Cryptominers Exploiting WebLogic RCE CVE-2020-14882 https://thedfirreport.com/2020/11/12/cryptominers-exploiting-weblogic-rce-cve-2020-14882/
The DFIR Report
Cryptominers Exploiting WebLogic RCE CVE-2020-14882
Intro Towards the end of October, we started seeing attackers take advantage of a WebLogic RCE vulnerability (CVE-2020-14882). Recently, SANS ISC talked about this vulnerability being exploited in …
bdshemu: The Bitdefender shellcode emulator https://hvmi.github.io/blog/2020/11/11/bdshemu.html
Advanced MSSQL Injection Tricks https://swarm.ptsecurity.com/advanced-mssql-injection-tricks/
[Linux Kernel Exploitation 0x0] Debugging the Kernel with QEMU https://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x0-debugging.html
DPWs are the new DPCs : Deferred Procedure Waits in Windows 10 21H1 https://windows-internals.com/dpws-are-the-new-dpcs-deferred-procedure-waits-in-windows-10-21h1/
Introducing x64 emulation in preview for Windows 10 on ARM PCs to the Windows Insider Program https://blogs.windows.com/windows-insider/2020/12/10/introducing-x64-emulation-in-preview-for-windows-10-on-arm-pcs-to-the-windows-insider-program/
Windows Insider Blog
Introducing x64 emulation in preview for Windows 10 on ARM PCs to the Windows Insider Program
Updated 11/16/2021: x64 emulation for Windows is now generally available in Windows 11. For those interested in experiencing this, a PC running Windows 11 on Arm is required. Today, we're releasing the first preview of x64 emulation
How to get root on Ubuntu 20.04 by pretending nobody’s /home https://securitylab.github.com/research/Ubuntu-gdm3-accountsservice-LPE
New APT32 Malware Campaign Targets Cambodian Government https://www.recordedfuture.com/apt32-malware-campaign/
Recordedfuture
New APT32 Malware Campaign Targets Cambodian Government
Recorded Future’s Insikt Group has discovered a new malware campaign targeting the Cambodian government using an ASEAN-themed spearphish.
Nice contribution » Diff tool for comparing symbols in PDB files https://github.com/WalkingCat/SymDiff
GitHub
GitHub - WalkingCat/SymDiff: Diff tool for comparing symbols in PDB files
Diff tool for comparing symbols in PDB files. Contribute to WalkingCat/SymDiff development by creating an account on GitHub.
CVE-2020-16995: Microsoft Azure Network Watcher Linux Extension EoP https://www.intezer.com/blog/cloud-security/cve-2020-16995-microsoft-azure-network-watcher-linux-extension/
Intezer
CVE-2020-16995: Microsoft Azure Network Watcher Linux Extension EoP
Disclosing a vulnerability in Microsoft Azure's VM extension known as the Network Watcher Agent for Linux.
Parent PID Spoofing (Stage 2) Ataware Ransomware – Part 0x3 https://www.securityinbits.com/malware-analysis/parent-pid-spoofing-stage-2-ataware-ransomware-part-3/
Securityinbits
Parent PID Spoofing (Stage 2) Ataware Ransomware - Part 0x3 - Securityinbits
Ataware Ransomware Stage 2 uses Parent PID Spoofing technique to change it parent PID to lsass.exe and download the final Ataware Ransomware.
Cryptofuzz - Differential cryptography fuzzing https://github.com/guidovranken/cryptofuzz
Introduction to Reverse Engineering with Ghidra: A Four Session Course https://wrongbaud.github.io/posts/ghidra-training/
Wrongbaud’s Blog
Introduction to Reverse Engineering with Ghidra: A Four Session Course
A blog focusing on hardware and software reverse engineering
Securing the fight against COVID-19 through open source https://securitylab.github.com/research/securing-the-fight-against-covid19-through-oss
GHSL-2020-138, GHSL-2020-139: Remote code execution (RCE) and elevation of privileges (EoP) in SmartStoreNET - CVE-2020-27996, CVE-2020-27997 https://securitylab.github.com/advisories/GHSL-2020-138-139-SmartstoreAG-SmartStoreNET
GitHub Security Lab
GHSL-2020-138, GHSL-2020-139: Remote code execution (RCE) and elevation of privileges (EoP) in SmartStoreNET - CVE-2020-27996,…
SmartStoreNET 4.0.0 is vulnerable to Remote code execution (RCE) and elevation of privileges (EoP)
GHSL-2020-142: Heap memory corruption in png-img - CVE-2020-28248 https://securitylab.github.com/advisories/GHSL-2020-142-gemini-png-img
Github
GHSL-2020-142: Heap memory corruption in png-img - CVE-2020-28248 - GitHub Security Lab
The NAN bindings provided by png-img for libpng are vulnerable to an integer overflow which results in an underallocation of heap memory and subsequent heap memory corruption.
"/proc/kmem" reimplementation for Windows 10. It allows a programmer to read/write kernel memory simply by opening a handle to a process named "/proc/kmem" https://githacks.org/_xeroxz/kmem
GitLab
_xeroxz / kmem
/proc/kmem reimplementation for windows
1768 K: a tool to decode and dump the configuration of Cobal Strike beacons https://blog.didierstevens.com/2020/11/07/1768-k/
Didier Stevens
1768 K
According to Wikipedia, 1768 Kelvin is the melting point of the metal cobalt. This tool decodes and dumps the configuration of Cobalt Strike beacons. You can find a sample beacon here. 1768_v0_0_3.…