Analyzing CVE-2020-16040 https://faraz.faith/2021-01-07-cve-2020-16040-analysis/
faraz.faith
Analyzing CVE-2020-16040
We have continued the post series on methods for unrelocating Windows modules, enjoy the reading! » https://reversea.me/index.php/unrelocating-windows-modules-ii/
Bug discovery diaries: uncovering sngrep overflow issues with blackbox fuzzing https://www.rtcsec.com/post/2021/01/bug-discovery-diaries-uncovering-sngrep-overflow-issues-with-blackbox-fuzzing/
Parent Process vs. Creator Process https://scorpiosoftware.net/2021/01/10/parent-process-vs-creator-process/
Pavel Yosifovich
Parent Process vs. Creator Process
Normally, a process created by another process in Windows establishes a parent-child relationship between them. This relationship can be viewed in tools such as Process Explorer. Here is an example…
Chrome 1-Day Hunting - Uncovering and Exploiting CVE-2020-15999 https://starlabs.sg/blog/2021/01/chrome-1-day-hunting-uncovering-and-exploiting-cve-2020-15999/
starlabs.sg
Chrome 1-Day Hunting - Uncovering and Exploiting CVE-2020-15999
Introduction This blog post details the exploitation process for the vulnerability CVE 2020-15999 in Google Chrome 86.0.4222.0 on Linux. While CVE 2020-15999 is a heap-based buffer overflow in the font-loading library Freetype rather than Chrome proper, its…
Evaluating Cookies to Hide Backdoors https://securityboulevard.com/2021/01/evaluating-cookies-to-hide-backdoors
A journey into IoT Forensics - Episode 5 - Analysis of the Apple HomePod and the Apple Home Kit Environment (aka thanks RN Team!) https://blog.digital-forensics.it/2021/01/a-journey-into-iot-forensics-episode-5.html
blog.digital-forensics.it
A journey into IoT Forensics - Episode 5 - Analysis of the Apple HomePod and the Apple Home Kit Environment (aka thanks RN Team!)
DFIR research
Research Paper: Understanding and Exploiting Zerologon https://sidb.in/2021/01/06/Zerologon-Paper.html
sidb.in
Research Paper: Understanding and Exploiting Zerologon - computer insecurities
Zerologon? What’s that? Zerologon is the cool new vulnerability in town with a CVSS score of 10. It has intrigued me ever since it came out. I have read Secu...
Mitigations and Best Practices for ExAllocatePoolZero Security Vulnerabilities https://www.osr.com/blog/2021/01/07/mitigations-exallocatepoolzero-security-vulnerability/
OSR
Mitigations and Best Practices for ExAllocatePoolZero Security Vulnerabilities
tl;dr The Windows V2004 WDK/EWDK had a serious security vulnerability. It has been updated to mitigate that vulnerability, and you should update all of your machines that have the WDK/EWDK installe…
Steam's login method is kinda interesting https://owlspace.xyz/cybersec/steam-login/
Course on Machine Learning and security » https://security.kiwi/docs/introduction/
Security Kiwi
Introduction to the Course
A Machine Learning Course Focused on Security
The malware analyst’s guide to aPLib decompression https://0xc0decafe.com/malware-analysts-guide-to-aplib-decompression/
0Xc0Decafe
The malware analyst’s guide to aPLib decompression
From l0w to h1gh level - full stack cyber!
A Trump Sex Video? No, It's a RAT! https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/updated-qnode-rat-downloader-distributed-as-trump-video-scandal/
Reversing TL-WR840N: Buying cheap routers to find vulnerabilities in them https://therealunicornsecurity.github.io/TPLink/
therealunicornsecurity.github.io
Reversing TL-WR840N
Buying cheap routers to find vulnerabilities in them
Local Privilege Escalation 0day in PsExec Gets a Micropatch https://blog.0patch.com/2021/01/local-privilege-escalation-0day-in.html
0Patch
Local Privilege Escalation 0day in PsExec Gets a Micropatch
by Mitja Kolsek, the 0patch Team [Update 3/25/2021: Seventy-seven days after we had issued a free micropatch for a local privilege esca...
Purgalicious VBA: Macro Obfuscation With VBA Purging https://www.fireeye.de/blog/threat-research/2020/11/purgalicious-vba-macro-obfuscation-with-vba-purging.html
FireEye
Purgalicious VBA: Macro Obfuscation With VBA Purging
We explain how VBA purging works, share some detection and hunting opportunities, and introduce a new tool: OfficePurge.
Details about CVE-2020-26262, bypass of Coturn's default access control protection https://www.rtcsec.com/post/2021/01/details-about-cve-2020-26262-bypass-of-coturns-default-access-control-protection/
CVE-2020-9971 Abusing XPC Service mechanism to elevate privilege in macOS/iOS https://xlab.tencent.com/en/2021/01/11/cve-2020-9971-abusing-xpc-service-to-elevate-privilege/
Tencent Xuanwu Lab
CVE-2020-9971 Abusing XPC Service mechanism to elevate privilege in macOS/iOS
Author: Zhipeng Huo(@R3dF09) of Tencent Security Xuanwu Lab 0x0 IntroductionIn this blog, I will detail an interesting logic vulnerability I found in launchd process when it is managing the XPC Servic