Some anti-debug and anti-memory dump for Android OS https://github.com/darvincisec/AntiDebugandMemoryDump
GitHub
GitHub - darvincisec/AntiDebugandMemoryDump: Anti-Debug and Anti-Memory Dump for Android
Anti-Debug and Anti-Memory Dump for Android. Contribute to darvincisec/AntiDebugandMemoryDump development by creating an account on GitHub.
CheckPoint cybersec report 2021, good details on critical vulnerabilities exploited in 2020 https://www.checkpoint.com/downloads/resources/cyber-security-report-2021.pdf
CVE-2020-8625: A Fifteen-Year-Old RCE Bug Returns in ISC BIND Server https://www.zerodayinitiative.com/blog/2021/2/24/cve-2020-8625-a-fifteen-year-old-rce-bug-returns-in-isc-bind-server
Zero Day Initiative
Zero Day Initiative — CVE-2020-8625: A Fifteen-Year-Old RCE Bug Returns in ISC BIND Server
The Patch The patched versions are BIND 9.16.12 and BIND 9.11.28. To fix BIND 9.16, ISC fixed the buffer allocation size at (1). In BIND 9.11, they applied the patch as well. Conclusion This bug shows how vulnerabilities can reside undetected for years…
Nice chart about the connections between cybercrime groups » https://www.zdnet.com/article/this-chart-shows-the-connections-between-cybercrime-groups/
ZDNET
This chart shows the connections between cybercrime groups
CrowdStrike puts together a list of connections and how cybercrime groups cooperate with each other.
1Password has none, KeePass has none... So why are there seven embedded trackers in the LastPass Android app? https://www.theregister.com/2021/02/25/lastpass_android_trackers_found/
The Register
1Password has none, KeePass has none... So why are there seven embedded trackers in the LastPass Android app?
Third-party code in security-critical apps is obviously suboptimal, but company says you can opt out
Network Graph Analysis for Suricata and Zeek using Brim and NetworkX https://medium.com/brim-securitys-knowledge-funnel/visualizing-network-cyber-attacks-with-suricata-and-zeek-using-brim-and-networkx-332dd265d4b6
Medium
Visualizing Network Cyber Attacks with Suricata and Zeek using Brim and NetworkX
Gaining meaningful Insights out of Security Data
VMware vCenter Server CVE-2021-21972 Remote Code Execution Vulnerability checker https://github.com/alt3kx/CVE-2021-21972
GitHub
GitHub - alt3kx/CVE-2021-21972
Contribute to alt3kx/CVE-2021-21972 development by creating an account on GitHub.
An Exploration of JSON Interoperability Vulnerabilities https://labs.bishopfox.com/tech-blog/an-exploration-of-json-interoperability-vulnerabilities
Bishop Fox
An Exploration & Remediation of JSON Interoperability Vulnerabilities
Learn more about how the same JSON document can be parsed with different values across microservices, leading to a variety of potential security risks.
Nice discussion on the need of changing CVSS, as it does not reflect appropriately the risks to a vulnerable system » "Time to Change the CVSS?" https://ieeexplore.ieee.org/abstract/document/9382369
ieeexplore.ieee.org
Time to Change the CVSS?
According to its creators, the Common Vulnerability Scoring System (CVSS) "provides a way to capture the principal characteristics of a vulnerability ... reflecting its severity ... to help organizations properly assess and prioritize their vulnerability…
POCs for Shellcode Injection via Callbacks https://github.com/ChaitanyaHaritash/Callback_Shellcode_Injection
GitHub
GitHub - ChaitanyaHaritash/Callback_Shellcode_Injection: POCs for Shellcode Injection via Callbacks
POCs for Shellcode Injection via Callbacks. Contribute to ChaitanyaHaritash/Callback_Shellcode_Injection development by creating an account on GitHub.
It's always important to refresh our knowledge » A brief introduction to PE format https://medium.com/ax1al/a-brief-introduction-to-pe-format-6052914cc8dd
Medium
A brief introduction to PE format
good idea » A Journey Combining Web Hacking and Binary Exploitation in Real World! https://blog.orange.tw/2021/02/a-journey-combining-web-and-binary-exploitation.html
Orange Tsai
A Journey Combining Web Hacking and Binary Exploitation in Real World!
Hi, this blog post is just a short post to address the technique part in one of my Red Team cases last year. I believe it’s worth sharing, so I reproduced this in my lab environment and made this topi
D-LINKGATE - A Preauth RCE to Root Chain on D-Link https://suid.ch/research/DAP-2020_Preauth_RCE_Chain.html
Pwn2Own Tokyo 2020: Defeating the TP-Link AC1750 https://www.synacktiv.com/en/publications/pwn2own-tokyo-2020-defeating-the-tp-link-ac1750.html
Synacktiv
Pwn2Own Tokyo 2020: Defeating the TP-Link AC1750
write-up » Hack The Box: Passage https://khaoticdev.net/hack-the-box-passage/
About the security content of iOS 14.4.1 and iPadOS 14.4.1 https://support.apple.com/en-us/HT212221
Apple Support
About the security content of iOS 14.4.1 and iPadOS 14.4.1
This document describes the security content of iOS 14.4.1 and iPadOS 14.4.1.
VU#782301: pppd vulnerable to buffer overflow due to a flaw in EAP packet processing https://www.kb.cert.org/vuls/id/782301/
www.kb.cert.org
CERT/CC Vulnerability Note VU#782301
pppd vulnerable to buffer overflow due to a flaw in EAP packet processing
Bazar Drops the Anchor https://thedfirreport.com/2021/03/08/bazar-drops-the-anchor/
The DFIR Report
Bazar Drops the Anchor
Intro The malware identified as Anchor first entered the scene in late 2018 and has been linked to the same group as Trickbot, due to similarities in code and usage of the two different malware families in the same intrusions. In 2020 the Bazar malware family…