Securing the fight against COVID-19 through open source https://securitylab.github.com/research/securing-the-fight-against-covid19-through-oss
GHSL-2020-138, GHSL-2020-139: Remote code execution (RCE) and elevation of privileges (EoP) in SmartStoreNET - CVE-2020-27996, CVE-2020-27997 https://securitylab.github.com/advisories/GHSL-2020-138-139-SmartstoreAG-SmartStoreNET
GitHub Security Lab
GHSL-2020-138, GHSL-2020-139: Remote code execution (RCE) and elevation of privileges (EoP) in SmartStoreNET - CVE-2020-27996,…
SmartStoreNET 4.0.0 is vulnerable to Remote code execution (RCE) and elevation of privileges (EoP)
GHSL-2020-142: Heap memory corruption in png-img - CVE-2020-28248 https://securitylab.github.com/advisories/GHSL-2020-142-gemini-png-img
Github
GHSL-2020-142: Heap memory corruption in png-img - CVE-2020-28248 - GitHub Security Lab
The NAN bindings provided by png-img for libpng are vulnerable to an integer overflow which results in an underallocation of heap memory and subsequent heap memory corruption.
"/proc/kmem" reimplementation for Windows 10. It allows a programmer to read/write kernel memory simply by opening a handle to a process named "/proc/kmem" https://githacks.org/_xeroxz/kmem
GitLab
_xeroxz / kmem
/proc/kmem reimplementation for windows
1768 K: a tool to decode and dump the configuration of Cobal Strike beacons https://blog.didierstevens.com/2020/11/07/1768-k/
Didier Stevens
1768 K
According to Wikipedia, 1768 Kelvin is the melting point of the metal cobalt. This tool decodes and dumps the configuration of Cobalt Strike beacons. You can find a sample beacon here. 1768_v0_0_3.…
Firefox Vulnerability Research Part 2 https://blog.exodusintel.com/2020/11/10/firefox-vulnerability-research-part-2/
Exodus Intelligence
Firefox Vulnerability Research Part 2 - Exodus Intelligence
By Arthur Gerkis and David Barksdale This series of posts makes public some old Firefox research which our Zero-Day customers had access to before it was known publicly, and then our N-Day customers after it was patched. We’ve also used this research to teach…
Chaining vulnerabilities lead to account takeover https://medium.com/bugbountywriteup/chaining-vulnerabilities-lead-to-account-takeover-b583f0c10591
Medium
Chaining vulnerabilities lead to account takeover
In this write-up, I will explain how I was able to chain five vulnerabilities that lead to one link click account takeover.
Running code in the context of iOS Kernel: Part I + LPE POC on iOS 13.7 https://blog.zecops.com/vulnerabilities/running-code-in-the-context-of-ios-kernel-part-i-lpe-poc-on-ios-13-7/
Jamf
Jamf Threat Labs | Blog
Well, finally some good news in 2020 >> https://twitter.com/ghidraninja/status/1339653192917913600?s=20
Twitter
stacksmashing
It's happening: Ghidra is finally getting a debugger! https://t.co/rQeWPYwg3i
The Definitive Guide to Linux System Calls https://blog.packagecloud.io/eng/2016/04/05/the-definitive-guide-to-linux-system-calls/#kernel-side-int-0x80-entry-point
blog.packagecloud.io
The Definitive Guide to Linux System Calls | Packagecloud Blog
This complete guide explains all about Linux system calls with sample codes and results.
NetworkSniffer: Log iOS network traffic without a proxy https://github.com/evilpenguin/NetworkSniffer
GitHub
GitHub - evilpenguin/NetworkSniffer: Log iOS network traffic without a proxy
Log iOS network traffic without a proxy. Contribute to evilpenguin/NetworkSniffer development by creating an account on GitHub.
Analysis about the issues happened in Google last Monday » Google Cloud Infrastructure Components Incident #20013 https://status.cloud.google.com/incident/zall/20013#20013004
Architecture of a ransomware (1/2) https://securityshenaningans.medium.com/architecture-of-a-ransomware-1-2-1b9fee757fcb
Medium
Architecture of a ransomware (1/2)
Last couple of months we’ve seen a rise in ransomware related incidents, mostly due to the increase of remote work COVID-19. Nevertheless…
.NET Process injection in a new process with QueueUserAPC using D/invoke - compatible with gadgettojscript https://gist.github.com/jfmaes/944991c40fb34625cf72fd33df1682c0
Gist
.NET Process injection in a new process with QueueUserAPC using D/invoke - compatible with gadgettojscript
.NET Process injection in a new process with QueueUserAPC using D/invoke - compatible with gadgettojscript - DInjectQueuerAPC.cs
Good report on the last events with SolarWinds Orion » Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/
Microsoft News
Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect…
We, along with the security industry and our partners, continue to investigate the extent of the Solorigate attack. While investigations are underway, we want to provide the defender community with intel to understand the scope and impact, remediation guidance…
Discovering, exploiting and shutting down a dangerous Windows print spooler vulnerability https://www.accenture.com/us-en/blogs/cyber-defense/discovering-exploiting-shutting-down-dangerous-windows-print-spooler-vulnerability
Accenture
What We Think | Business & Technology Insights
Accenture thought leadership offers business and technology insights on key market forces & technologies to set your company on the path to value. Learn more.
uafuzz: Binary-level Directed Fuzzing for Use-After-Free Vulnerabilities https://securityonline.info/uafuzz/
Penetration Testing
uafuzz: Binary-level Directed Fuzzing for Use-After-Free Vulnerabilities
uafuzz is a directed fuzzer dedicated to Use-After-Free (UAF) bugs at binary-level by carefully tuning the key components of directed fuzzing