RME-DisCo @ UNIZAR [www.reversea.me]
@reverseame
3.4K
subscribers
1
photo
5.55K
links
Telegram channel of RME, part of the DisCo Research Group of the University of Zaragoza (Spain) focused on cybersecurity aspects. "It’s not that I have something to hide. I have nothing I want you to see"
Link to the channel:
https://t.me/reverseame
Download Telegram
Join
RME-DisCo @ UNIZAR [www.reversea.me]
3.4K subscribers
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/doegox/status/1252667831302455296?s=09
Twitter
Philippe Teuwen
"If succesfuly exploited, an attacker within NFC range could obtain remote code execution on android device's NFC daemon." https://t.co/T24r3qWNnF
RME-DisCo @ UNIZAR [www.reversea.me]
https://github.com/james0x40/CVE-2020-0624
GitHub
GitHub - james0x40/CVE-2020-0624: win32k use-after-free poc
win32k use-after-free poc. Contribute to james0x40/CVE-2020-0624 development by creating an account on GitHub.
RME-DisCo @ UNIZAR [www.reversea.me]
https://insinuator.net/2020/04/cve-2020-0022-an-android-8-0-9-0-bluetooth-zero-click-rce-bluefrag/
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/SBousseaden/status/1253421514386337795?s=19
Twitter
Samir
started as a a fun way to take notes ... 16 mindmaps so far :) https://t.co/1VA1OUBzQ5
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.zecops.com/vulnerabilities/youve-got-0-click-mail/
Jamf
Jamf Threat Labs | Blog
RME-DisCo @ UNIZAR [www.reversea.me]
https://h0mbre.github.io/atillk64_exploit/#
The Human Machine Interface
CVE-2020-12138 Exploit Proof-of-Concept, Privilege Escalation in ATI Technologies Inc. Driver atillk64.sys
Background
RME-DisCo @ UNIZAR [www.reversea.me]
https://itm4n.github.io/windows-dll-hijacking-clarified/
itm4n’s blog
Windows DLL Hijacking (Hopefully) Clarified
Whenever a “new” DLL hijacking / planting trick is posted on Twitter, it generates a lot of comments. “It’s not a vulnerability!” or “There is a lot of hijackable DLLs on Windows…” are the most common reactions. Though, people often don’t really speak about…
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.fireeye.com/blog/threat-research/2020/03/six-facts-about-address-space-layout-randomization-on-windows.html
Mandiant
Six Facts about Address Space Layout Randomization on Windows | Mandiant
RME-DisCo @ UNIZAR [www.reversea.me]
https://bugs.chromium.org/p/project-zero/issues/detail?id=2004
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.xpnsec.com/undersanding-and-evading-get-injectedthread/
XPN InfoSec Blog
@_xpn_ - Understanding and Evading Get-InjectedThread
One of the many areas of this field that I really enjoy is the "cat and mouse" game played between RedTeam and BlueTeam, each forcing the other to up their game. Often we see some awesome tools being released to help defenders detect malware or shellcode…
RME-DisCo @ UNIZAR [www.reversea.me]
https://revers.engineering/patchguard-detection-of-hypervisor-based-instrospection-p1/
Reverse Engineering
Patchguard: Detection of Hypervisor Based Introspection [P1] - Reverse Engineering
Errata Or Nah? Over the last 2-3 years, Microsoft has inserted various methods of virtualization introspection detection (big brain words) into the workings of patchguard. It shouldn’t come as surprise that this has happened, as subverting kernel patch protection…
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/olafhartong/status/1255234547710676994?s=19
Twitter
Olaf Hartong
#Sysmon 11 is out with a new Event type and several improvements! I’ve published a blog post detailing all new features here: https://t.co/kHcnnX1Ue6 #DFIR #Sysinternals #ThreatHunting
RME-DisCo @ UNIZAR [www.reversea.me]
https://robertheaton.com/2020/04/27/how-does-a-tcp-reset-attack-work/
Robert Heaton
How does a TCP Reset Attack work? | Robert Heaton
A TCP reset attack is executed using a single packet of data, no more than a few bytes in size. A spoofed TCP segment, crafted and sent by an attacker, tricks two victims into abandoning a TCP connection, interrupting possibly vital communications between…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.elcomsoft.com/2020/04/forensic-guide-to-imessage-whatsapp-telegram-signal-and-skype-data-acquisition/
ElcomSoft blog
Forensic guide to iMessage, WhatsApp, Telegram, Signal and Skype data acquisition
Instant messaging apps have become the de-facto standard of real-time, text-based communications. The acquisition of instant messaging chats and communication histories can be extremely important for an investigation. In this article, we compare the five…
RME-DisCo @ UNIZAR [www.reversea.me]
https://erev0s.com/blog/how-hook-android-native-methods-frida-noob-friendly/
Erev0S
How to hook Android Native methods with Frida (Noob Friendly)
Hooking C/C++ code in Android application using Frida with introduction and explainations in every step - noob friendly
RME-DisCo @ UNIZAR [www.reversea.me]
https://link.springer.com/search?facet-content-type=%22Book%22&package=mat-covid19_textbooks&sortOrder=newestFirst&showAll=true&facet-discipline=%22Computer+Science%22
RME-DisCo @ UNIZAR [www.reversea.me]
Libros gratis de Springer de Computer Science durante esta situación de la COVID19
RME-DisCo @ UNIZAR [www.reversea.me]
https://blogs.windows.com/windowsdeveloper/2020/04/30/rust-winrt-public-preview/amp/?__twitter_impression=true
Windows Developer Blog
Rust/WinRT Public Preview
We are excited to announce that the Rust/WinRT project finally has a permanent and public home on GitHub: https://github.com/microsoft/winrt-rs Rust/WinRT follows in the tradition established by C++/WinRT of building language projections for the Windows Runtime…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.doyensec.com//2020/04/30/polymorphic-images-for-xss.html
Doyensec
Researching Polymorphic Images for XSS on Google Scholar
A few months ago I came across a curious design pattern on Google Scholar. Multiple screens of the web application were fetched and rendered using a combination of location.hash parameters and XHR to retrieve the supposed templating snippets from a relative…
RME-DisCo @ UNIZAR [www.reversea.me]
https://artik.blue/reversing-radare2-1
ExpiredDomains.com
artik.blue is for sale! Check it out on ExpiredDomains.com
Buy artik.blue for 100 on GoDaddy via ExpiredDomains.com. This premium expired .blue domain is ideal for establishing a strong online identity.
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.tst.sh/reverse-engineering-flutter-apps-part-1/
ping's blog
Reverse engineering Flutter apps (Part 1)
Chapter 1: Down the rabbit hole
To start this journey I'll cover some backstory on the Flutter stack and how it works.
What you probably already know: Flutter was built from the ground up with its own render pipeline and widget library, allowing it to…