OpenSSH 8.4 released. Attention: SHA-1 algorithm will be deprecated shortly. Alternatives provided in the notice https://marc.info/?l=openssh-unix-dev&m=160121534105667&w=2&mc_cid=ba5825adff&mc_eid=5a6384b5cb
Writing an x86 bootloader in Rust that can launch vmlinux https://vmm.dev/en/rust/krabs.md
vmm.dev
Writing an x86 bootloader in Rust that can launch vmlinux
I've been developping an x86 bootloader in Rust that can use Linux boot protocol. In this article, I'd like to write about my motivation, features of this project, and issues.
Good summary of (Patrik's) bug bounty tools https://blog.it-securityguard.com/pbbt.pdf
Evasive URLs in Spam https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/evasive-urls-in-spam/
Levelblue
Evasive URLs in Spam | Trustwave
Cybercriminals are continuously evolving their tools, tactics, and techniques to evade spam detection systems. We recently observed some spam campaigns that heavily relied on URL obfuscation in email messages.
MemFuck: Bypassing User-Mode Hooks https://winternl.com/memfuck/
winternl
MemFuck: Bypassing User-Mode Hooks
Dynamic malware analysis is the preferred way to determine the legitimacy of an application for many AVs/EDRs/MDSs. Unlike static analysis, dynamic analysis can capture and analyze Windows API calls…
Let's Learn: In-Depth Reversing of Qakbot "qbot" Banker Part 1 https://www.vkremez.com/2018/07/lets-learn-in-depth-reversing-of-qakbot.html
1Win México
1win México ᐈ Сasino en línea - sitio web oficial
✅ Registrarse en sitio web oficial 1win casino & casa de apuestas en México ✓ Bono de 14.000 MXN ✔️ Juega con dinero real ✔ Tragaperras ✔️
Kernel exploitation: weaponizing CVE-2020-17382 MSI Ambient Link driver https://www.matteomalvica.com/blog/2020/09/24/weaponizing-cve-2020-17382/ (PoCs in https://github.com/uf0o/CVE-2020-17382)
Matteomalvica
Kernel exploitation: weaponizing CVE-2020-17382 MSI Ambient Link driver
Introduction to Windows Drivers Exploitation
MEDUZA: A more or less universal SSL unpinning tool for iOS https://github.com/kov4l3nko/MEDUZA
MacOS Injection via Third Party Frameworks https://blog.xpnsec.com/macos-injection-via-third-party-frameworks/
XPN InfoSec Blog
@_xpn_ - MacOS Injection via Third Party Frameworks
In this post, we are going to take a look at a couple of interesting methods of leveraging third-party technologies to achieve our code injection goals. For us, this translates to running code in the context of a target application without having to resort…
Micropatch for Zerologon, the "perfect" Windows vulnerability (CVE-2020-1472) https://blog.0patch.com/2020/09/micropatch-for-zerologon-perfect.html
0patch - Better Security Patches
Micropatch for Zerologon, the "perfect" Windows vulnerability (CVE-2020-1472)
Tiny reboot-less security patches for critical vulnerabilities in Windows, Microsoft Office, and other Windows products
Lambdas: From C++11 to C++20, Part 1 https://www.bfilipek.com/2019/02/lambdas-story-part1.html?m=1
C++ Stories
Lambdas: From C++11 to C++20, Part 1
Lambda expressions are one of the most powerful additions to C++11, and they continue to evolve with each new C++ language standard. In this article, we’ll go through history and see the evolution of this crucial part of modern C++.
The second part is available:…
The second part is available:…
Locating the Trojan inside an infected COVID-19 contact tracing app https://medium.com/@cryptax/locating-the-trojan-inside-an-infected-covid-19-contact-tracing-app-21e23f90fbfe
Medium
Locating the Trojan inside an infected COVID-19 contact tracing app
An italian company, SoftMining, developed an Android COVID-19 contact tracing application “SM-COVID-19”. Unfortunately, malware authors…
Code Review 101: How to perform source code review to find vulnerabilities in web applications https://vickieli.dev/hacking/code-review-101/
Vickie Li's Security Blog
Code Review 101
How to perform source code review to find vulnerabilities in web applications.
PDF from NSA to help selecting secure multi-factor authentication solutions https://media.defense.gov/2020/Sep/22/2002502665/-1/-1/0/CSI_MULTIFACTOR_AUTHENTICATION_SOLUTIONS_UOO17091520.PDF
uTorrent CVE-2020-8437 Vulnerability And Exploit Overview https://blog.whtaguy.com/2020/09/utorrent-cve-2020-8437-vulnerability.html
Mav Levin Security Research
uTorrent CVE-2020-8437 Vulnerability And Exploit Overview
The world’s most popular torrent client, uTorrent, contained a security vulnerability — later to be called CVE-2020-8437— that could be exploited by a remote...
Fuzzing Image Parsing in Windows, Part One: Color Profiles https://www.fireeye.com/blog/threat-research/2020/09/fuzzing-image-parsing-in-windows-color-profiles.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Trickbot disrupted https://www.microsoft.com/security/blog/2020/10/12/trickbot-disrupted/
Microsoft Security Blog
Trickbot disrupted | Microsoft Security Blog
Microsoft took action against the Trickbot botnet, disrupting one of the world’s most persistent malware operations. Microsoft worked with telecommunications providers around the world to disrupt key Trickbot infrastructure.