How To Host Your Own DNS-over-HTTPS And DNS-over-TLS Services https://blog.technitium.com/2020/07/how-to-host-your-own-dns-over-https-and.html
Technitium
How To Host Your Own DNS-over-HTTPS, DNS-over-TLS, And DNS-over-QUIC Services
Updated: 2 May 2026 With Technitium DNS Server , you can not just consume DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), or DNS-over-QUIC...
Let’s build a high-performance fuzzer with GPUs! https://blog.trailofbits.com/2020/10/22/lets-build-a-high-performance-fuzzer-with-gpus/
The Trail of Bits Blog
Let’s build a high-performance fuzzer with GPUs!
TL;DR: Can we use GPUs to get 10x performance/dollar when fuzzing embedded software in the cloud? Based on our preliminary work, we think the answer is yes! Fuzzing is a software testing technique that supplies programs with many randomized inputs in an attempt…
Ryuk in 5 Hours https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/
The DFIR Report
Ryuk in 5 Hours - The DFIR Report
Intro The Ryuk threat actors went from a phishing email to domain wide ransomware in 5 hours. They escalated privileges using Zerologon (CVE-2020-1472), less than 2 hours after the initial phish. They used tools such as Cobalt Strike, AdFind, WMI, and PowerShell…
Detailing Two VMware Workstation TOCTOU Vulnerabilities https://www.zerodayinitiative.com/blog/2020/10/22/detailing-two-vmware-workstation-toctou-vulnerabilities
Zero Day Initiative
Zero Day Initiative — Detailing Two VMware Workstation TOCTOU Vulnerabilities
On October 20, VMware released a security patch addressing six vulnerabilities in VMware ESXi, Workstation, Fusion, and NSX-T. Two of those bugs fall into the category of Time-of-check Time-of-use (TOCTOU) race conditions. Now that the patch is out, I wanted…
Exploiting Android deep links and exported components (EkoParty'20 presentation) https://docs.google.com/presentation/d/1YnO_XF-iw2CvJa3rM-GdwYDV22SSzqVHQttXVedY3O4/edit#slide=id.p
Google Docs
B3nac - Exploiting Android deep links and exported components
Exploiting Android deep links and exported components By Kyle B3nac @b3nac
Customizing Wireshark for malware analysis https://paulcimino.com/customizing-wireshark-for-malware-analysis/
Paul Cimino
Customizing Wireshark for malware analysis
I recently watched a series of really good videos from Brad Duncan, the man behind malware-traffic-analysis.net, and my initial takeaway was that setting up Wireshark properly will lead to a much b…
CVE-2020-16938: Bypassing NTFS permissions to read any files as unprivileged user https://github.com/ioncodes/CVE-2020-16938
GitHub
GitHub - ioncodes/CVE-2020-16938: Bypassing NTFS permissions to read any files as unprivileged user.
Bypassing NTFS permissions to read any files as unprivileged user. - ioncodes/CVE-2020-16938
Let's talk macOS Authorization https://theevilbit.github.io/posts/macos_authorization/
theevilbit blog
Let's talk macOS Authorization
This is a blog post I wanted to write for a while now, but somehow never got the time for it, and I also knew that it will require lots of time, so I kept delaying it. I finally kicked my ass, sat down, and wrote it.
The goal of the post is to cover many…
The goal of the post is to cover many…
wsb-detect: library to detect if you are running in Windows Sandbox https://github.com/LloydLabs/wsb-detect
GitHub
GitHub - LloydLabs/wsb-detect: wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB")
wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB") - LloydLabs/wsb-detect
Bad Neighbors Can Break Windows (CVE-2020-16898) https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/bad-neighbors-can-break-windows-cve-2020-16898/
Trustwave
Bad Neighbors Can Break Windows (CVE-2020-16898)
The vulnerability, codenamed “Bad Neighbor”, is a bug in the IPv6 Neighbor Discovery Protocol, particularly it’s improper handling of ICMPv6 Router Advertisement Packets. While publicly available proof of concept (PoC) code results in a denial of service…
Pass-the-hash WiFi https://sensepost.com/blog/2020/pass-the-hash-wifi/
Using a PIE binary as a Shared Library — HCSC-2020 CTF Writeup https://medium.com/bugbountywriteup/using-a-pie-binary-as-a-shared-library-hcsc-2020-ctf-writeup-390a8a437f31
Medium
Using a PIE binary as a Shared Library — HCSC-2020 CTF Writeup
Writeup of a hard RE challenge hosted by the National Cyber-Security Center of Hungary featuring PIE binary to SO lib transformation.
Interception of Android implicit intents https://blog.oversecured.com/Interception-of-Android-implicit-intents/
News, Techniques & Guides
Interception of Android implicit intents
Explicit intents have a set receiver (the name of an app package and the class name of a handler component) and can be delivered only to a predetermined component (activity, receiver, service). With implicit intents, only certain
0day in Windows 7 and Server 2008 R2 Gets a Micropatch https://blog.0patch.com/2020/11/0day-in-windows-7-and-server-2008-r2.html
0Patch
0day in Windows 7 and Server 2008 R2 Gets a Micropatch
by Mitja Kolsek, the 0patch Team [Update 1/22/2021: This vulnerability did not get patched by December 2020 or January 2021 Extended Se...
Active Directory (AD) Attacks & Enumeration at the Network Layer https://www.lares.com/blog/active-directory-ad-attacks-enumeration-at-the-network-layer/
Lares
Active Directory (AD) Attacks & Enumeration at the Network Layer
Intro Defending an Active Directory environment, particularly a large one, is a daunting task. Telemetry generated by Active Directory itself as well as the hosts connected to it are critical…
A story of three CVE's in Ubuntu Desktop https://www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.html
Academic papers related to fuzzing, binary analysis, and exploit dev, which I want to read or have already read https://github.com/0xricksanchez/paper_collection
GitHub
GitHub - 0xricksanchez/paper_collection: Academic papers related to fuzzing, binary analysis, and exploit dev, which I want to…
Academic papers related to fuzzing, binary analysis, and exploit dev, which I want to read or have already read - 0xricksanchez/paper_collection
How the Pandemic is Reshaping the Bug-Bounty Landscape https://threatpost.com/pandemic-reshaping-bug-bounty-landscape/160644/
Threat Post
How the Pandemic is Reshaping the Bug-Bounty Landscape
Bugcrowd Founder Casey Ellis talks about COVID-19's impact on bug bounty hunters, bug bounty program adoption and more.