RME-DisCo @ UNIZAR [www.reversea.me]
@reverseame
3.4K
subscribers
1
photo
5.55K
links
Telegram channel of RME, part of the DisCo Research Group of the University of Zaragoza (Spain) focused on cybersecurity aspects. "It’s not that I have something to hide. I have nothing I want you to see"
Link to the channel:
https://t.me/reverseame
Download Telegram
Join
RME-DisCo @ UNIZAR [www.reversea.me]
3.4K subscribers
RME-DisCo @ UNIZAR [www.reversea.me]
https://insinuator.net/2019/07/emotet-at-heise-emotet-there-emotet-everywhere-dissection-of-an-incident/
Insinuator.net
Emotet at Heise, Emotet there, Emotet everywhere – Dissection of an Incident
After the Emotet Incident at Heise, where ERNW has been consulted for Incident Response, we decided to start a blogpost series, in which we want to regularly report on current attacks that we observe. In particular we want to provide details about the utilized…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.elcomsoft.com/2020/04/ios-acquisition-methods-compared-logical-full-file-system-and-icloud/
ElcomSoft blog
iOS acquisition methods compared: logical, full file system and iCloud
The iPhone is one of the most popular smartphone devices. Thanks to its huge popularity, the iPhone gets a lot of attention from the forensic community. Multiple acquisition methods exist, allowing forensic users to obtain more or less information with more…
RME-DisCo @ UNIZAR [www.reversea.me]
https://ricercasecurity.blogspot.com/2020/04/ill-ask-your-body-smbghost-pre-auth-rce.html
Blogspot
"I'll ask your body": SMBGhost pre-auth RCE abusing Direct Memory Access structs
Posted by hugeh0ge, Ricerca Security NOTE: We have decided to make our PoC exclusively available to our customers to avoid abuse by scr...
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/doegox/status/1252667831302455296?s=09
Twitter
Philippe Teuwen
"If succesfuly exploited, an attacker within NFC range could obtain remote code execution on android device's NFC daemon." https://t.co/T24r3qWNnF
RME-DisCo @ UNIZAR [www.reversea.me]
https://github.com/james0x40/CVE-2020-0624
GitHub
GitHub - james0x40/CVE-2020-0624: win32k use-after-free poc
win32k use-after-free poc. Contribute to james0x40/CVE-2020-0624 development by creating an account on GitHub.
RME-DisCo @ UNIZAR [www.reversea.me]
https://insinuator.net/2020/04/cve-2020-0022-an-android-8-0-9-0-bluetooth-zero-click-rce-bluefrag/
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/SBousseaden/status/1253421514386337795?s=19
Twitter
Samir
started as a a fun way to take notes ... 16 mindmaps so far :) https://t.co/1VA1OUBzQ5
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.zecops.com/vulnerabilities/youve-got-0-click-mail/
Jamf
Jamf Threat Labs | Blog
RME-DisCo @ UNIZAR [www.reversea.me]
https://h0mbre.github.io/atillk64_exploit/#
The Human Machine Interface
CVE-2020-12138 Exploit Proof-of-Concept, Privilege Escalation in ATI Technologies Inc. Driver atillk64.sys
Background
RME-DisCo @ UNIZAR [www.reversea.me]
https://itm4n.github.io/windows-dll-hijacking-clarified/
itm4n’s blog
Windows DLL Hijacking (Hopefully) Clarified
Whenever a “new” DLL hijacking / planting trick is posted on Twitter, it generates a lot of comments. “It’s not a vulnerability!” or “There is a lot of hijackable DLLs on Windows…” are the most common reactions. Though, people often don’t really speak about…
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.fireeye.com/blog/threat-research/2020/03/six-facts-about-address-space-layout-randomization-on-windows.html
Mandiant
Six Facts about Address Space Layout Randomization on Windows | Mandiant
RME-DisCo @ UNIZAR [www.reversea.me]
https://bugs.chromium.org/p/project-zero/issues/detail?id=2004
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.xpnsec.com/undersanding-and-evading-get-injectedthread/
XPN InfoSec Blog
@_xpn_ - Understanding and Evading Get-InjectedThread
One of the many areas of this field that I really enjoy is the "cat and mouse" game played between RedTeam and BlueTeam, each forcing the other to up their game. Often we see some awesome tools being released to help defenders detect malware or shellcode…
RME-DisCo @ UNIZAR [www.reversea.me]
https://revers.engineering/patchguard-detection-of-hypervisor-based-instrospection-p1/
Reverse Engineering
Patchguard: Detection of Hypervisor Based Introspection [P1] - Reverse Engineering
Errata Or Nah? Over the last 2-3 years, Microsoft has inserted various methods of virtualization introspection detection (big brain words) into the workings of patchguard. It shouldn’t come as surprise that this has happened, as subverting kernel patch protection…
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/olafhartong/status/1255234547710676994?s=19
Twitter
Olaf Hartong
#Sysmon 11 is out with a new Event type and several improvements! I’ve published a blog post detailing all new features here: https://t.co/kHcnnX1Ue6 #DFIR #Sysinternals #ThreatHunting
RME-DisCo @ UNIZAR [www.reversea.me]
https://robertheaton.com/2020/04/27/how-does-a-tcp-reset-attack-work/
Robert Heaton
How does a TCP Reset Attack work? | Robert Heaton
A TCP reset attack is executed using a single packet of data, no more than a few bytes in size. A spoofed TCP segment, crafted and sent by an attacker, tricks two victims into abandoning a TCP connection, interrupting possibly vital communications between…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.elcomsoft.com/2020/04/forensic-guide-to-imessage-whatsapp-telegram-signal-and-skype-data-acquisition/
ElcomSoft blog
Forensic guide to iMessage, WhatsApp, Telegram, Signal and Skype data acquisition
Instant messaging apps have become the de-facto standard of real-time, text-based communications. The acquisition of instant messaging chats and communication histories can be extremely important for an investigation. In this article, we compare the five…
RME-DisCo @ UNIZAR [www.reversea.me]
https://erev0s.com/blog/how-hook-android-native-methods-frida-noob-friendly/
Erev0S
How to hook Android Native methods with Frida (Noob Friendly)
Hooking C/C++ code in Android application using Frida with introduction and explainations in every step - noob friendly
RME-DisCo @ UNIZAR [www.reversea.me]
https://link.springer.com/search?facet-content-type=%22Book%22&package=mat-covid19_textbooks&sortOrder=newestFirst&showAll=true&facet-discipline=%22Computer+Science%22
RME-DisCo @ UNIZAR [www.reversea.me]
Libros gratis de Springer de Computer Science durante esta situación de la COVID19
RME-DisCo @ UNIZAR [www.reversea.me]
https://blogs.windows.com/windowsdeveloper/2020/04/30/rust-winrt-public-preview/amp/?__twitter_impression=true
Windows Developer Blog
Rust/WinRT Public Preview
We are excited to announce that the Rust/WinRT project finally has a permanent and public home on GitHub: https://github.com/microsoft/winrt-rs Rust/WinRT follows in the tradition established by C++/WinRT of building language projections for the Windows Runtime…