Collaborative Reverse Engineering with Ghidra Server https://byte.how/posts/collaborative-reverse-engineering/
byte.how
Collaborative Reverse Engineering with Ghidra Server
How to use Ghidra's built-in "git" server for shared version control
ARM64 Reversing and Exploitation Part 1 - ARM Instruction Set + Simple Heap Overflow http://highaltitudehacks.com/2020/09/05/arm64-reversing-and-exploitation-part-1-arm-instruction-set-heap-overflow/
ARM64 Reversing and Exploitation Part 2 - Use After Free http://highaltitudehacks.com/2020/09/06/arm64-reversing-and-exploitation-part-2-use-after-free/
Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers https://www.virusbulletin.com/conference/vb2019/abstracts/attribution-object-using-rtf-object-dimensions-track-apt-phishing-weaponizers
A tool to help malware analysts signature unique parts of RTF documents https://github.com/PwCUK-CTO/rtfsig
GitHub
GitHub - PwCUK-CTO/rtfsig: A tool to help malware analysts signature unique parts of RTF documents
A tool to help malware analysts signature unique parts of RTF documents - PwCUK-CTO/rtfsig
Nice quiz about C integers, specially for students of "Exploiting Software Vulnerabilities" course :) https://www.acepace.net/integerQuiz/
acepace.net
John Regehr's Integers in C
A restoration of John Regehrs famous quiz on integers in C
New Snort, ClamAV coverage strikes back against Cobalt Strike https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html
Cisco Talos Blog
New Snort, ClamAV coverage strikes back against Cobalt Strike
By Nick Mavis. Editing by Joe Marshall and Jon Munshaw.
Cisco Talos is releasing a new research paper called “The Art and Science of Detecting Cobalt Strike.”
We recently released a more granular set of updated SNORTⓇ and ClamAVⓇ detection signatures to…
Cisco Talos is releasing a new research paper called “The Art and Science of Detecting Cobalt Strike.”
We recently released a more granular set of updated SNORTⓇ and ClamAVⓇ detection signatures to…
OpenSSH 8.4 released. Attention: SHA-1 algorithm will be deprecated shortly. Alternatives provided in the notice https://marc.info/?l=openssh-unix-dev&m=160121534105667&w=2&mc_cid=ba5825adff&mc_eid=5a6384b5cb
Writing an x86 bootloader in Rust that can launch vmlinux https://vmm.dev/en/rust/krabs.md
vmm.dev
Writing an x86 bootloader in Rust that can launch vmlinux
I've been developping an x86 bootloader in Rust that can use Linux boot protocol. In this article, I'd like to write about my motivation, features of this project, and issues.
Good summary of (Patrik's) bug bounty tools https://blog.it-securityguard.com/pbbt.pdf
Evasive URLs in Spam https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/evasive-urls-in-spam/
Levelblue
Evasive URLs in Spam | Trustwave
Cybercriminals are continuously evolving their tools, tactics, and techniques to evade spam detection systems. We recently observed some spam campaigns that heavily relied on URL obfuscation in email messages.
MemFuck: Bypassing User-Mode Hooks https://winternl.com/memfuck/
winternl
MemFuck: Bypassing User-Mode Hooks
Dynamic malware analysis is the preferred way to determine the legitimacy of an application for many AVs/EDRs/MDSs. Unlike static analysis, dynamic analysis can capture and analyze Windows API calls…
Let's Learn: In-Depth Reversing of Qakbot "qbot" Banker Part 1 https://www.vkremez.com/2018/07/lets-learn-in-depth-reversing-of-qakbot.html
1Win México
1win México ᐈ Сasino en línea - sitio web oficial
✅ Registrarse en sitio web oficial 1win casino & casa de apuestas en México ✓ Bono de 14.000 MXN ✔️ Juega con dinero real ✔ Tragaperras ✔️
Kernel exploitation: weaponizing CVE-2020-17382 MSI Ambient Link driver https://www.matteomalvica.com/blog/2020/09/24/weaponizing-cve-2020-17382/ (PoCs in https://github.com/uf0o/CVE-2020-17382)
Matteomalvica
Kernel exploitation: weaponizing CVE-2020-17382 MSI Ambient Link driver
Introduction to Windows Drivers Exploitation
MEDUZA: A more or less universal SSL unpinning tool for iOS https://github.com/kov4l3nko/MEDUZA
MacOS Injection via Third Party Frameworks https://blog.xpnsec.com/macos-injection-via-third-party-frameworks/
XPN InfoSec Blog
@_xpn_ - MacOS Injection via Third Party Frameworks
In this post, we are going to take a look at a couple of interesting methods of leveraging third-party technologies to achieve our code injection goals. For us, this translates to running code in the context of a target application without having to resort…
Micropatch for Zerologon, the "perfect" Windows vulnerability (CVE-2020-1472) https://blog.0patch.com/2020/09/micropatch-for-zerologon-perfect.html
0patch - Better Security Patches
Micropatch for Zerologon, the "perfect" Windows vulnerability (CVE-2020-1472)
Tiny reboot-less security patches for critical vulnerabilities in Windows, Microsoft Office, and other Windows products