The Current State of Exploit Development, Part 1
https://www.crowdstrike.com/blog/state-of-exploit-development-part-1/
https://www.crowdstrike.com/blog/state-of-exploit-development-part-1/
The Art Of Mac Malware https://taomm.org/
taomm.org
The Art of Mac Malware
Books about Mac malware (by Patrick Wardle)
Demystifying Modern Windows Rootkits #BlackHatUSA #2020 https://billdemirkapi.me/slides/Demystifying-Modern-Windows-Rootkits-BH.pdf
So you've decided you want to write a Windows rootkit. Good thing this chap's just demystified it in a talk https://www.theregister.com/2020/08/07/def_con_demirkapi/
The Register
So you've decided you want to write a Windows rootkit. Good thing this chap's just demystified it in a talk
Demirkapi shows how drivers can be misused for deep pwnage
Another interesting talk of #BlackHatUSA #2020 "Reversing the Root: Identifying the Exploited Vulnerability in 0-days Used In-The-Wild" https://github.com/maddiestone/ConPresentations/blob/master/BH2020.ReversingTheRoot.pdf
A Brief History of Recent Advances in IPv6 Security, Part I: Addressing https://www.si6networks.com/2020/08/06/a-brief-history-of-recent-advances-in-ipv6-security-part-i/
Windows Print Spooler Patch Bypass Re-Enables Persistent Backdoor https://www.zerodayinitiative.com/blog/2020/8/11/windows-print-spooler-patch-bypass-re-enables-persistent-backdoor
Zero Day Initiative
Zero Day Initiative — Windows Print Spooler Patch Bypass Re-Enables Persistent Backdoor
In May 2020, Microsoft patched CVE-2020-1048 , a critical privilege escalation bug in Windows. Through this vulnerability, an attacker with the ability to execute low-privileged code on a Windows machine can easily establish a persistent backdoor, allowing…
Robots, Oracles and Protocols; Breaking Cryptography Through Information Leakage https://medium.com/dataseries/robots-oracles-and-protocols-breaking-cryptography-through-information-leakage-3a1e73c9483a
Medium
A Guided Tour of Adaptive Chosen Ciphertext Attacks
The field of Cryptography is amongst the most important in all of academia, while also being the most difficult to get right. Being…
Analyzing a buffer overflow in the DLINK DIR-645 with Qiling framework and Ghidra https://nahueldsanchez.wordpress.com/2020/08/10/analizing-a-buffer-overflow-in-the-dlink-dir-645-with-qiling-framework-and-ghidra/
Naah's blog
Analyzing a buffer overflow in the DLINK DIR-645 with Qiling framework and Ghidra
Over the last couple of weeks I’ve been playing with Qiling framework, a super interesting project that I recommend you to give a try. As I think that the best way to learn is doing, I wanted…
How Malicious Tor Relays are Exploiting Users in 2020 (Part I) https://medium.com/@nusenu/how-malicious-tor-relays-are-exploiting-users-in-2020-part-i-1097575c0cac
Medium
How Malicious Tor Relays are Exploiting Users in 2020 (Part I)
>23% of the Tor network’s exit capacity has been attacking Tor users
Course materials for Advanced Binary Deobfuscation by NTT Secure Platform Laboratories https://github.com/malrev/ABD
GitHub
GitHub - malrev/ABD: Course materials for Advanced Binary Deobfuscation by NTT Secure Platform Laboratories
Course materials for Advanced Binary Deobfuscation by NTT Secure Platform Laboratories - malrev/ABD
Digging the Adobe Sandbox - IPC Internals http://dronesec.pw/blog/2020/08/07/digging-the-adobe-sandbox-internals/
dronesec.pw
Digging the Adobe Sandbox - IPC Internals -
This post kicks off a short series into reversing the Adobe Reader sandbox. I initially started this research early last year and have been working …
Discovery and analysis of a Windows PhoneBook Use-After-Free vulnerability (CVE-2020-1530)
https://symeonp.github.io/2020/12/08/phonebook-uaf-analysis.html
https://symeonp.github.io/2020/12/08/phonebook-uaf-analysis.html
Ciphey is an automated decryption tool. Input encrypted text, get the decrypted text back https://github.com/Ciphey/Ciphey
GitHub
GitHub - bee-san/Ciphey: ⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes…
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡ - bee-san/Ciphey
Malwoverview is a first response tool to perform an initial and quick triage in a directory containing malware samples, specific malware sample, suspect URL and domains https://github.com/alexandreborges/malwoverview
GitHub
GitHub - alexandreborges/malwoverview: Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis…
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, ...
App Attest: (Properly!) Protecting iOS apps from Jailbreak Tweaks in iOS 14 https://swiftrocks.com/app-attest-apple-protect-ios-jailbreak
Swiftrocks
App Attest: How to prevent an iOS app's APIs from being abused
As (possibly) a response to jailbreaking become popular again in recent times, Apple has released their own solution to hackers creating compromised versions of your app.
Defense Evasion: Hide Artifacts https://www.hackingarticles.in/defense-evasion-hide-artifacts/
Hacking Articles
Defense Evasion: Hide Artifacts - Hacking Articles
Today, in this article, we will focus on various methods that are implemented by an attacker to evade their detection by hiding artifacts in the