Nice analysis from 360 >> Necro is going to version 3 and using PyInstaller and DGA https://blog.netlab.360.com/necro/
360 Netlab Blog - Network Security Research Lab at 360
Necro is going to version 3 and using PyInstaller and DGA
Overview.
Necro is a classic family of botnet written in Python that was first discovered in 2015, at the beginning, it targeted Windows systems and often tagged by security vendors as Python.IRCBot and called N3Cr0m0rPh (Necromorph) by the author himself.…
Necro is a classic family of botnet written in Python that was first discovered in 2015, at the beginning, it targeted Windows systems and often tagged by security vendors as Python.IRCBot and called N3Cr0m0rPh (Necromorph) by the author himself.…
Déjà vu-lnerability: A Year in Review of 0-days Exploited In-The-Wild in 2020 https://googleprojectzero.blogspot.com/2021/02/deja-vu-lnerability.html
Blogspot
Déjà vu-lnerability
A Year in Review of 0-days Exploited In-The-Wild in 2020 Posted by Maddie Stone, Project Zero 2020 was a year full of 0-day exploits. Many o...
Critical RCE and SLP Protocol Vulnerabilities in VMWare https://securityboulevard.com/2021/02/critical-rce-and-slp-protocol-vulnerabilities-in-vmware
Security Boulevard
Critical RCE and SLP Protocol Vulnerabilities in VMWare
The post Critical RCE and SLP Protocol Vulnerabilities in VMWare appeared first on Fidelis Cybersecurity.
Major Vulnerabilities discovered and patched in Realtek RTL8195A Wi-Fi Module https://www.vdoo.com/blog/realtek-rtl8195a-vulnerabilities-discovered
CVE-2020-XXXXX - Getting root on webOS https://blog.recurity-labs.com/2021-02-03/webOS_Pt1.html
hadowMove: Lateral Movement by Duplicating Existing Sockets https://www.ired.team/offensive-security/lateral-movement/shadowmove-lateral-movement-by-stealing-duplicating-existing-connected-sockets
www.ired.team
ShadowMove: Lateral Movement by Duplicating Existing Sockets | Red Team Notes
PDF is Broken: a justCTF Challenge https://blog.trailofbits.com/2021/02/02/pdf-is-broken-a-justctf-challenge/
The Trail of Bits Blog
PDF is Broken: a justCTF Challenge
Trail of Bits sponsored the recent justCTF competition, and our engineers helped craft several of the challenges, including D0cker, Go-fs, Pinata, Oracles, and 25519. In this post we’re going to cover another of our challenges, titled PDF is broken, and so…
Ransomware gangs are abusing VMWare ESXi exploits to encrypt virtual hard disks https://www.zdnet.com/article/ransomware-gangs-are-abusing-vmware-esxi-exploits-to-encrypt-virtual-hard-disks/
ZDNET
Ransomware gangs are abusing VMWare ESXi exploits to encrypt virtual hard disks
Two VMWare ESXi vulnerabilities, CVE-2019-5544 and CVE-2020-3992, reported as abused in the wild.
Very interesting introduction to Z3 » Software Verification and Analysis Using Z3 https://research.nccgroup.com/2021/01/29/software-verification-and-analysis-using-z3/
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
Talk on Dynamic Analysis of Conti Ransom (DEFCON 201 NJ) https://0xthreatintel.medium.com/my-talk-at-defcon-201-nj-76c18c548826
udp2raw-tunnel: a Tunnel which Turns UDP Traffic into Encrypted UDP/FakeTCP/ICMP Traffic by using Raw Socket,helps you Bypass UDP FireWalls(or Unstable UDP Environment) https://github.com/wangyu-/udp2raw-tunnel
GitHub
GitHub - wangyu-/udp2raw: A Tunnel which Turns UDP Traffic into Encrypted UDP/FakeTCP/ICMP Traffic by using Raw Socket,helps you…
A Tunnel which Turns UDP Traffic into Encrypted UDP/FakeTCP/ICMP Traffic by using Raw Socket,helps you Bypass UDP FireWalls(or Unstable UDP Environment) - wangyu-/udp2raw
The Kerberos Credential Thievery Compendium (GNU/Linux) https://adepts.of0x.cc/kerberos-thievery-linux/
The Kerberos Credential Thievery Compendium (GNU/Linux) |
The Kerberos Credential Thievery Compendium (GNU/Linux) | AdeptsOf0xCC
Collection of well-known techniques to steal kerberos credentials in GNU/Linux environments
Reverse engineering Flutter for Android https://rloura.wordpress.com/2020/12/04/reversing-flutter-for-android-wip/
A Moment of Insanity
Reverse engineering Flutter for Android
Disclaimer: the contents of this article are the result of countless hours of personal investigation combined with exhaustive trial and error. I have never contacted Flutter or Dart development tea…
It seems that it really goes beyond a theoretical attack! » Spectre exploits in the "wild" https://dustri.org/b/spectre-exploits-in-the-wild.html
dustri.org
Spectre exploits in the "wild"
Personal blog of Julien (jvoisin) Voisin
Cve-2021-3156: sudo Heap Buffer Overflow Vulnerability POC https://chowdera.com/2021/01/20210128144518068v.html