RME-DisCo @ UNIZAR [www.reversea.me]
@reverseame
3.4K
subscribers
1
photo
5.55K
links
Telegram channel of RME, part of the DisCo Research Group of the University of Zaragoza (Spain) focused on cybersecurity aspects. "It’s not that I have something to hide. I have nothing I want you to see"
Link to the channel:
https://t.me/reverseame
Download Telegram
Join
RME-DisCo @ UNIZAR [www.reversea.me]
3.4K subscribers
RME-DisCo @ UNIZAR [www.reversea.me]
https://bugs.chromium.org/p/project-zero/issues/detail?id=2004
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.xpnsec.com/undersanding-and-evading-get-injectedthread/
XPN InfoSec Blog
@_xpn_ - Understanding and Evading Get-InjectedThread
One of the many areas of this field that I really enjoy is the "cat and mouse" game played between RedTeam and BlueTeam, each forcing the other to up their game. Often we see some awesome tools being released to help defenders detect malware or shellcode…
RME-DisCo @ UNIZAR [www.reversea.me]
https://revers.engineering/patchguard-detection-of-hypervisor-based-instrospection-p1/
Reverse Engineering
Patchguard: Detection of Hypervisor Based Introspection [P1] - Reverse Engineering
Errata Or Nah? Over the last 2-3 years, Microsoft has inserted various methods of virtualization introspection detection (big brain words) into the workings of patchguard. It shouldn’t come as surprise that this has happened, as subverting kernel patch protection…
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/olafhartong/status/1255234547710676994?s=19
Twitter
Olaf Hartong
#Sysmon 11 is out with a new Event type and several improvements! I’ve published a blog post detailing all new features here: https://t.co/kHcnnX1Ue6 #DFIR #Sysinternals #ThreatHunting
RME-DisCo @ UNIZAR [www.reversea.me]
https://robertheaton.com/2020/04/27/how-does-a-tcp-reset-attack-work/
Robert Heaton
How does a TCP Reset Attack work? | Robert Heaton
A TCP reset attack is executed using a single packet of data, no more than a few bytes in size. A spoofed TCP segment, crafted and sent by an attacker, tricks two victims into abandoning a TCP connection, interrupting possibly vital communications between…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.elcomsoft.com/2020/04/forensic-guide-to-imessage-whatsapp-telegram-signal-and-skype-data-acquisition/
ElcomSoft blog
Forensic guide to iMessage, WhatsApp, Telegram, Signal and Skype data acquisition
Instant messaging apps have become the de-facto standard of real-time, text-based communications. The acquisition of instant messaging chats and communication histories can be extremely important for an investigation. In this article, we compare the five…
RME-DisCo @ UNIZAR [www.reversea.me]
https://erev0s.com/blog/how-hook-android-native-methods-frida-noob-friendly/
Erev0S
How to hook Android Native methods with Frida (Noob Friendly)
Hooking C/C++ code in Android application using Frida with introduction and explainations in every step - noob friendly
RME-DisCo @ UNIZAR [www.reversea.me]
https://link.springer.com/search?facet-content-type=%22Book%22&package=mat-covid19_textbooks&sortOrder=newestFirst&showAll=true&facet-discipline=%22Computer+Science%22
RME-DisCo @ UNIZAR [www.reversea.me]
Libros gratis de Springer de Computer Science durante esta situación de la COVID19
RME-DisCo @ UNIZAR [www.reversea.me]
https://blogs.windows.com/windowsdeveloper/2020/04/30/rust-winrt-public-preview/amp/?__twitter_impression=true
Windows Developer Blog
Rust/WinRT Public Preview
We are excited to announce that the Rust/WinRT project finally has a permanent and public home on GitHub: https://github.com/microsoft/winrt-rs Rust/WinRT follows in the tradition established by C++/WinRT of building language projections for the Windows Runtime…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.doyensec.com//2020/04/30/polymorphic-images-for-xss.html
Doyensec
Researching Polymorphic Images for XSS on Google Scholar
A few months ago I came across a curious design pattern on Google Scholar. Multiple screens of the web application were fetched and rendered using a combination of location.hash parameters and XHR to retrieve the supposed templating snippets from a relative…
RME-DisCo @ UNIZAR [www.reversea.me]
https://artik.blue/reversing-radare2-1
ExpiredDomains.com
artik.blue is for sale! Check it out on ExpiredDomains.com
Buy artik.blue for 100 on GoDaddy via ExpiredDomains.com. This premium expired .blue domain is ideal for establishing a strong online identity.
RME-DisCo @ UNIZAR [www.reversea.me]
https://blog.tst.sh/reverse-engineering-flutter-apps-part-1/
ping's blog
Reverse engineering Flutter apps (Part 1)
Chapter 1: Down the rabbit hole
To start this journey I'll cover some backstory on the Flutter stack and how it works.
What you probably already know: Flutter was built from the ground up with its own render pipeline and widget library, allowing it to…
RME-DisCo @ UNIZAR [www.reversea.me]
https://blogs.jpcert.or.jp/en/2020/04/ie-firefox-0day.html
JPCERT/CC Eyes
Attacks Simultaneously Exploiting Vulnerability in IE (CVE-2020-0674) and Firefox (CVE-2019-17026) - JPCERT/CC Eyes
On 8 January 2020, Mozilla released an advisory regarding a vulnerability in Firefox. On 17 January, Microsoft reported that 0-day attacks exploiting a vulnerability in Internet Explorer (IE) had been seen in the wild. JPCERT/CC confirmed attacks exploiting…
RME-DisCo @ UNIZAR [www.reversea.me]
https://carstein.github.io/2020/04/18/writing-simple-fuzzer-1.html
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.ctrl.blog/entry/restore-lost-email-from-ram.html
www.ctrl.blog
How I recovered a lost email from my email client’s memory
A bug caused 30 minutes of work on an email to disappear. However, I was able to recover it by poking around in the process memory using gdb/gcore. Here’s how.
RME-DisCo @ UNIZAR [www.reversea.me]
https://unit42.paloaltonetworks.com/hunting-mutex/
Unit 42
Hunting the Mutex
Mutex analysis is an often overlooked and useful tool for malware author fingerprinting, family classification, and even discovery.
RME-DisCo @ UNIZAR [www.reversea.me]
https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html
Google Cloud Blog
Navigating the MAZE: Tactics, Techniques and Procedures Associated With MAZE Ransomware Incidents | Google Cloud Blog
RME-DisCo @ UNIZAR [www.reversea.me]
https://github.com/maxpl0it/CVE-2020-0674-Exploit
GitHub
GitHub - maxpl0it/CVE-2020-0674-Exploit: This is an exploit for CVE-2020-0674 that runs on the x64 version of IE 8, 9, 10, and…
This is an exploit for CVE-2020-0674 that runs on the x64 version of IE 8, 9, 10, and 11 on Windows 7. - maxpl0it/CVE-2020-0674-Exploit
RME-DisCo @ UNIZAR [www.reversea.me]
https://twitter.com/moyix/status/1099724239450497025?s=09
Twitter
Brendan Dolan-Gavitt
Heading into the research talks at BAR 2019 now. Up first is B2R2: Building an Efficient Front-End for Binary Analysis, our best paper winner.
RME-DisCo @ UNIZAR [www.reversea.me]
https://github.com/horsicq/XELFViewer
GitHub
GitHub - horsicq/XELFViewer: ELF file viewer/editor for Windows, Linux and MacOS.
ELF file viewer/editor for Windows, Linux and MacOS. - horsicq/XELFViewer