Bug or Feature: Privilege Escalation in Windows Autopilot https://sec-consult.com/en/blog/2020/11/bug-oder-feature-privilege-escalation-in-windows-autopilot/
SEC Consult
Bug Or Feature: Privilege Escalation In Windows Autopilot
SEC Consult identified a local privilege escalation vulnerability in the Windows Autopilot deployment process.
Shadows from the past threaten Italian enterprises https://yoroi.company/research/shadows-from-the-past-threaten-italian-enterprises/
Tinexta Cyber
Il polo italiano della Cyber Security
Innovazione digitale sicura Protezione per un futuro digitale resiliente Tinexta Cyber è il polo italiano della cyber security. Parte del gruppo Tinexta, nasce dalla sintesi di tre eccellenze – Corvallis, Swascan e Yoroi – con l’obiettivo di supportare le…
BruteShark: a Network Forensic Analysis Tool (NFAT) that performs deep processing and inspection of network traffic https://github.com/odedshimon/BruteShark
GitHub
GitHub - odedshimon/BruteShark: Network Analysis Tool
Network Analysis Tool. Contribute to odedshimon/BruteShark development by creating an account on GitHub.
"Old but gold" » How to get every detail about SSDT , GDT , IDT in a blink of an eye https://rayanfam.com/topics/how-to-get-every-details-about-ssdt-gdt-idt-in-a-blink-of-an-eye/
Rayanfam Blog
How to get every detail about SSDT , GDT , IDT in a blink of an eye
We write about Windows Internals, Hypervisors, Linux, and Networks.
How anti-fingerprinting extensions tend to make fingerprinting easier https://palant.info/2020/12/10/how-anti-fingerprinting-extensions-tend-to-make-fingerprinting-easier/
Almost Secure
How anti-fingerprinting extensions tend to make fingerprinting easier
Browser extensions claiming to protect against fingerprinting will typically result in more data available for fingerprinting.
This is for the Pwners: Exploiting a WebKit 0-day in PlayStation 4 https://www.synacktiv.com/publications/this-is-for-the-pwners-exploiting-a-webkit-0-day-in-playstation-4.html
Synacktiv
This is for the Pwners: Exploiting a WebKit 0-day in PlayStation 4
WES-NG provides the list of vulnerabilities the Windows OS is vulnerable to, including any exploits for these vulnerabilities https://github.com/bitsadmin/wesng
GitHub
GitHub - bitsadmin/wesng: Windows Exploit Suggester - Next Generation
Windows Exploit Suggester - Next Generation. Contribute to bitsadmin/wesng development by creating an account on GitHub.
CVE-2020-17143 and CVE-2020-17141 PoCs (XXE bugs against Exchange Server) https://twitter.com/steventseeley/status/1337415647593107457?s=20
Twitter
ϻг_ϻε
I provided PoC exploits for CVE-2020-17143 and CVE-2020-17141 which demonstrate the XXE bugs against Exchange Server. - Low privileged authentication only - CVE-2020-17141 is interesting because its in the EWS API https://t.co/yYB8Frzwsl https://t.co/wmtGRPMpVB
Watchcom discovers new Cisco Jabber vulnerabilities https://watchcom.no/nyheter/nyhetsarkiv/cisco-jabber-vulnerabilities-resurface/
www.watchcom.no
Cisco Jabber vulnerabilities resurface
Understanding an email header https://mediatemple.net/community/products/dv/204643950/understanding-an-email-header
Vulnerability Spotlight: Multiple vulnerabilities in Foxit PDF Reader JavaScript engine https://blog.talosintelligence.com/2020/12/vuln-spotlight-foxit-javascript-reader.html
Cisco Talos Blog
Vulnerability Spotlight: Multiple vulnerabilities in Foxit PDF Reader JavaScript engine
Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities. Blog by Jon Munshaw.
Executive summary
Cisco Talos recently discovered multiple vulnerabilities in Foxit PDF Reader’s JavaScript engine. Foxit PDF Reader is a commonly used PDF reader…
Executive summary
Cisco Talos recently discovered multiple vulnerabilities in Foxit PDF Reader’s JavaScript engine. Foxit PDF Reader is a commonly used PDF reader…
A brief introduction about CLSID and a bypass found https://medium.com/stolabs/a-brief-introduction-about-clsid-and-a-bypass-found-c11be972a38b
Medium
A brief introduction about CLSID and a bypass found
Hi there! A few days ago I was studying about the CLSID, or Class ID, and I’ve found something interesting! A bypass in the Avast Sandbox…
Test for network leaks, discover a product flaw and get vendor to fix https://medium.com/sensorfu/test-for-network-leaks-discover-a-product-flaw-and-get-vendor-to-fix-c041abbda39a
Medium
Test for network leaks, discover a product flaw and get vendor to fix
Plot twist: this time it is not about us doing vulnerability research and reporting. This is a story about our customer in action, told to…
Analysing the fall 2020 Emotet Campaign https://neurosoft.gr/analysing-the-fall-2020-emotet-campaign/
CVE-2020-17140 Windows SMB Information Disclosure Analysis https://blogs.360.cn/post/CVE-2020-17140-Analysis.html
Brownie is a platform to rapidly prototype and weaponise DLL hijacks https://github.com/slaeryan/AQUARMOURY/tree/master/Brownie
Nice reading about ZK proofs » Reverie: An optimized zero-knowledge proof system https://blog.trailofbits.com/2020/12/14/reverie-an-optimized-zero-knowledge-proof-system/
The Trail of Bits Blog
Reverie: An optimized zero-knowledge proof system
Zero-knowledge proofs, once a theoretical curiosity, have recently seen widespread deployment in blockchain systems such as Zcash and Monero. However, most blockchain applications of ZK proofs make proof size and performance tradeoffs that are a poor fit…
Page Fault Injection in Virtual Machines: Accessing Swapped-Out Pages from HVMI https://hvmi.github.io/blog/2020/12/14/pfinjection.html
emba: an analyzer for Linux-based firmware of embedded devices https://github.com/e-m-b-a/emba
GitHub
GitHub - e-m-b-a/emba: EMBA - The firmware security analyzer
EMBA - The firmware security analyzer. Contribute to e-m-b-a/emba development by creating an account on GitHub.
Root Cause Analysis of a Heap-Based Buffer Overflow in GNU Readline https://insinuator.net/2020/12/root-cause-analysis-of-a-heap-based-buffer-overflow-in-gnu-readline/