nice talk of 34C3 (attacks on modern C++ software) >> Type confusion: discovery, abuse, and protection https://media.ccc.de/v/34c3-8848-type_confusion_discovery_abuse_and_protection
media.ccc.de
Type confusion: discovery, abuse, and protection
Type confusion, often combined with use-after-free, is the main attack vector to compromise modern C++ software like browsers or virtual ...
WOW64!Hooks: WOW64 Subsystem Internals and Hooking Techniques https://www.fireeye.com/blog/threat-research/2020/11/wow64-subsystem-internals-and-hooking-techniques.html
Google Cloud Blog
WOW64!Hooks: WOW64 Subsystem Internals and Hooking Techniques | Mandiant | Google Cloud Blog
Our member @ricardojrodriguez will be today at noon in #XIVJornadasCCNCERT, organized by @CCNCERT, to talk about patch diffing with Ghidra and BinDiff, analyzing the Zerologon vulnerability. Don’t miss it!! https://www.ccn-cert.cni.es/xivjornadas.html
www.ccn-cert.cni.es
Inicio
Bienvenido al portal de CCN-CERT
Official report from Amazon » Summary of the Amazon Kinesis Event in the Northern Virginia (US-EAST-1) Region https://aws.amazon.com/message/11201/
Published by the Harvard Law School, quite interesting! >> A Researcher’s Guide to Some Legal Risks of Security Research https://clinic.cyber.harvard.edu/files/2020/10/Security_Researchers_Guide-2.pdf
Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection https://www.fireeye.com/blog/threat-research/2017/11/ursnif-variant-malicious-tls-callback-technique.html
FireEye
Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique
to Achieve Process Injection
to Achieve Process Injection
We recently came across a Ursnif/Gozi-ISFB sample that manipulated TLS callbacks while injecting to child process.
Multiple vulnerabilities through filename manipulation (CVE-2020-28948 and CVE-2020-28949) in PEAR https://github.com/pear/Archive_Tar/issues/33
GitHub
Multiple vulnerabilities through filename manipulation (CVE-2020-28948 and CVE-2020-28949) · Issue #33 · pear/Archive_Tar
I have submitted this to the PEAR bug tracker as well as the PEAR group mailing list, and I'm not sure if either has gone through, so opening an issue here with the hope that this is the right ...
Extraordinary Vulnerabilities Discovered in TCL Android TVs, Now World’s 3rd Largest TV Manufacturer https://sick.codes/extraordinary-vulnerabilities-discovered-in-tcl-android-tvs-now-worlds-3rd-largest-tv-manufacturer/
Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips!
Extraordinary Vulnerabilities Discovered in TCL Android TVs, Now World’s 3rd Largest TV Manufacturer. - Sick Codes - Security Research…
The following piece is the culmination of a three-month long investigation into Smart TVs running Android. Having lived through this research experience, I can wholeheartedly say that there were multiple moments that I, and another security researcher that…
xpcspy - Bidirectional XPC message interception and more (with Frida) https://github.com/hot3eed/xpcspy
GitHub
GitHub - hot3eed/xpcspy: Bidirectional XPC message interception and more. Powered by Frida
Bidirectional XPC message interception and more. Powered by Frida - hot3eed/xpcspy
Not related to security, but it's a MUST tool >> hyperfine: a command-line benchmarking tool https://github.com/sharkdp/hyperfine
GitHub
GitHub - sharkdp/hyperfine: A command-line benchmarking tool
A command-line benchmarking tool. Contribute to sharkdp/hyperfine development by creating an account on GitHub.
Flare-On 2020 Solutions Write-Ups http://tonyweb.xyz/index.php/2020/11/07/flare-on-2020-solutions-write-ups/
Windows Defender Attack Surface Reduction Rules bypass https://oddvar.moe/2018/03/15/windows-defender-attack-surface-reduction-rules-bypass/
Oddvar Moe's Blog
Windows Defender Attack Surface Reduction Rules bypass
I discovered an easy way to bypass the Windows Defender Attack Surface Reduction Rules using code inside a macro. This issue has already been fixed with the Windows Defender virus definition versio…
Resourceful macOS Malware Hides in Named Fork https://labs.sentinelone.com/resourceful-macos-malware-hides-in-named-fork/
SentinelLabs
Resourceful macOS Malware Hides in Named Fork - SentinelLabs
Threat actors targeting macOS are deploying a new trick to hide payloads and avoid detection thanks to an old technology: the named resource fork.
Everyone Talks About Insecure Randomness, But Nobody Does Anything About It https://www.airza.net/2020/11/09/everyone-talks-about-insecure-randomness-but-nobody-does-anything-about-it.html
www.airza.net
Everyone Talks About Insecure Randomness, But Nobody Does Anything About It
In which I take a crack at pointing a neural network at random noise, and achieve 95+% predictive bitwise accuracy against my hated foe in this world, Xorshift128.
AMNESIA:33 Multiple vulnerabilities found on open-source TCP/IP stacks https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01
Theft of FireEye Red Team Tools https://us-cert.cisa.gov/ncas/current-activity/2020/12/08/theft-fireeye-red-team-tools