Fuzzing Image Parsing in Windows, Part Two: Uninitialized Memory https://www.fireeye.com/blog/threat-research/2021/03/fuzzing-image-parsing-in-windows-uninitialized-memory.html
Trellix
Research | Trellix Stories
Trellix Research, get the latest cybersecurity trends, best practices, security vulnerabilities, and more from industry leaders.
Safe code & pitfalls: DLL side-loading, WinAPI and C++: Why your C++ (or not) app is probably vulnerable right now https://medium.com/@1ndahous3/safe-code-pitfalls-dll-side-loading-winapi-and-c-73baaf48bdf5
Medium
Safe code & pitfalls: DLL side-loading, WinAPI and C++
Why your C++ (or not) app is probably vulnerable right now
The Lone Sharepoint https://www.crummie5.club/the-lone-sharepoint/
Microsoft Windows “LoadUvsTable()” Heap-based Buffer Overflow Vulnerability https://www.emt.ae/microsoft-windows-loaduvstable-heap-based-buffer-overflow-vulnerability/
emt Distribution - Technology Distributor, Endpoint Security, SIEM, WAF, Firewall, Virtualization, SIEM for MSSP, Cloud Solutions, MSP, Patch Management, Vulnerability Intelligent, Web Vulnerability Scanner, BlackStratus, Academy, Kaspersky Lab, Avira, ESET, AlienVault, Secunia, Flexera, Parallels, Network Monitoring, Whtasup Gold, IPSWITCH
Microsoft Windows "LoadUvsTable()" Heap-based Buffer Overflow Vulnerability | emt Distribution - Technology Distributor, Endpoint…
By Hossein Lotfi, Senior Security Specialist Update December 14, 2016: During the analysis of the fix of Microsoft we confirmed a related error remains unpatched. Therefore an additional Secunia Advisory SA74000 [5] has been issued to account for that. On…
Interesting write-up! » How I Might Have Hacked Any Microsoft Account https://thezerohack.com/how-i-might-have-hacked-any-microsoft-account
The Zero Hack
How I Might Have Hacked Any Microsoft Account - The Zero Hack
This article is about how I found a vulnerability on Microsoft online services that might have allowed anyone to takeover any Microsoft account without consent permission. Microsoft security team patched the issue and rewarded me $50,000 as a part of their…
33c3 CTF Write-up: Shia https://secgroup.github.io/2017/01/03/33c3ctf-writeup-shia/
Very nice content here to learn about software exploitation » Offensive Software Exploitation (OSE) Course https://exploitation.ashemery.com/
exploitation-course
OFFENSIVE SECURITY & REVERSE ENGINEERING (OSRE) Course
Offensive Software Exploitation Course
Reverse Engineering a Flutter app by recompiling Flutter Engine
https://tinyhack.com/2021/03/07/reversing-a-flutter-app-by-recompiling-flutter-engine/
https://tinyhack.com/2021/03/07/reversing-a-flutter-app-by-recompiling-flutter-engine/
Tinyhack.com
Reverse Engineering a Flutter app by recompiling Flutter Engine
It is not easy to reverse engineer a release version of a flutter app because the tooling is not available and the flutter engine itself changes rapidly. As of now, if you are lucky, you can dump the classes and method names of a flutter app using darter…
Reverse-engineering Rosetta 2 part2: Analyzing other aspects of Rosetta 2 runtime and AOT shared cache files https://ffri.github.io/ProjectChampollion/part2/
Analyzing Attacks Against Microsoft Exchange Server With China Chopper Webshells https://unit42.paloaltonetworks.com/china-chopper-webshell/
Unit 42
Analyzing Attacks Against Microsoft Exchange Server With China Chopper Webshells
We analyze incidental artifacts of China Chopper webshell attacks against Microsoft Exchange Server, gaining insight into attackers' methodology.
Overview of dnsmasq Vulnerabilities: The Dangers of DNS Cache Poisoning https://unit42.paloaltonetworks.com/overview-of-dnsmasq-vulnerabilities-the-dangers-of-dns-cache-poisoning/
Unit 42
Overview of dnsmasq Vulnerabilities: The Dangers of DNS Cache Poisoning
Recently, security researchers discovered new issues that continue to make dnsmasq vulnerable. These vulnerabilities can lead to DNS cache poisoning, denial of service (DoS) and possibly remote code execution (RCE).
How to prevent SQL Injection vulnerabilities: How Prepared Statements Work https://medium.com/@jaredablon_31568/how-to-prevent-sql-injection-vulnerabilities-how-prepared-statements-work-f492c369614f
Medium
How to prevent SQL Injection vulnerabilities: How Prepared Statements Work
Read the full post here: https://blog.hackedu.com/how-to-prevent-sql-injection-vulnerabilities-how-prepared-statements-w
Database Hardening Best Practices https://security.berkeley.edu/education-awareness/best-practices-how-tos/system-application-security/database-hardening-best
SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group https://www.secureworks.com/blog/supernova-web-shell-deployment-linked-to-spiral-threat-group
Secureworks
SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group
Similarities between the SUPERNOVA activity and a previous compromise of the network suggest that SPIRAL was responsible for both intrusions and reveal information about the threat group.
Clast82 – A new Dropper on Google Play Dropping the AlienBot Banker and MRAT https://research.checkpoint.com/2021/clast82-a-new-dropper-on-google-play-dropping-the-alienbot-banker-and-mrat/
Check Point Research
Clast82 – A new Dropper on Google Play Dropping the AlienBot Banker and MRAT - Check Point Research
Research by: Aviran Hazum, Bohdan Melnykov, Israel Wernik Check Point Research (CPR) recently discovered a new Dropper spreading via the official Google Play store, which downloads and installs the AlienBot Banker and MRAT. This Dropper, dubbed Clast82, utilizes…
nice post » One day short of a full chain: Part 1 - Android Kernel arbitrary code execution https://securitylab.github.com/research/one_day_short_of_a_fullchain_android
Email forensics Analysis https://linuxhint.com/email_forensics_analysis/
Linuxhint
Email forensics Analysis
Email forensic Analysis is used to find the actual sender and receiver of an email, date and time it is received and the info about intermediate devices involved in the delivery of the message. The email has become a primary source of communication for organizations…
How to Perform Symbolic Execution of Mobile Apps with R2Frida & ESILSolve https://www.nowsecure.com/blog/2021/03/10/how-to-perform-symbolic-execution-of-mobile-apps-with-r2frida-esilsolve/
Nowsecure
Perform Symbolic Execution of Mobile Apps with R2Frida & ESILSolve
Learn about the many benefits of ESILSolve and how to harness symbolic execution in the the NowSecure tutorial.
Analysis of an active Telegram malvertising campaign https://suid.ch/research/Telegram_Malware_Analysis.html