterPlanetary File System (IPFS), and malicious use of it.
👍1
APT28 Attacks on Cisco Routers: What We Know So Far https://www.securityengineering.dev/apt28-cisco-routers-vulnerability-april-2023/
Security Engineering Notebook
APT28 Attacks on Cisco Routers: What We Know So Far
Russian cyber-attack targets Cisco devices. Read on for the details and suggested mitigations.
Detecting and decrypting Sliver C2 – a threat hunter’s guide https://www.immersivelabs.com/blog/detecting-and-decrypting-sliver-c2-a-threat-hunters-guide/
Immersivelabs
Detecting and decrypting Sliver C2 – a threat hunter's guide
Originating from the Bishop Fox team, Sliver is an open-source, cross-platform, and extensible C2 framework. It’s written primarily in Go, making it fast, portable, and easy to customize.
CVE-2023-0339 — Technical Analysis https://attackerkb.com/topics/BYpdQRJKJd/cve-2023-0339/rapid7-analysis
AttackerKB
CVE-2023-0339 | AttackerKB
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Po…
The Fuzzing Guide to the Galaxy: An Attempt with Android System Services https://blog.thalium.re/posts/fuzzing-samsung-system-services/
THALIUM
The Fuzzing Guide to the Galaxy: An Attempt with Android System Services
Although the Android base is open source, many different constructors customize it with their own UIs and APIs. All these additions represent an extra attack surface that can change from one phone model to another. We tried to automatically fuzz the closed…
The Fuzzing Guide to the Galaxy: An Attempt with Android System Services https://blog.thalium.re/posts/fuzzing-samsung-system-services/
THALIUM
The Fuzzing Guide to the Galaxy: An Attempt with Android System Services
Although the Android base is open source, many different constructors customize it with their own UIs and APIs. All these additions represent an extra attack surface that can change from one phone model to another. We tried to automatically fuzz the closed…
Everything-is-wrong writeup: Reverse engineering Haskell like a masochist https://medium.com/@acheron2302/everything-is-wrong-writeup-reverse-engineering-haskell-like-a-masochist-9586f033d397
Medium
Everything-is-wrong writeup: Reverse engineering Haskell like a masochist
Disclaimer: My understanding about haskell reverse engineering is still limited so if I am wrong about anything feel free to ping me on my…
CVE-2023-29084 Command injection in ManageEngine ADManager Plus https://hnd3884.github.io/posts/CVE-2023-29084-Command-injection-in-ManageEngine-ADManager-plus/
HoangND
CVE-2023-29084 Command injection in ManageEngine ADManager Plus
CVE-2023-29084 analysis
A Journey Through the Secrets of Firmware: Exploring the Foundations https://medium.com/@tristejoursoir/a-journey-through-the-secrets-of-firmware-exploring-the-foundations-6d0d288d5917
Medium
A Journey Through the Secrets of Firmware: Exploring the Foundations
A lot of people are interested in how the computer starts up. This is where the magic begins and continues as long as the device is on. In…
nice blog series » mast1c0re: Introduction – Exploiting the PS4 and PS5 through a game save https://mccaulay.co.uk/mast1c0re-introduction-exploiting-the-ps4-and-ps5-through-a-gamesave/
Producing a POC for CVE-2022-42475 (Fortinet RCE) https://blog.scrt.ch/2023/03/14/producing-a-poc-for-cve-2022-42475-fortinet-rce/