The core of Apple is PPL: Breaking the XNU kernel's kernel https://googleprojectzero.blogspot.com/2020/07/the-core-of-apple-is-ppl-breaking-xnu.html
projectzero.google
The core of Apple is PPL: Breaking the XNU kernel's kernel
Posted by Brandon Azad, Project ZeroWhile doing research for the one-byte exploit technique,...
Linux warning: TrickBot malware is now infecting your systems https://www.bleepingcomputer.com/news/security/linux-warning-trickbot-malware-is-now-infecting-your-systems/
BleepingComputer
Linux warning: TrickBot malware is now infecting your systems
TrickBot's Anchor malware platform has been ported to infect Linux devices and compromise further high-impact and high-value targets using covert channels.
CVE-2020–9854: "Unauthd" (code available in https://github.com/A2nkF/unauthd) https://objective-see.com/blog/blog_0x4D.html
GitHub
GitHub - A2nkF/unauthd: A local privilege escalation chain from user to kernel for MacOS < 10.15.5. CVE-2020–9854
A local privilege escalation chain from user to kernel for MacOS < 10.15.5. CVE-2020–9854 - GitHub - A2nkF/unauthd: A local privilege escalation chain from user to kernel for MacOS < ...
DUT Processes in Windows 10 https://windows-internals.com/dut-processes-in-windows-10/
Write-Up 02- TryHackMe- Basic Pentesting https://medium.com/bugbountywriteup/write-up-02-tryhackme-basic-pentesting-797dbd0721df
Medium
Write-Up 02- TryHackMe- Basic Pentesting
This writeup is about the Basic Pentesting Room on the TryHackMe Platform. I am going to explain in detail the procedure involved in…
Over 70% of ICS Vulnerabilities Disclosed in First Half of 2020 Remotely Exploitable https://www.securityweek.com/over-70-ics-vulnerabilities-disclosed-first-half-2020-remotely-exploitable
Securityweek
Over 70% of ICS Vulnerabilities Disclosed in First Half of 2020 Remotely Exploitable | SecurityWeek.Com
Over 70% of the ICS vulnerabilities disclosed in the first half of 2020 were remotely exploitable, Claroty reports
Microsoft Joins Open Source Security Foundation https://www.microsoft.com/security/blog/2020/08/03/microsoft-open-source-security-foundation-founding-member-securing-open-source-software/
Microsoft Security Blog
Microsoft Joins Open Source Security Foundation | Microsoft Security Blog
We're excited to announce that that Microsoft is joining industry partners to create the Open Source Security Foundation (OpenSSF), a new cross-industry collaboration hosted at the Linux Foundation.
How to Create Unlimited Rotating IP Addresses with AWS https://medium.com/@devinjaystokes/using-proxycannon-ng-to-create-unlimited-rotating-proxies-fccffa70a728
Medium
How to Create Unlimited Rotating IP Addresses with AWS
We can increase our capabilities to distribute our HTTP requests over a larger and larger pool of networks.
Removing Kernel Callbacks Using Signed Drivers https://br-sn.github.io/Removing-Kernel-Callbacks-Using-Signed-Drivers/
CPR Anti-Debug Encyclopedia: The Check Point Anti-Debug Techniques Repository https://research.checkpoint.com/2020/cpr-anti-debug-encyclopedia-the-check-point-anti-debug-techniques-repository/
Check Point Research
CPR Anti-Debug Encyclopedia: The Check Point Anti-Debug Techniques Repository - Check Point Research
Debugging is the essential part of malware analysis. Every time we need to drill down into malware behavior, restore encryption methods or examine communication protocols – generally, whenever we need to examine memory at a certain moment of time – we use…
A Ghidra framework for iOS kernelcache reverse engineering https://github.com/0x36/ghidra_kernelcache/
GitHub
GitHub - 0x36/ghidra_kernelcache: a Ghidra framework for iOS kernelcache reverse engineering
a Ghidra framework for iOS kernelcache reverse engineering - 0x36/ghidra_kernelcache
Netenum - A Tool To Passively Discover Active Hosts On A Network https://www.kitploit.com/2020/08/netenum-tool-to-passively-discover.html
KitPloit - PenTest & Hacking Tools
Netenum - A Tool To Passively Discover Active Hosts On A Network
Attacks on Implementations of Secure Systems --> handbook of the course taught in 2020 at Ben-Gurion University by Dr. Yossi Oren https://github.com/Yossioren/AttacksonImplementationsCourseBook
GitHub
GitHub - Yossioren/AttacksonImplementationsCourseBook
Contribute to Yossioren/AttacksonImplementationsCourseBook development by creating an account on GitHub.
Exploiting Android Messengers with WebRTC: Part 2 https://googleprojectzero.blogspot.com/2020/08/exploiting-android-messengers-part-2.html
projectzero.google
Exploiting Android Messengers with WebRTC: Part 2
Posted by Natalie Silvanovich, Project ZeroThis is a three-part series on exploiting messenger ap...
The Current State of Exploit Development, Part 1
https://www.crowdstrike.com/blog/state-of-exploit-development-part-1/
https://www.crowdstrike.com/blog/state-of-exploit-development-part-1/
The Art Of Mac Malware https://taomm.org/
taomm.org
The Art of Mac Malware
Books about Mac malware (by Patrick Wardle)
Demystifying Modern Windows Rootkits #BlackHatUSA #2020 https://billdemirkapi.me/slides/Demystifying-Modern-Windows-Rootkits-BH.pdf
So you've decided you want to write a Windows rootkit. Good thing this chap's just demystified it in a talk https://www.theregister.com/2020/08/07/def_con_demirkapi/
The Register
So you've decided you want to write a Windows rootkit. Good thing this chap's just demystified it in a talk
Demirkapi shows how drivers can be misused for deep pwnage
Another interesting talk of #BlackHatUSA #2020 "Reversing the Root: Identifying the Exploited Vulnerability in 0-days Used In-The-Wild" https://github.com/maddiestone/ConPresentations/blob/master/BH2020.ReversingTheRoot.pdf
A Brief History of Recent Advances in IPv6 Security, Part I: Addressing https://www.si6networks.com/2020/08/06/a-brief-history-of-recent-advances-in-ipv6-security-part-i/