Nice write-up of Not Beginners Stack (Zer0pts CTF 2021) » https://litios.github.io/2021/03/11/not-beginners-stack.html
Litios Blog
Not Beginners Stack
WNKKKNW WXxc'...':d0NW W0d:..'cxxdl,..'cx0N NOo;..,lOXW WKkl,..,cxKW WXkl'..;o0N NKxc,..,lkXW WKxc'..:xKW N0xc'..;okXW N0d;..'lkXW N0dc'..:oOXW NOo,..,oON WNOd:'.':xX Kl'..;d0N WXx' .dW Wo 'xX WKxc'..c0 Ko;..,cxKN W0d:..'ckXW WKkl,..,lxKW NOo,..,lON W0l.…
Implementing Direct Syscalls Using Hell’s Gate https://teamhydra.blog/2020/09/18/implementing-direct-syscalls-using-hells-gate/
Team Hydra
Implementing Direct Syscalls Using Hell’s Gate
I first encountered the concept of using direct system calls to bypass user-land API hooking a little more than a year ago when I read a blog post by Cornelis De Pla (@Cn33liz). It is an exce…
Shadrak: a script to generate decompression bomb in various formats https://gitlab.com/brn1337/shadrak
GitLab
prisma / Shadrak · GitLab
Shadrak is a script to generate decompression bomb in various formats.
Old, but gold » Writing a basic Windows debugger https://www.codeproject.com/Articles/43682/Writing-a-basic-Windows-debugger
Codeproject
For those who code
CVE-2020-24581 D-Link DSL-2888A Remote Command Execution https://reconshell.com/cve-2020-24581-d-link-dsl-2888a-remote-command-execution/
VM Detection Tricks, Part 2: Driver Thread Fingerprinting https://labs.nettitude.com/blog/vm-detection-tricks-part-2-driver-thread-fingerprinting/
LRQA Nettitude Labs
VM Detection Tricks, Part 2: Driver Thread Fingerprinting
This year we're documenting a series of new and as-yet undocumented VM detection tricks. These detection tricks will be focused on 64-bit Windows 10 or Windows Server 2019 guests, targeting a variety of VM platforms.
In the first article we investigated…
In the first article we investigated…
1day exploit for chrome CVE-2020-16040 (includes a typer hardening bypass, works for chrome version <= 87.0.4280.88) https://github.com/r4j0x00/exploits/tree/master/CVE-2020-16040
GitHub
exploits/CVE-2020-16040 at master · r4j0x00/exploits
Contribute to r4j0x00/exploits development by creating an account on GitHub.
TryHackMe: DNS Manipulation Walkthrough https://infosecwriteups.com/tryhackme-dns-manipulation-walkthrough-5944bf60f10f
Playing in the (Windows) Sandbox https://research.checkpoint.com/2021/playing-in-the-windows-sandbox/
Check Point Research
Playing in the (Windows) Sandbox - Check Point Research
Research By: Alex Ilgayev Introduction Two years ago, Microsoft released a new feature as a part of the Insiders build 18305 – Windows Sandbox. This sandbox has some useful specifications: Integrated part of Windows 10 (Pro/Enterprise). Runs on top of Hyper…
Exploiting remote DoS vulnerability in my not-so-smart TV https://vavkamil.cz/2021/03/11/exploiting-remote-dos-vulnerability-in-my-not-so-smart-tv/
Kamil Vavra @vavkamil
Exploiting remote DoS vulnerability in my not-so-smart TV
tl;dr: I found a remotely exploitable DoS vulnerability in my “smart” TV in less than two hours after unboxing. I have released full details, including a 0-day PoC exploit.
New steganography attack targets Azerbaijan https://blog.malwarebytes.com/threat-analysis/2021/03/new-steganography-attack-targets-azerbaijan/
Malwarebytes Labs
New steganography attack targets Azerbaijan
A lure document targeting Azerbaijan uses steganography to conceal a remote administration Trojan.
iOS pentesting guide from a n00bs perspective https://payatu.com/blog/abhilashnigam/ios-pentesing-guide-from-a-n00bs-perspective.1
Attack Surface Analysis - Part 2 - Custom Protocol Handlers https://parsiya.net/blog/2021-03-17-attack-surface-analysis-part-2-custom-protocol-handlers/
parsiya.net
Attack Surface Analysis - Part 2 - Custom Protocol Handlers
Custom protocol handlers are an obscure attack surface. They allow us to convert
local attacks into remote ones and are an alternative way to
jump the browser sandbox without 0days).
Similar to the…
local attacks into remote ones and are an alternative way to
jump the browser sandbox without 0days).
Similar to the…
New macOS malware XcodeSpy Targets Xcode Developers with EggShell Backdoor https://labs.sentinelone.com/new-macos-malware-xcodespy-targets-xcode-developers-with-eggshell-backdoor/
SentinelOne
New macOS Malware XcodeSpy Targets Xcode Developers with EggShell Backdoor - SentinelLabs
Targeting software developers is one route to a successful supply chain attack. Now threat actors are going after Apple developers through the Xcode IDE.
How we found and fixed a rare race condition in our session handling https://github.blog/2021-03-18-how-we-found-and-fixed-a-rare-race-condition-in-our-session-handling/
The GitHub Blog
How we found and fixed a rare race condition in our session handling
On March 8, out of an abundance of caution, we logged all users out of GitHub.com. In this post we share technical details of the vulnerability and steps we're taking to ensure it doesn't happen again.
Lsass Memory Dumps are Stealthier than Ever Before – Part 2 https://www.deepinstinct.com/2021/02/16/lsass-memory-dumps-are-stealthier-than-ever-before-part-2/
Deep Instinct
LSASS Memory Dumps: New Method for Dumping LSASS [Part 2] | Deep Instinct
In this article, we show a new way to dump LSASS memory without dropping any new tool on the endpoint that is highly evasive.