New APT32 Malware Campaign Targets Cambodian Government https://www.recordedfuture.com/apt32-malware-campaign/
Recordedfuture
New APT32 Malware Campaign Targets Cambodian Government
Recorded Future’s Insikt Group has discovered a new malware campaign targeting the Cambodian government using an ASEAN-themed spearphish.
Nice contribution » Diff tool for comparing symbols in PDB files https://github.com/WalkingCat/SymDiff
GitHub
GitHub - WalkingCat/SymDiff: Diff tool for comparing symbols in PDB files
Diff tool for comparing symbols in PDB files. Contribute to WalkingCat/SymDiff development by creating an account on GitHub.
CVE-2020-16995: Microsoft Azure Network Watcher Linux Extension EoP https://www.intezer.com/blog/cloud-security/cve-2020-16995-microsoft-azure-network-watcher-linux-extension/
Intezer
CVE-2020-16995: Microsoft Azure Network Watcher Linux Extension EoP
Disclosing a vulnerability in Microsoft Azure's VM extension known as the Network Watcher Agent for Linux.
Parent PID Spoofing (Stage 2) Ataware Ransomware – Part 0x3 https://www.securityinbits.com/malware-analysis/parent-pid-spoofing-stage-2-ataware-ransomware-part-3/
Securityinbits
Parent PID Spoofing (Stage 2) Ataware Ransomware - Part 0x3 - Securityinbits
Ataware Ransomware Stage 2 uses Parent PID Spoofing technique to change it parent PID to lsass.exe and download the final Ataware Ransomware.
Cryptofuzz - Differential cryptography fuzzing https://github.com/guidovranken/cryptofuzz
Introduction to Reverse Engineering with Ghidra: A Four Session Course https://wrongbaud.github.io/posts/ghidra-training/
Wrongbaud’s Blog
Introduction to Reverse Engineering with Ghidra: A Four Session Course
A blog focusing on hardware and software reverse engineering
Securing the fight against COVID-19 through open source https://securitylab.github.com/research/securing-the-fight-against-covid19-through-oss
GHSL-2020-138, GHSL-2020-139: Remote code execution (RCE) and elevation of privileges (EoP) in SmartStoreNET - CVE-2020-27996, CVE-2020-27997 https://securitylab.github.com/advisories/GHSL-2020-138-139-SmartstoreAG-SmartStoreNET
GitHub Security Lab
GHSL-2020-138, GHSL-2020-139: Remote code execution (RCE) and elevation of privileges (EoP) in SmartStoreNET - CVE-2020-27996,…
SmartStoreNET 4.0.0 is vulnerable to Remote code execution (RCE) and elevation of privileges (EoP)
GHSL-2020-142: Heap memory corruption in png-img - CVE-2020-28248 https://securitylab.github.com/advisories/GHSL-2020-142-gemini-png-img
Github
GHSL-2020-142: Heap memory corruption in png-img - CVE-2020-28248 - GitHub Security Lab
The NAN bindings provided by png-img for libpng are vulnerable to an integer overflow which results in an underallocation of heap memory and subsequent heap memory corruption.
"/proc/kmem" reimplementation for Windows 10. It allows a programmer to read/write kernel memory simply by opening a handle to a process named "/proc/kmem" https://githacks.org/_xeroxz/kmem
GitLab
_xeroxz / kmem
/proc/kmem reimplementation for windows
1768 K: a tool to decode and dump the configuration of Cobal Strike beacons https://blog.didierstevens.com/2020/11/07/1768-k/
Didier Stevens
1768 K
According to Wikipedia, 1768 Kelvin is the melting point of the metal cobalt. This tool decodes and dumps the configuration of Cobalt Strike beacons. You can find a sample beacon here. 1768_v0_0_3.…
Firefox Vulnerability Research Part 2 https://blog.exodusintel.com/2020/11/10/firefox-vulnerability-research-part-2/
Exodus Intelligence
Firefox Vulnerability Research Part 2 - Exodus Intelligence
By Arthur Gerkis and David Barksdale This series of posts makes public some old Firefox research which our Zero-Day customers had access to before it was known publicly, and then our N-Day customers after it was patched. We’ve also used this research to teach…
Chaining vulnerabilities lead to account takeover https://medium.com/bugbountywriteup/chaining-vulnerabilities-lead-to-account-takeover-b583f0c10591
Medium
Chaining vulnerabilities lead to account takeover
In this write-up, I will explain how I was able to chain five vulnerabilities that lead to one link click account takeover.
Running code in the context of iOS Kernel: Part I + LPE POC on iOS 13.7 https://blog.zecops.com/vulnerabilities/running-code-in-the-context-of-ios-kernel-part-i-lpe-poc-on-ios-13-7/
Jamf
Jamf Threat Labs | Blog
Well, finally some good news in 2020 >> https://twitter.com/ghidraninja/status/1339653192917913600?s=20
Twitter
stacksmashing
It's happening: Ghidra is finally getting a debugger! https://t.co/rQeWPYwg3i
The Definitive Guide to Linux System Calls https://blog.packagecloud.io/eng/2016/04/05/the-definitive-guide-to-linux-system-calls/#kernel-side-int-0x80-entry-point
blog.packagecloud.io
The Definitive Guide to Linux System Calls | Packagecloud Blog
This complete guide explains all about Linux system calls with sample codes and results.
NetworkSniffer: Log iOS network traffic without a proxy https://github.com/evilpenguin/NetworkSniffer
GitHub
GitHub - evilpenguin/NetworkSniffer: Log iOS network traffic without a proxy
Log iOS network traffic without a proxy. Contribute to evilpenguin/NetworkSniffer development by creating an account on GitHub.