Reversing Go - Part 1 Reversing Golang Binaries https://x0r19x91.gitlab.io/post/reversing-go-part-1/
Breaking the Google Audio reCAPTCHA with Google's own Speech to Text API https://incolumitas.com/2021/01/02/breaking-audio-recaptcha-with-googles-own-speech-to-text-api/
incolumitas.com
Breaking the Google Audio reCAPTCHA with Google's own Speech to Text API
In this project, I make use of a method from early 2019 that demonstrates how to solve the Audio reCAPTCHA with Google's own Speech to Text API. This method still works, which is quite astonishing.
Setting up iOS Debugging https://understruction.com/setting-up-ios-debugging
Code Injection: Windows Taskbar https://x0r19x91.gitlab.io/post/code-injection-mstasklist/
R.I.P ROP: CET Internals in Windows 20H1 http://windows-internals.com/cet-on-windows/
Analysis of Brunhilda malware, a DAAS (Dropper as a Service) platform https://raw.githubusercontent.com/prodaft/malware-ioc/master/BrunhildaProject/BrunHilda_DaaS.pdf
Royal Road-related attacks observed during 2020 » https://nao-sec.org/2021/01/royal-road-redive.html
nao-sec.org
Royal Road! Re:Dive - @nao_sec
Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat https://blog.malwarebytes.com/threat-analysis/2021/01/retrohunting-apt37-north-korean-apt-used-vba-self-decode-technique-to-inject-rokrat/
A Deep Dive into Lokibot Infection Chain https://blog.talosintelligence.com/2021/01/a-deep-dive-into-lokibot-infection-chain.html
Cisco Talos
A Deep Dive into Lokibot Infection Chain
Lokibot is one of the most well-known information stealers on the malware landscape. In this post, we'll provide a technical breakdown of one of the latest Lokibot campaigns. Talos also has a new script to unpack the dropper's third stage. The actors behind…
Using Windows Disposable VMs for test and research https://rolando.anton.sh/blog/2021/01/01/using-windows-disposable-vms-for-test-and-research/
Finding Targeted SUNBURST Victims with pDNS https://www.netresec.com/?page=Blog&month=2021-01&post=Finding-Targeted-SUNBURST-Victims-with-pDNS
Netresec
Finding Targeted SUNBURST Victims with pDNS
Our SunburstDomainDecoder tool can now be used to identify SUNBURST victims that have been explicitly targeted by the attackers. The only input needed is passive DNS (pDNS) data for avsvmcloud.com subdomains. Companies and organizations that have installed…
Nice vuln analysis » NTFS Remote Code Execution (CVE-2020-17096) Analysis https://blog.zecops.com/vulnerabilities/ntfs-remote-code-execution-cve-2020-17096-analysis/
Jamf
Jamf Threat Labs | Blog
From a small BAT file to Mass Logger infostealer https://isc.sans.edu/forums/diary/From+a+small+BAT+file+to+Mass+Logger+infostealer/26946/
Tying It All Together - Pwning To Own on LG phones https://douevenknow.us/post/639414006930702336/tying-it-all-together-pwning-to-own-on-lg-phones
Tumblr
Tying It All Together - Pwning To Own on LG phones
Last year I detailed a secure EL3 vulnerability which affected (and still affects, for devices with discontinued updates) LG Android devices. However, this vulnerability alone isn't actually all that...
Reverse Engineering The Saboteur game for Xbox360 with Linux https://daniele.tech/2020/12/reverse-engineering-the-saboteur-game-for-xbox360-with-linux/
Daniele Mte90 Scasciafratte
Reverse Engineering The Saboteur game for Xbox360 with Linux - Daniele Mte90 Scasciafratte
I spent my Christmas hoildays on reverse engineering some files of this Xbox 360 game version just for fun with not an happy conclusion...
THE EVOLUTION OF THE FIN7 JSSLOADER https://www.morphisec.com/hubfs/eBooks_and_Whitepapers/FIN7%20JSSLOADER%20FINAL%20WEB.pdf
Cobalt Strike and Metasploit accounted for a quarter of all malware C&C servers in 2020 https://www.zdnet.com/google-amp/article/cobalt-strike-and-metasploit-accounted-for-a-quarter-of-all-malware-c-c-servers-in-2020/
ZDNet
Cobalt Strike and Metasploit accounted for a quarter of all malware C&C servers in 2020
Security firm Recorded Future said it tracked more than 10,000 malware command and control servers last year, used across more than 80 malware families.
Analyzing CVE-2020-16040 https://faraz.faith/2021-01-07-cve-2020-16040-analysis/
faraz.faith
Analyzing CVE-2020-16040
We have continued the post series on methods for unrelocating Windows modules, enjoy the reading! » https://reversea.me/index.php/unrelocating-windows-modules-ii/
Bug discovery diaries: uncovering sngrep overflow issues with blackbox fuzzing https://www.rtcsec.com/post/2021/01/bug-discovery-diaries-uncovering-sngrep-overflow-issues-with-blackbox-fuzzing/