All That for a Coinminer? https://thedfirreport.com/2021/01/18/all-that-for-a-coinminer/
The DFIR Report
All That for a Coinminer? - The DFIR Report
A threat actor recently brute forced a local administrator password using RDP and then dumped credentials using Mimikatz. They not only dumped LogonPasswords but they also exported all Kerberos tickets. The threat actor used Advanced IP Scanner to scan the…
Introduction to Ghidra Scripting for Embedded ELFs and UPX https://www.archcloudlabs.com/projects/ghidra_scripting_01/
Arch Cloud Labs
Introduction to Ghidra Scripting for Embedded ELFs and UPX
About the Project The more Cryptominer malware I look at (or anything targeting Linux), the more trends I’ve identified that are common regardless of the underlying intent. Everyone loves to use UPX.
And why wouldn’t they? It’s a free Open Source packer that…
And why wouldn’t they? It’s a free Open Source packer that…
Training Transformers for Cyber Security Tasks: A Case Study on Malicious URL Prediction https://www.fireeye.com/blog/threat-research/2021/01/training-transformers-for-cyber-security-tasks-malicious-url-prediction.html
Trellix
Research | Trellix Stories
Trellix Research, get the latest cybersecurity trends, best practices, security vulnerabilities, and more from industry leaders.
RIFT: Analysing a Lazarus Shellcode Execution Method https://research.nccgroup.com/2021/01/23/rift-analysing-a-lazarus-shellcode-execution-method/
Windows Exploitation Tricks: Trapping Virtual Memory Access https://googleprojectzero.blogspot.com/2021/01/windows-exploitation-tricks-trapping.html
projectzero.google
Windows Exploitation Tricks: Trapping Virtual Memory Access
Posted by James Forshaw, Project ZeroThis blog is a continuation of my series of Windows exploita...
Flare-On 7 – Task 10 https://hshrzd.wordpress.com/2021/01/05/flare-on-7-task-10/
hasherezade's 1001 nights
Flare-On 7 – Task 10
This year’s FlareOn was very interesting. I managed to finish it with 87th place. In this small series I will describe my favorite tasks, and how I solved them. I hope to provide some educati…
Playing with Process Memory Integrity on Linux https://redcanary.com/blog/process-memory-integrity-linux/
Red Canary
Red Canary
Red Canary
Playing with Process Memory Integrity on Linux environments
Exploit Primitive Playground demostrates how adversaries leverage remote code execution vulnerabilities to execute in-memory payloads.
OWASP Top-10 2021. Statistics-based proposal https://lab.wallarm.com/owasp-top-10-2021-proposal-based-on-a-statistical-data/
Wallarm
OWASP Top-10 2021. Statistics-based proposal. 📄— Wallarm
The statistics-based calculations of OWASP Top Ten 2021 ☝️It's based on an analysis of 2 millions of security reports from 144 public sources
KEMTLS: Post-quantum TLS without signatures https://blog.cloudflare.com/kemtls-post-quantum-tls-without-signatures/
The Cloudflare Blog
KEMTLS: Post-quantum TLS without signatures
The TLS 1.3 protocol has been around for quite some time, but it will be broken once quantum computers arrive. What can we do? In this blog post, we will examine a technique for achieving full post-quantum security for TLS 1.3 in the face of quantum computers:…
ManiMed: Market Analysis https://insinuator.net/2021/01/manimed-part-1/
Insinuator.net
ManiMed: Market Analysis
Manipulating Medical Devices
The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases…
The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases…
DNS Hijacking – Taking Over Top-Level Domains and Subdomains https://blog.detectify.com/2021/01/19/dns-hijacking-taking-over-top-level-domains-and-subdomains/
Detectify Blog
DNS Hijacking – Taking Over Top-Level Domains and Subdomains - Detectify Blog
An ethical hacker recently claimed a country-code top-level domain. Learn how this DNS hijacking occured and more on subodmain takeovers
Windows 7 TCP/IP hijacking http://blog.pi3.com.pl/?p=850
Defeat Bitdefender total security using windows API unhooking to perform process injection https://shells.systems/defeat-bitdefender-total-security-using-windows-api-unhooking-to-perform-process-injection/
Shells.Systems
Defeat Bitdefender total security using windows API unhooking to perform process injection - Shells.Systems
Estimated Reading Time: 14 minutesBypassing endpoint protections such as AVs/EDRs is a phase that you need to take care of when you prepare for your red team operation, it could take some time to understand how these solutions are working before you try…
Remotely Exploitable 0day in Internet Explorer Gets a Free Micropatch https://blog.0patch.com/2021/02/remotely-exploitable-0day-in-internet.html
Nice presentation on Windows Process Hollowing (by @ochsenmeier) https://www.winitor.com/pdf/Windows-Process-Hollowing.pdf
Emulation of Kernel Mode Rootkits With Speakeasy https://www.fireeye.de/blog/threat-research/2021/01/emulation-of-kernel-mode-rootkits-with-speakeasy.html
FireEye
Emulation of Kernel Mode Rootkits With Speakeasy
In this blog post we discuss how Speakeasy can be effective at automatically identifying rootkit activity from the kernel mode binary.
Ghidra 101: Decoding Stack Strings https://www.tripwire.com/state-of-security/security-data-protection/ghidra-101-decoding-stack-strings/
Tripwire
Ghidra 101: Decoding Stack Strings
This stack string technique is a way for a programmer to obscure string data within a program by blending it as opaque operand instructions
Reverse Engineering iMessage: Leveraging the Hardware to Protect the Software https://www.nowsecure.com/blog/2021/01/27/reverse-engineering-imessage-leveraging-the-hardware-to-protect-the-software/
Nowsecure
Reverse Engineering iMessage to Help Improve Security | NowSecure
Our researcher reverse engineered Apple iMessage to explore extending it the secure messaging app to other systems. See how he fared.
nice vuln report >> Heap-based buffer overflow in Sudo (CVE-2021-3156) https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt
DNSpooq - dnsmasq cache poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685) https://github.com/knqyf263/dnspooq
GitHub
GitHub - knqyf263/dnspooq: DNSpooq - dnsmasq cache poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685)
DNSpooq - dnsmasq cache poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685) - knqyf263/dnspooq