justCTF[*]2020 - debug_me_if_you_can, REmap writeups https://lkmidas.github.io/posts/20210201-justctf2020-writeups/
My cool site
justCTF[*]2020 - debug_me_if_you_can, REmap writeups
Writeups for justCTF[*]2020 reversing challenges
New Threat: Matryosh Botnet Is Spreading https://blog.netlab.360.com/matryosh-botnet-is-spreading-en/
360 Netlab Blog - Network Security Research Lab at 360
New Threat: Matryosh Botnet Is Spreading
Background
On January 25, 2021, 360 netlab BotMon system labeled a suspicious ELF file as
Mirai, but the network traffic did not match Mirai's characteristics.
This anomaly caught our attention, and after analysis, we determined that it was a new botnet…
On January 25, 2021, 360 netlab BotMon system labeled a suspicious ELF file as
Mirai, but the network traffic did not match Mirai's characteristics.
This anomaly caught our attention, and after analysis, we determined that it was a new botnet…
Microsoft Remote Desktop Web Access Authentication Timing Attack https://raxis.com/blog/rd-web-access-vulnerability
Raxis
Metasploit Module: MS Remote Desktop Auth Timing Attack
Raxis team member Matt Dunn has uncovered a vulnerability in Microsoft’s Remote Desktop Web Access application (RD Web Access). Learn more in this blog article.
CANalyse: a vehicle network analysis and attack tool https://github.com/KartheekLade/CANalyse
GitHub
GitHub - KartheekLade/CANalyse: A vehicle network analysis and attack tool.
A vehicle network analysis and attack tool. Contribute to KartheekLade/CANalyse development by creating an account on GitHub.
Hunting for bugs in Telegram's animated stickers remote attack surface https://www.shielder.it/blog/2021/02/hunting-for-bugs-in-telegrams-animated-stickers-remote-attack-surface/
Shielder
Shielder - Hunting for bugs in Telegram's animated stickers remote attack surface
polict's 2020 journey in researching the lottie animation format, its integration in mobile apps and the vulnerabilities triggerable by a remote attacker against any Telegram user.
Auditd CVE 2021-3156 https://www.archcloudlabs.com/projects/auditd-cve-2021-3156/
Arch Cloud Labs
Auditd CVE 2021-3156
About The Project CVE-2021-3156 is a 10-year-old sudo vulnerability that allows for privilege escalation in Linux environments. If you’re responsible for a Linux server, this definitely caught your attention due to the severity. Some rough PoCs wound up Github…
Another variant to compromise frontend developers by malicious packages https://csal.medium.com/another-variant-to-compromise-frontend-developers-by-malicious-packages-b724dd4fef9
Medium
Another variant to compromise frontend developers by malicious packages
Some days ago I was watching 10 Things I Regret About Node.js and the introduction to Deno started with this slide about security.
Nice reverse engineering research on Apple GPU! » Apple G13 GPU architecture docs and tools https://github.com/dougallj/applegpu
GitHub
GitHub - dougallj/applegpu: Apple G13 GPU architecture docs and tools
Apple G13 GPU architecture docs and tools. Contribute to dougallj/applegpu development by creating an account on GitHub.
SerenityOS - Writing a full chain exploit https://devcraft.io/2021/02/11/serenityos-writing-a-full-chain-exploit.html
devcraft.io
SerenityOS - Writing a full chain exploit
I recently came across SerenityOS when it was featured in hxp CTF and then on LiveOverflow’s YouTube channel. SerenityOS is an open source operating system written from scratch by Andreas Kling and now has a strong and active community behind it. If you’d…
Stealthy Process Communication Between Threads on Windows 10 https://blog.syscall.party/post/windows-10-stealthy-threads/
blog.syscall.party
Stealthy Process Communication Between Threads on Windows 10
A small blog of my findings and research.
Swarm of Palo Alto PAN-OS vulnerabilities https://swarm.ptsecurity.com/swarm-of-palo-alto-pan-os-vulnerabilities/
A Practical Approach To Attacking IoT Embedded Designs (I) https://labs.ioactive.com/2021/02/a-practical-approach-to-attacking-iot.html
Ioactive
A Practical Approach To Attacking IoT Embedded Designs (I)
by Ruben Santamarta The booming IoT ecosystem has meant massive growth in the embedded systems market due to the high demand for connect...
Discovering an Undisclosed Stack Overflow Vulnerability in Microsoft SQL Server (CVE-2019-1068) https://0xsaiyajin.github.io/vulnerability-research/2021/02/06/discovering-an-undisclosed-stack-overflow-vulnerability-in-mssql-server-cve-2019-1068.html
Nice analysis » Analysis and exploitation of the iOS kernel vulnerability CVE-2021-1782 https://www.synacktiv.com/publications/analysis-and-exploitation-of-the-ios-kernel-vulnerability-cve-2021-1782
Synacktiv
Analysis and exploitation of the iOS kernel vulnerability CVE-2021-1782
Two weeks ago, CVE-2021-1782 was fixed by Apple.
Detecting Manual Syscalls from User Mode https://winternl.com/detecting-manual-syscalls-from-user-mode/
winternl
Detecting Manual Syscalls from User Mode
By now direct system calls are ubiquitous in offensive tooling. Manual system calls remain effective for evading userland based EDRs. From within userland, there has been little answer to this…
DNS exfiltration of data: step-by-step simple guide https://hinty.io/devforth/dns-exfiltration-of-data-step-by-step-simple-guide/
hinty.io
DNS exfiltration of data: step-by-step simple guide
Complete Guide to Windows File System Auditing https://www.varonis.com/blog/windows-file-system-auditing/
Varonis
Complete Guide to Windows File System Auditing - Varonis
Windows file auditing is key in a cybersecurity plan. Learn about file system auditing and why you'll need an alternate method to get usable file audit data