We Hacked Apple for 3 Months: Here’s What We Found https://samcurry.net/hacking-apple/
samcurry.net
We Hacked Apple for 3 Months: Here’s What We Found
Between the period of July 6th to October 6th myself, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes worked together and hacked on the Apple bug bounty program.
Zero-day in Sign in with Apple https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-apple/
NTLMRawUnHide: parse network packet capture files and extract NTLMv2 hashes https://securityonline.info/ntlmrawunhide/
Penetration Testing
NTLMRawUnHide: parse network packet capture files and extract NTLMv2 hashes
NTLMRawUnHide was developed to extract NTLMv2 hashes from files generated by native Windows binaries like NETSH.EXE and PKTMON.EXE without conversion.
Acronis backup software contains multiple privilege escalation vulnerabilities https://kb.cert.org/vuls/id/114757
www.kb.cert.org
CERT/CC Vulnerability Note VU#114757
Acronis backup software contains multiple privilege escalation vulnerabilities
Really nice post! » Low-level Reversing of SIGred (CVE-2020–1350), by @ricnar456 https://www.coresecurity.com/core-labs/articles/low-level-reversing-sigred-cve-2020-1350
Coresecurity
Low-level Reversing of SIGred (CVE-2020–1350) | Core Labs Articles| Core Security
Explore how the SIGred (CVE-2020-1350) vulnerability can exploited.
Microsoft SharePoint Server DataFormWebPart CreateChildControls Server-Side Include Remote Code Execution Vulnerability https://srcincite.io/pocs/cve-2020-16952.py.txt
Mastering 4 Stages of Malware Analysis https://zeltser.com/mastering-4-stages-of-malware-analysis/
Lenny Zeltser
Mastering 4 Stages of Malware Analysis
Malware analysis techniques form a pyramid of increasing complexity: fully-automated analysis, static properties examination, interactive behavioral analysis, and manual code reversing. Analysts typically combine these stages iteratively, with insights from…
Morty Sherlocked: Android Application Based CTF Challenge Walkthrough https://medium.com/swlh/morty-sherlocked-android-application-ctf-challenge-walkthrough-ab1ec2161cb4
Medium
Morty Sherlocked: Android Application Based CTF Challenge Walkthrough
Morty Sherlocked is a beginner level Android application CTF challenge. It walks us through the basic concepts of Android application…
You should update immediately your iOS device >> https://thehackernews.com/2020/11/update-your-ios-devices-now-3-actively.html
OceanLotus Old techniques, new backdoor https://www.welivesecurity.com/wp-content/uploads/2018/03/ESET_OceanLotus.pdf
nice talk on BH Asia20 >> Finding Backdoors in Applications https://i.blackhat.com/asia-20/Friday/asia-20-Loke-Patching-Loopholes-Finding-Backdoors-In-Applications.pdf
How to Find Vulnerabilities in Code: Bad Words
https://btlr.dev/blog/how-to-find-vulnerabilities-in-code-bad-words
https://btlr.dev/blog/how-to-find-vulnerabilities-in-code-bad-words
Sophisticated new Android malware marks the latest evolution of mobile ransomware https://www.microsoft.com/security/blog/2020/10/08/sophisticated-new-android-malware-marks-the-latest-evolution-of-mobile-ransomware/
Microsoft News
Sophisticated new Android malware marks the latest evolution of mobile ransomware
We found a piece of a particularly sophisticated Android ransomware with novel techniques and behavior, exemplifying the rapid evolution of mobile threats that we have also observed on other platforms.
PoetRAT: Malware targeting public and private sector in Azerbaijan evolves https://blog.talosintelligence.com/2020/10/poetrat-update.html
Cisco Talos Blog
PoetRAT: Malware targeting public and private sector in Azerbaijan evolves
By Warren Mercer, Paul Rascagneres and Vitor Ventura.
* The Azerbaijan public sector and other important organizations are still targeted by new versions of PoetRAT.
* This actor leverages malicious Microsoft Word documents alleged to be from the Azerbaijan…
* The Azerbaijan public sector and other important organizations are still targeted by new versions of PoetRAT.
* This actor leverages malicious Microsoft Word documents alleged to be from the Azerbaijan…
Audi A7 2014 MMI Mishandles the Format-string Specifiers https://tiger-team-1337.blogspot.com/2020/10/audi-a7-2014-mmi-mishandles-format.html
Blogspot
Audi A7 2014 MMI Mishandles the Format-string Specifiers
Date: 2020-10-13 Author: Kevin2600 CVE: CVE-2020-27524 Version: Audi A7 2014 MMI Vendor : https://www.audi.com/en.html Attack-Vector:...
More TA551 (Shathak) Word docs push IcedID (Bokbot) https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/
Moving From Manual Reverse Engineering of UEFI Modules To Dynamic Emulation of UEFI Firmware https://labs.sentinelone.com/moving-from-manual-re-of-uefi-modules-to-dynamic-emulation-of-uefi-firmware/
SentinelOne
Moving From Manual Reverse Engineering of UEFI Modules To Dynamic Emulation of UEFI Firmware - SentinelLabs
Learn how to emulate, trace, debug, and Reverse Engineer UEFI modules in part 2 of our new blog series on Firmware Security
The Difficulties of Tracking Running Processes on Linux https://natanyellin.com/posts/tracking-running-processes-on-linux/
Natanyellin
The Difficulties of Tracking Running Processes on Linux
Introduction Everyone knows how to track which processes run on Linux, but almost no-one tracks them accurately. In fact, all of the methods listed in this post have some deficiency or another. Lets define requirements:
All processes should be logged including…
All processes should be logged including…
Technical Advisory – Pulse Connect Secure – RCE via Template Injection (CVE-2020-8243)
https://research.nccgroup.com/2020/10/06/technical-advisory-pulse-connect-secure-rce-via-template-injection-cve-2020-8243/
https://research.nccgroup.com/2020/10/06/technical-advisory-pulse-connect-secure-rce-via-template-injection-cve-2020-8243/
NCC Group Research
Technical Advisory – Pulse Connect Secure – RCE via Template Injection (CVE-2020-8243)
NCC Group Technical Advisory: Pulse Connect Secure - RCE via Template Injection (CVE-2020-8243)