Life and Death of a Linux Process https://natanyellin.com/posts/life-and-death-of-a-linux-process/
Natanyellin
Life and Death of a Linux Process
This post contains a rough sketch of the life and death of a process on Linux. It is a first-order approximation only. A later post will refine this further and provide a more precise description, adding details about pid namespaces, obscure syscalls, and…
Zerologon is now detected by Microsoft Defender for Identity https://www.microsoft.com/security/blog/2020/11/30/zerologon-is-now-detected-by-microsoft-defender-for-identity/
Microsoft Security Blog
Zerologon is now detected by Microsoft Defender for Identity | Microsoft Security Blog
A new detection allows Microsoft Defender for Identity to detect adversaries as they try to exploit the Zerologon vulnerability (CVE-2020-1472) against your domain controllers.
How I found a Tor vulnerability in Brave Browser, reported it, watched it get patched, got a CVE (CVE-2020-8276) and a small bounty, all in one working day https://community.disclose.io/t/how-i-found-a-tor-vulnerability-in-brave-browser-reported-it-watched-it-get-patched-got-a-cve-cve-2020-8276-and-a-small-bounty-all-in-one-working-day/65
@disclose_io Community Forum
How I found a TOR vulnerability in Brave Browser, reported it, watched it get patched, got a CVE (CVE-2020-8276), and a small bounty…
Recently, I discovered a small but potentially devastating vulnerability in the new Tor feature of the Brave browser. As of November 2nd 2020, Brave monthly users have massively increased their browser market share to 20 Million Monthly Active Users + 7…
grap: Automating QakBot strings decryption https://blog.quosec.net/posts/grap_qakbot_strings/
blog.quosec.net
grap: Automating QakBot strings decryption
Our last grap post demonstrated on how to use grap to create and find patterns within QakBot samples.
This post focuses on QakBot’s documented strings decryption feature:
Create patterns to find the function where it is implemented Extract relevant variables…
This post focuses on QakBot’s documented strings decryption feature:
Create patterns to find the function where it is implemented Extract relevant variables…
Bitdefender: UPX Unpacking Featuring Ten Memory Corruptions https://landave.io/2020/11/bitdefender-upx-unpacking-featuring-ten-memory-corruptions/
landave's blog
Bitdefender: UPX Unpacking Featuring Ten Memory Corruptions
Blog about anti-virus software vulnerabilities.
nice talk of 34C3 (attacks on modern C++ software) >> Type confusion: discovery, abuse, and protection https://media.ccc.de/v/34c3-8848-type_confusion_discovery_abuse_and_protection
media.ccc.de
Type confusion: discovery, abuse, and protection
Type confusion, often combined with use-after-free, is the main attack vector to compromise modern C++ software like browsers or virtual ...
WOW64!Hooks: WOW64 Subsystem Internals and Hooking Techniques https://www.fireeye.com/blog/threat-research/2020/11/wow64-subsystem-internals-and-hooking-techniques.html
Google Cloud Blog
WOW64!Hooks: WOW64 Subsystem Internals and Hooking Techniques | Mandiant | Google Cloud Blog
Our member @ricardojrodriguez will be today at noon in #XIVJornadasCCNCERT, organized by @CCNCERT, to talk about patch diffing with Ghidra and BinDiff, analyzing the Zerologon vulnerability. Don’t miss it!! https://www.ccn-cert.cni.es/xivjornadas.html
www.ccn-cert.cni.es
Inicio
Bienvenido al portal de CCN-CERT
Official report from Amazon » Summary of the Amazon Kinesis Event in the Northern Virginia (US-EAST-1) Region https://aws.amazon.com/message/11201/
Published by the Harvard Law School, quite interesting! >> A Researcher’s Guide to Some Legal Risks of Security Research https://clinic.cyber.harvard.edu/files/2020/10/Security_Researchers_Guide-2.pdf
Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection https://www.fireeye.com/blog/threat-research/2017/11/ursnif-variant-malicious-tls-callback-technique.html
FireEye
Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique
to Achieve Process Injection
to Achieve Process Injection
We recently came across a Ursnif/Gozi-ISFB sample that manipulated TLS callbacks while injecting to child process.
Multiple vulnerabilities through filename manipulation (CVE-2020-28948 and CVE-2020-28949) in PEAR https://github.com/pear/Archive_Tar/issues/33
GitHub
Multiple vulnerabilities through filename manipulation (CVE-2020-28948 and CVE-2020-28949) · Issue #33 · pear/Archive_Tar
I have submitted this to the PEAR bug tracker as well as the PEAR group mailing list, and I'm not sure if either has gone through, so opening an issue here with the hope that this is the right ...
Extraordinary Vulnerabilities Discovered in TCL Android TVs, Now World’s 3rd Largest TV Manufacturer https://sick.codes/extraordinary-vulnerabilities-discovered-in-tcl-android-tvs-now-worlds-3rd-largest-tv-manufacturer/
Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips!
Extraordinary Vulnerabilities Discovered in TCL Android TVs, Now World’s 3rd Largest TV Manufacturer. - Sick Codes - Security Research…
The following piece is the culmination of a three-month long investigation into Smart TVs running Android. Having lived through this research experience, I can wholeheartedly say that there were multiple moments that I, and another security researcher that…
xpcspy - Bidirectional XPC message interception and more (with Frida) https://github.com/hot3eed/xpcspy
GitHub
GitHub - hot3eed/xpcspy: Bidirectional XPC message interception and more. Powered by Frida
Bidirectional XPC message interception and more. Powered by Frida - hot3eed/xpcspy
Not related to security, but it's a MUST tool >> hyperfine: a command-line benchmarking tool https://github.com/sharkdp/hyperfine
GitHub
GitHub - sharkdp/hyperfine: A command-line benchmarking tool
A command-line benchmarking tool. Contribute to sharkdp/hyperfine development by creating an account on GitHub.
Flare-On 2020 Solutions Write-Ups http://tonyweb.xyz/index.php/2020/11/07/flare-on-2020-solutions-write-ups/