More angr - Defeating 5 ELF Crackmes https://binaryresearch.github.io/2020/01/22/more-angr-defeating-5-ELF-crackmes.html
What is a canary, how does it work, and what does that mean if I want to write a modern exploit https://aaronryool.blogspot.com/2020/07/what-is-canary-how-does-it-work-and.html
Blogspot
What is a canary, how does it work, and what does that mean if I want to write a modern exploit.
Canaries were once regularly used in coal mining as an early warning system . Toxic gases such as carbon monoxide or asphyxiant gases...
CVE-2020-1337 – PrintDemon is dead, long live PrintDemon! https://voidsec.com/cve-2020-1337-printdemon-is-dead-long-live-printdemon/
VoidSec
CVE-2020-1337 – PrintDemon is dead, long live PrintDemon! - VoidSec
Vulnerability description, root cause analysis and PoC for CVE-2020-1337: PrintDemon’s (CVE-2020-1048) Patch Bypass via Junction Directory (TOCTOU).
CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader https://www.zerodayinitiative.com/blog/2020/9/2/cve-2020-9715-exploiting-a-use-after-free-in-adobe-reader
Zero Day Initiative
Zero Day Initiative — CVE-2020-9715: Exploiting a Use-After-Free in Adobe Reader
It’s a great feeling when you wake up in the morning to the smell of a fresh pour-over coffee and find a nice 0-day waiting for you in the queue. That’s my typical day-to-day morning at the ZDI. I won’t lie - some of the submissions can be disappointing but…
N1QL Injection: Kind of SQL Injection in a NoSQL Database https://labs.f-secure.com/blog/n1ql-injection-kind-of-sql-injection-in-a-nosql-database/
F-Secure
Useful online security tips and articles | F‑Secure
True cyber security combines advanced technology and best practice. Get tips and read articles on how to take your online security even further.
Fuzzing the Linux kernel (x86) entry code, Part 2 of 3 https://blogs.oracle.com/linux/fuzzing-the-linux-kernel-x86-entry-code%2c-part-2-of-3
Oracle
Fuzzing the Linux kernel (x86) entry code, Part 2 of 3
Part two of a three-part series that explores how to write a fuzzer targeting the Linux kernel entry code on x86.
Nice tutorial! -> "From a C project, through assembly, to shellcode" https://vxug.fakedoma.in/papers/VXUG/Exclusive/FromaCprojectthroughassemblytoshellcodeHasherezade.pdf
CVE-2020-16875 Microsoft Exchange Server DlpUtils AddTenantDlpPolicy Remote Code Execution Vulnerability (with PoCs) https://srcincite.io/advisories/src-2020-0019/
Man-in-the-Browser in Google Chrome: Part 2 – Locating SSL_Write and SSL_Read https://plainsec.org/man-in-the-browser-in-google-chrome-part-2-locating-ssl-write-and-ssl-read/
How to compile Windows XP / Server 2003 code from the leak https://wink.messengergeek.com/t/how-to-compile-windows-xp-server-2003-code-from-the-leak/18252
MessengerGeek
How to compile Windows XP / Server 2003 code from the leak
I suppose a “Last Dance” of a thread should be appropriate. So, you’ve gotten your hand on that mighty XP SP1 / Server 2003 code from 4chan somehow and are wondering what you can do with it? well i may have some info for you. First off, this most of the…
The short story of 1 Linux Kernel Use-After-Free bug and 2 CVEs (CVE-2020-14356 and CVE-2020-25220) http://blog.pi3.com.pl/?p=720
MemFuck: Bypassing User-Mode Hooks https://winternl.com/memfuck/
Nice contribution --> Microsoft announces new Project OneFuzz framework, an open source developer tool to find and fix bugs at scale https://www.microsoft.com/security/blog/2020/09/15/microsoft-onefuzz-framework-open-source-developer-tool-fix-bugs/
Microsoft Security Blog
Microsoft announces new Project OneFuzz framework, an open source developer tool to find and fix bugs at scale | Microsoft Security…
We're excited to release a new tool called OneFuzz, an extensible fuzz testing framework for Azure.