RME-DisCo @ UNIZAR [www.reversea.me]
@reverseame
3.4K
subscribers
1
photo
5.55K
links
Telegram channel of RME, part of the DisCo Research Group of the University of Zaragoza (Spain) focused on cybersecurity aspects. "It’s not that I have something to hide. I have nothing I want you to see"
Link to the channel:
https://t.me/reverseame
Download Telegram
Join
RME-DisCo @ UNIZAR [www.reversea.me]
3.4K subscribers
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.fireeye.com/blog/threat-research/2020/04/time-between-disclosure-patch-release-and-vulnerability-exploitation.html
FireEye
Think Fast: Time Between Disclosure, Patch Release and Vulnerability
Exploitation — Intelligence for Vulnerability Management,…
The majority of exploitation in the wild occurs before patch issuance or within a few days of a patch becoming available.
RME-DisCo @ UNIZAR [www.reversea.me]
https://posts.specterops.io/methodology-for-static-reverse-engineering-of-windows-kernel-drivers-3115b2efed83?gi=b800ebc3c52c
Medium
Methodology for Static Reverse Engineering of Windows Kernel Drivers
Introduction
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.vastart.dev/2020/04/calling-arbitrary-functions-in-exes.html
blog.vastart.dev
Calling Arbitrary Functions In EXEs: Performing Calls to EXE Functions Like DLL Exports
convert EXE to DLL walk through and example. How to convert a .exe file to a .dll to be able to call arbitrary functions with controlled data. Useful for fuzzing and reverse engineering.
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.vastart.dev/2019/10/stack-overflow-cve-2019-17424.html
blog.vastart.dev
Stack Overflow CVE-2019-17424 Vulnerability Write-Up and RCE Exploit Walk Through
CVE-2019-17424 Stack Overflow Vulnerability detailed write-up and exploit walk through for beginner and intermediate learners with ASLR and DEP bypass.
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.forallsecure.com/uncovering-openwrt-remote-code-execution-cve-2020-7982?hs_amp=true&__twitter_impression=true
Forallsecure
Uncovering OpenWRT remote code execution (CVE-2020-7982)
In this technical guide, ForAllSecure Researcher, Guido Vranken walks readers through his workflow for uncovering for OpenWRT remote code execution vulnerability.
RME-DisCo @ UNIZAR [www.reversea.me]
https://nickbloor.co.uk/2020/03/29/patching-android-split-apks/
NickstaDB
Patching Android Split APKs
I recently came up against my first split APK during an Android app security assessment. My usual toolkit doesn’t support split APKs, so I hacked together a solution to allow me to instrument…
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/_CPResearch_/status/1252174102133116928?s=19
Twitter
Check Point Research
[CPR-Zero] CVE-2020-0791 (Windows 10 Kernel): Out-Of-Bounds Read\Write in the StrechBlt function in win32kfull.sys https://t.co/PGg9X2bNHE
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/_fel1x/status/1252502296661016576?s=09
Twitter
Felix Wilhelm
My writeup for the haproxy http2 bug (CVE-2020-11100) is now public: https://t.co/rWgz4bfnCZ. Includes a PoC exploit to demonstrate RCE against Ubuntu 19.10.
RME-DisCo @ UNIZAR [www.reversea.me]
https://insinuator.net/2019/07/emotet-at-heise-emotet-there-emotet-everywhere-dissection-of-an-incident/
Insinuator.net
Emotet at Heise, Emotet there, Emotet everywhere – Dissection of an Incident
After the Emotet Incident at Heise, where ERNW has been consulted for Incident Response, we decided to start a blogpost series, in which we want to regularly report on current attacks that we observe. In particular we want to provide details about the utilized…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.elcomsoft.com/2020/04/ios-acquisition-methods-compared-logical-full-file-system-and-icloud/
ElcomSoft blog
iOS acquisition methods compared: logical, full file system and iCloud
The iPhone is one of the most popular smartphone devices. Thanks to its huge popularity, the iPhone gets a lot of attention from the forensic community. Multiple acquisition methods exist, allowing forensic users to obtain more or less information with more…
RME-DisCo @ UNIZAR [www.reversea.me]
https://ricercasecurity.blogspot.com/2020/04/ill-ask-your-body-smbghost-pre-auth-rce.html
Blogspot
"I'll ask your body": SMBGhost pre-auth RCE abusing Direct Memory Access structs
Posted by hugeh0ge, Ricerca Security NOTE: We have decided to make our PoC exclusively available to our customers to avoid abuse by scr...
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/doegox/status/1252667831302455296?s=09
Twitter
Philippe Teuwen
"If succesfuly exploited, an attacker within NFC range could obtain remote code execution on android device's NFC daemon." https://t.co/T24r3qWNnF
RME-DisCo @ UNIZAR [www.reversea.me]
https://github.com/james0x40/CVE-2020-0624
GitHub
GitHub - james0x40/CVE-2020-0624: win32k use-after-free poc
win32k use-after-free poc. Contribute to james0x40/CVE-2020-0624 development by creating an account on GitHub.
RME-DisCo @ UNIZAR [www.reversea.me]
https://insinuator.net/2020/04/cve-2020-0022-an-android-8-0-9-0-bluetooth-zero-click-rce-bluefrag/
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/SBousseaden/status/1253421514386337795?s=19
Twitter
Samir
started as a a fun way to take notes ... 16 mindmaps so far :) https://t.co/1VA1OUBzQ5
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.zecops.com/vulnerabilities/youve-got-0-click-mail/
Jamf
Jamf Threat Labs | Blog
RME-DisCo @ UNIZAR [www.reversea.me]
https://h0mbre.github.io/atillk64_exploit/#
The Human Machine Interface
CVE-2020-12138 Exploit Proof-of-Concept, Privilege Escalation in ATI Technologies Inc. Driver atillk64.sys
Background
RME-DisCo @ UNIZAR [www.reversea.me]
https://itm4n.github.io/windows-dll-hijacking-clarified/
itm4n’s blog
Windows DLL Hijacking (Hopefully) Clarified
Whenever a “new” DLL hijacking / planting trick is posted on Twitter, it generates a lot of comments. “It’s not a vulnerability!” or “There is a lot of hijackable DLLs on Windows…” are the most common reactions. Though, people often don’t really speak about…
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.fireeye.com/blog/threat-research/2020/03/six-facts-about-address-space-layout-randomization-on-windows.html
Mandiant
Six Facts about Address Space Layout Randomization on Windows | Mandiant
RME-DisCo @ UNIZAR [www.reversea.me]
https://bugs.chromium.org/p/project-zero/issues/detail?id=2004
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.xpnsec.com/undersanding-and-evading-get-injectedthread/
XPN InfoSec Blog
@_xpn_ - Understanding and Evading Get-InjectedThread
One of the many areas of this field that I really enjoy is the "cat and mouse" game played between RedTeam and BlueTeam, each forcing the other to up their game. Often we see some awesome tools being released to help defenders detect malware or shellcode…