Bare Bones Banking malware coded for research & educational purposes https://github.com/1d8/Coqui
GitHub
GitHub - 1d8/Coqui: Bare Bones Banking malware coded for research & educational purposes
Bare Bones Banking malware coded for research & educational purposes - 1d8/Coqui
ATM makers Diebold and NCR deploy fixes for 'deposit forgery' attacks https://www.zdnet.com/article/atm-makers-diebold-and-ncr-deploy-fixes-for-deposit-forgery-attacks/
ZDNet
ATM makers Diebold and NCR deploy fixes for 'deposit forgery' attacks | ZDNet
ATMs from the two companies had bugs that could have allowed card fraudsters to modify the amount of money they deposited on their card, and then abuse the new account balance for illegal cash withdrawals.
TERRACOTTA Android Malware: A Technical Study https://www.whiteops.com/blog/terracotta-android-malware-a-technical-study
HUMAN Security
TERRACOTTA Android Malware: A Technical Study - HUMAN Security
The Satori Threat Intelligence & Research Team takes a deep dive into the TERRACOTTA ad fraud operation and its sophistication.
Interesting thread on Windows logon activty behind the curtain https://twitter.com/SteveSyfuhs/status/1297957799079510018?s=09
Twitter
Steve Syfuhs
Have you ever wondered what happens behind the scenes when you type your password into the Windows logon screen and hit enter? I'm waiting for a build to complete, so I'm gonna tell you.
An Interview With RedBear: A Hacker Training the Next Generation of Cybercriminals https://therecord.media/an-interview-with-redbear-a-hacker-training-the-next-generation-of-cybercriminals/
The Record
An Interview With RedBear: A Hacker Training the Next Generation of Cybercriminals
A security intelligence analyst interviews RedBear, a hacker and malware tester who is training the next generation of cybercriminals.
Transparent Tribe: Evolution analysis,
part 1 https://securelist.com/transparent-tribe-part-1/98127/
part 1 https://securelist.com/transparent-tribe-part-1/98127/
Malicious Apps Could Take Over Samsung Devices https://char49.com/articles/malicious-apps-could-take-over-samsung-devicesv
Nice description of Windows internals --> One Windows Kernel https://techcommunity.microsoft.com/t5/windows-kernel-internals/one-windows-kernel/ba-p/267142
TECHCOMMUNITY.MICROSOFT.COM
One Windows Kernel
Windows is one of the most versatile and flexible operating systems out there, running on a variety of machine architectures and available in multiple SKUs. It currently supports x86, x64, ARM and ARM64 architectures. Windows used to support Itanium, PowerPC…
Exploit Development: Between a Rock and a (Xtended Flow) Guard Place: Examining XFG https://connormcgarr.github.io/examining-xfg/
Connor McGarr’s Blog
Exploit Development: Between a Rock and a (Xtended Flow) Guard Place: Examining XFG
Taking a look at Microsoft’s new forward-edge CFI solution: Xtended Flow Guard
A Voyage to Uncovering Telemetry: Identifying RPC Telemetry for Detection Engineers https://ipc-research.readthedocs.io/en/latest/subpages/RPC.html
Full disclosure: 0day vulnerability (backdoor) in firmware for Xiaongmai-based DVRs, NVRs and IP cameras https://habr.com/en/post/486856/
Habr
Full disclosure: 0day vulnerability (backdoor) in firmware for Xiaongmai-based DVRs, NVRs and IP cameras
This is a full disclosure of recent backdoor integrated into DVR/NVR devices built on top of HiSilicon SoC with Xiaongmai firmware. Described vulnerability...
Russia’s Approach to Cyber Warfare (by CNA) https://www.cna.org/cna_files/pdf/DOP-2016-U-014231-1Rev.pdf
Detailed Analysis of Ghostcat Vulnerability (Cve-2020–1938) in Apache Tomcat Servers https://medium.com/bugbountywriteup/detailed-analysis-of-ghostcat-vulnerability-cve-2020-1938-in-apache-tomcat-servers-and-using-it
Improvements of fuzzing techniques in Vuzzer https://hajjik666.blogspot.com/2020/08/improvements-of-fuzzing-techniques-in.html
Blogspot
Improvements of fuzzing techniques in Vuzzer
Hi, this is my report of my academic internship at the University of Bristol’s Cyber security group. This Cyber security group works on ...
Why you should always scan UDP ports (part 1/2) https://medium.com/bugbountywriteup/why-you-should-always-scan-udp-ports-part-1-2-d8ee7eb26727
Medium
Why you should always scan UDP ports (part 1/2)
IntroductIn this story we’ll see how we exploited snmp vulnerabilities, bypassed firewall rules and AppArmor to compromise the network.
Proxyjump, the SSH option you probably never heard of https://medium.com/maverislabs/proxyjump-the-ssh-option-you-probably-never-heard-of