RME-DisCo @ UNIZAR [www.reversea.me]
@reverseame
3.4K
subscribers
1
photo
5.55K
links
Telegram channel of RME, part of the DisCo Research Group of the University of Zaragoza (Spain) focused on cybersecurity aspects. "It’s not that I have something to hide. I have nothing I want you to see"
Link to the channel:
https://t.me/reverseame
Download Telegram
Join
RME-DisCo @ UNIZAR [www.reversea.me]
3.4K subscribers
RME-DisCo @ UNIZAR [www.reversea.me]
https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-xca/a8b7cb0a-92a6-4187-a23b-5e14273b96f8
Docs
[MS-XCA]: Xpress Compression Algorithm
Specifies the three variants of the Xpress Compression Algorithm: LZ77+Huffman, Plain LZ77, LZNT1, and their respective decompression algorithms.
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.fireeye.com/blog/threat-research/2020/04/time-between-disclosure-patch-release-and-vulnerability-exploitation.html
FireEye
Think Fast: Time Between Disclosure, Patch Release and Vulnerability
Exploitation — Intelligence for Vulnerability Management,…
The majority of exploitation in the wild occurs before patch issuance or within a few days of a patch becoming available.
RME-DisCo @ UNIZAR [www.reversea.me]
https://posts.specterops.io/methodology-for-static-reverse-engineering-of-windows-kernel-drivers-3115b2efed83?gi=b800ebc3c52c
Medium
Methodology for Static Reverse Engineering of Windows Kernel Drivers
Introduction
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.vastart.dev/2020/04/calling-arbitrary-functions-in-exes.html
blog.vastart.dev
Calling Arbitrary Functions In EXEs: Performing Calls to EXE Functions Like DLL Exports
convert EXE to DLL walk through and example. How to convert a .exe file to a .dll to be able to call arbitrary functions with controlled data. Useful for fuzzing and reverse engineering.
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.vastart.dev/2019/10/stack-overflow-cve-2019-17424.html
blog.vastart.dev
Stack Overflow CVE-2019-17424 Vulnerability Write-Up and RCE Exploit Walk Through
CVE-2019-17424 Stack Overflow Vulnerability detailed write-up and exploit walk through for beginner and intermediate learners with ASLR and DEP bypass.
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.forallsecure.com/uncovering-openwrt-remote-code-execution-cve-2020-7982?hs_amp=true&__twitter_impression=true
Forallsecure
Uncovering OpenWRT remote code execution (CVE-2020-7982)
In this technical guide, ForAllSecure Researcher, Guido Vranken walks readers through his workflow for uncovering for OpenWRT remote code execution vulnerability.
RME-DisCo @ UNIZAR [www.reversea.me]
https://nickbloor.co.uk/2020/03/29/patching-android-split-apks/
NickstaDB
Patching Android Split APKs
I recently came up against my first split APK during an Android app security assessment. My usual toolkit doesn’t support split APKs, so I hacked together a solution to allow me to instrument…
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/_CPResearch_/status/1252174102133116928?s=19
Twitter
Check Point Research
[CPR-Zero] CVE-2020-0791 (Windows 10 Kernel): Out-Of-Bounds Read\Write in the StrechBlt function in win32kfull.sys https://t.co/PGg9X2bNHE
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/_fel1x/status/1252502296661016576?s=09
Twitter
Felix Wilhelm
My writeup for the haproxy http2 bug (CVE-2020-11100) is now public: https://t.co/rWgz4bfnCZ. Includes a PoC exploit to demonstrate RCE against Ubuntu 19.10.
RME-DisCo @ UNIZAR [www.reversea.me]
https://insinuator.net/2019/07/emotet-at-heise-emotet-there-emotet-everywhere-dissection-of-an-incident/
Insinuator.net
Emotet at Heise, Emotet there, Emotet everywhere – Dissection of an Incident
After the Emotet Incident at Heise, where ERNW has been consulted for Incident Response, we decided to start a blogpost series, in which we want to regularly report on current attacks that we observe. In particular we want to provide details about the utilized…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.elcomsoft.com/2020/04/ios-acquisition-methods-compared-logical-full-file-system-and-icloud/
ElcomSoft blog
iOS acquisition methods compared: logical, full file system and iCloud
The iPhone is one of the most popular smartphone devices. Thanks to its huge popularity, the iPhone gets a lot of attention from the forensic community. Multiple acquisition methods exist, allowing forensic users to obtain more or less information with more…
RME-DisCo @ UNIZAR [www.reversea.me]
https://ricercasecurity.blogspot.com/2020/04/ill-ask-your-body-smbghost-pre-auth-rce.html
Blogspot
"I'll ask your body": SMBGhost pre-auth RCE abusing Direct Memory Access structs
Posted by hugeh0ge, Ricerca Security NOTE: We have decided to make our PoC exclusively available to our customers to avoid abuse by scr...
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/doegox/status/1252667831302455296?s=09
Twitter
Philippe Teuwen
"If succesfuly exploited, an attacker within NFC range could obtain remote code execution on android device's NFC daemon." https://t.co/T24r3qWNnF
RME-DisCo @ UNIZAR [www.reversea.me]
https://github.com/james0x40/CVE-2020-0624
GitHub
GitHub - james0x40/CVE-2020-0624: win32k use-after-free poc
win32k use-after-free poc. Contribute to james0x40/CVE-2020-0624 development by creating an account on GitHub.
RME-DisCo @ UNIZAR [www.reversea.me]
https://insinuator.net/2020/04/cve-2020-0022-an-android-8-0-9-0-bluetooth-zero-click-rce-bluefrag/
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/SBousseaden/status/1253421514386337795?s=19
Twitter
Samir
started as a a fun way to take notes ... 16 mindmaps so far :) https://t.co/1VA1OUBzQ5
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.zecops.com/vulnerabilities/youve-got-0-click-mail/
Jamf
Jamf Threat Labs | Blog
RME-DisCo @ UNIZAR [www.reversea.me]
https://h0mbre.github.io/atillk64_exploit/#
The Human Machine Interface
CVE-2020-12138 Exploit Proof-of-Concept, Privilege Escalation in ATI Technologies Inc. Driver atillk64.sys
Background
RME-DisCo @ UNIZAR [www.reversea.me]
https://itm4n.github.io/windows-dll-hijacking-clarified/
itm4n’s blog
Windows DLL Hijacking (Hopefully) Clarified
Whenever a “new” DLL hijacking / planting trick is posted on Twitter, it generates a lot of comments. “It’s not a vulnerability!” or “There is a lot of hijackable DLLs on Windows…” are the most common reactions. Though, people often don’t really speak about…
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.fireeye.com/blog/threat-research/2020/03/six-facts-about-address-space-layout-randomization-on-windows.html
Mandiant
Six Facts about Address Space Layout Randomization on Windows | Mandiant
RME-DisCo @ UNIZAR [www.reversea.me]
https://bugs.chromium.org/p/project-zero/issues/detail?id=2004