Reverse engineering Flutter for Android https://rloura.wordpress.com/2020/12/04/reversing-flutter-for-android-wip/
A Moment of Insanity
Reverse engineering Flutter for Android
Disclaimer: the contents of this article are the result of countless hours of personal investigation combined with exhaustive trial and error. I have never contacted Flutter or Dart development tea…
It seems that it really goes beyond a theoretical attack! » Spectre exploits in the "wild" https://dustri.org/b/spectre-exploits-in-the-wild.html
dustri.org
Spectre exploits in the "wild"
Personal blog of Julien (jvoisin) Voisin
Cve-2021-3156: sudo Heap Buffer Overflow Vulnerability POC https://chowdera.com/2021/01/20210128144518068v.html
MemLabs: An Introduction To Memory Forensics https://bananamafia.dev/post/mem/
Launching OSV - Better vulnerability triage for open source https://security.googleblog.com/2021/02/launching-osv-better-vulnerability.html
Google Online Security Blog
Launching OSV - Better vulnerability triage for open source
Posted by Oliver Chang and Kim Lewandowski, Google Security Team We are excited to launch OSV (Open Source Vulnerabilities), our first step...
nice post! » SROP Exploitation with radare2 https://bananamafia.dev/post/srop/
nice tool (and icon) :) » supercookoe: Browser fingerprinting via favicon! https://github.com/jonasstrehle/supercookie/
GitHub
GitHub - jonasstrehle/supercookie: ⚠️ Browser fingerprinting via favicon!
⚠️ Browser fingerprinting via favicon! Contribute to jonasstrehle/supercookie development by creating an account on GitHub.
justCTF[*]2020 - debug_me_if_you_can, REmap writeups https://lkmidas.github.io/posts/20210201-justctf2020-writeups/
My cool site
justCTF[*]2020 - debug_me_if_you_can, REmap writeups
Writeups for justCTF[*]2020 reversing challenges
New Threat: Matryosh Botnet Is Spreading https://blog.netlab.360.com/matryosh-botnet-is-spreading-en/
360 Netlab Blog - Network Security Research Lab at 360
New Threat: Matryosh Botnet Is Spreading
Background
On January 25, 2021, 360 netlab BotMon system labeled a suspicious ELF file as
Mirai, but the network traffic did not match Mirai's characteristics.
This anomaly caught our attention, and after analysis, we determined that it was a new botnet…
On January 25, 2021, 360 netlab BotMon system labeled a suspicious ELF file as
Mirai, but the network traffic did not match Mirai's characteristics.
This anomaly caught our attention, and after analysis, we determined that it was a new botnet…
Microsoft Remote Desktop Web Access Authentication Timing Attack https://raxis.com/blog/rd-web-access-vulnerability
Raxis
Metasploit Module: MS Remote Desktop Auth Timing Attack
Raxis team member Matt Dunn has uncovered a vulnerability in Microsoft’s Remote Desktop Web Access application (RD Web Access). Learn more in this blog article.
CANalyse: a vehicle network analysis and attack tool https://github.com/KartheekLade/CANalyse
GitHub
GitHub - KartheekLade/CANalyse: A vehicle network analysis and attack tool.
A vehicle network analysis and attack tool. Contribute to KartheekLade/CANalyse development by creating an account on GitHub.
Hunting for bugs in Telegram's animated stickers remote attack surface https://www.shielder.it/blog/2021/02/hunting-for-bugs-in-telegrams-animated-stickers-remote-attack-surface/
Shielder
Shielder - Hunting for bugs in Telegram's animated stickers remote attack surface
polict's 2020 journey in researching the lottie animation format, its integration in mobile apps and the vulnerabilities triggerable by a remote attacker against any Telegram user.
Auditd CVE 2021-3156 https://www.archcloudlabs.com/projects/auditd-cve-2021-3156/
Arch Cloud Labs
Auditd CVE 2021-3156
About The Project CVE-2021-3156 is a 10-year-old sudo vulnerability that allows for privilege escalation in Linux environments. If you’re responsible for a Linux server, this definitely caught your attention due to the severity. Some rough PoCs wound up Github…
Another variant to compromise frontend developers by malicious packages https://csal.medium.com/another-variant-to-compromise-frontend-developers-by-malicious-packages-b724dd4fef9
Medium
Another variant to compromise frontend developers by malicious packages
Some days ago I was watching 10 Things I Regret About Node.js and the introduction to Deno started with this slide about security.