Test Point Break: Analysis of Huawei’s OTA Fix For BootROM Vulnerabilities https://labs.taszk.io/articles/post/huawei_kirin990_bootrom_patch/
labs.taszk.io
Test Point Break: Analysis of Huawei’s OTA Fix For BootROM Vulnerabilities
Reverse engineering the OTA that broke the bootrom exploits
👍2
So long passwords, thanks for all the phish https://security.googleblog.com/2023/05/so-long-passwords-thanks-for-all-phish.html
Google Online Security Blog
So long passwords, thanks for all the phish
By: Arnar Birgisson and Diana K Smetters, Identity Ecosystems and Google Account Security and Safety teams Starting today , you can create a...
CVE-2023-29383: Abusing Linux chfn to Misrepresent /etc/passwd https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-29383-abusing-linux-chfn-to-misrepresent-etc-passwd/
Trustwave
CVE-2023-29383: Abusing Linux chfn to Misrepresent etc passwd | Trustwave
Two years ago, I picked out chfn as a candidate to be reviewed for security bugs. Why chfn I hear you ask? (Thanks for asking.) It is one of a small number of Set owner User ID (SUID) programs loaded with Linux which means it runs with the permissions of…
Leveraging XFG to help with reverse engineering https://m417z.com/Leveraging-XFG-to-help-with-reverse-engineering/
M417Z
Leveraging XFG to help with reverse engineering
Microsoft eXtended Flow Guard (XFG) is a control-flow integrity (CFI) technique that extends CFG with function call signatures. It was presented by Microsoft in 2019, and it’s an interesting mitigation, but this blog post isn’t going to discuss its security…
Some great notes on macOS Internals https://gist.github.com/kconner/cff08fe3e0bb857ea33b47d965b3e19f
Gist
macOS Internals
macOS Internals. GitHub Gist: instantly share code, notes, and snippets.
👍1
santa: A binary authorization system for macOS https://github.com/google/santa
GitHub
GitHub - google/santa: A binary authorization and monitoring system for macOS
A binary authorization and monitoring system for macOS - google/santa
👍1
CVE-2021-38001: A Brief Introduction to V8 Inline Cache and Exploitating Type Confusion https://y4y.space/2023/05/06/cve-2021-38001-a-brief-introduction-to-v8-inline-cache-and-exploitating-type-confusion/
www.y4y.space
CVE-2021-38001: A Brief Introduction to V8 Inline Cache and Exploitating Type Confusion · y4y
Some Background Info
AgentTesla - Full Loader Analysis - Resolving API Hashes Using Conditional Breakpoints https://embee-research.ghost.io/agenttesla-full-analysis-api-hashing/
Embee Research
AgentTesla Malware Analysis - How To Resolve API Hashes With Conditional Breakpoints
Analysis of a Multi-Stage Loader for AgentTesla. Covering Ghidra, Dnspy, X32dbg, API Hashing and more!
Deobfuscating the Recent Emotet Epoch 4 Macro https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/deobfuscating-the-recent-emotet-epoch-4-macro/
Trustwave
Deobfuscating the Recent Emotet Epoch 4 Macro
I’ve always been fascinated by wireless communications. The ability to launch seemingly invisible packets of information up into the air without even the need to consider aerodynamics itself seems like some kind of magic.
strings2 - Extract strings from binary files and process memory https://github.com/glmcdona/strings2
GitHub
GitHub - glmcdona/strings2: strings2: An improved strings extraction tool.
strings2: An improved strings extraction tool. Contribute to glmcdona/strings2 development by creating an account on GitHub.
Finding 0-day vulnerabilities in apps using the Red Team approach(RTC0005) https://redteamrecipe.com/Finding-0-day-vulnerabilities-in-apps-using-the-Red-Team-approach/
ExpiredDomains.com
redteamrecipe.com is for sale! Check it out on ExpiredDomains.com
Buy redteamrecipe.com for 195 on GoDaddy via ExpiredDomains.com. This premium expired .com domain is ideal for establishing a strong online identity.
Ethereum Transactions: 101 Things You Need to Know https://medium.com/@sergiomazariego/ethereum-transactions-101-things-you-need-to-know-d2e39cc1b10
Medium
Ethereum Transactions: 101 Things You Need to Know
IntroductionIn this blog post, you will find explanations of the basic concepts, terminologies, and technicalities involved in…
Auditing the Home Assistant Pre-Auth Attack Surface https://www.elttam.com/blog/pwnassistant/
Elttam
PwnAssistant - Controlling /home's via a Home Assistant RCE - elttam
How we found a critical pre-authentication RCE in Home Assistant, exploring the attack surface and publishing advisories including CVE-2023-27482.
Vulnerability Analysis with Ghidra Scripting https://medium.com/@cy1337/vulnerability-analysis-with-ghidra-scripting-ccf416cfa56d
Medium
Vulnerability Analysis with Ghidra Scripting
As some of you may have seen, I posted a challenge to use Ghidra to identify a vulnerability in a WarGames themed game. There has been a…
The Art of Clipboard Forensics Recovering Deleted Data https://xret2pwn.github.io/The-Art-of-Clipboard-Forensics-Recovering-Deleted-Data/
RET2Pwn
The Art of Clipboard Forensics Recovering Deleted Data
Introduction
🔥1
GULoader Campaigns: A Deep Dive Analysis of a highly evasive Shellcode based loader https://www.mcafee.com/blogs/other-blogs/mcafee-labs/guloader-campaigns-a-deep-dive-analysis-of-a-highly-evasive-shellcode-based-loader/
McAfee Blog
GULoader Campaigns: A Deep Dive Analysis of a highly evasive Shellcode based loader | McAfee Blog
Authored by: Anandeshwar Unnikrishnan Stage 1: GULoader Shellcode Deployment In recent GULoader campaigns, we are seeing a rise in NSIS-based installers
Fantastic Rootkits: And Where to Find Them (Part 1) https://www.cyberark.com/resources/threat-research-blog/fantastic-rootkits-and-where-to-find-them-part-1
Cyberark
Fantastic Rootkits: And Where to Find Them (Part 1)
Introduction In this blog series, we will cover the topic of rootkits — how they are built and the basics of kernel driver analysis — specifically on the Windows platform. In this first part, we...
👍2
Analysis of DHCP Service Remote Code Execution Vulnerability CVE-2023–28231https://medium.com/numen-cyber-labs/analysis-of-dhcp-service-remote-code-execution-vulnerability-cve-2023-28231-a4ce9f3a3fd
Medium
Analysis of DHCP Service Remote Code Execution Vulnerability CVE-2023–28231
CVE-2023–28231 Patch Analysis, with PoC
👍1