Source Byte
I made a useful MCP wrapper to help agents analyse multiple binaries in IDA in parallel, and easily switching them, check this out, if you will like it, it would be cool to get feedback and maybe a post in your channel 🙏 https://github.com/whoisqwerz/pocket_disasm
This media is not supported in your browser
VIEW IN TELEGRAM
👎5🥰5💅1💘1
👍5
Source Byte
https://zenodo.org/records/21348017
if you know assembly and have RE skills , then everything is open-source to you🥹
💅8👍2
Reverse Engineering a Ledger Nano X Hardware Implant
https://grandideastudio.com/portfolio/security/ledger-hardware-implant/
https://grandideastudio.com/portfolio/security/ledger-hardware-implant/
😈4🥰1
Alert
A new exploit has been discovered in Telegram that allows Japanese accounts to purchase 10,000 Stars for just $1.50, even though the normal price is $150.
Shortly after the exploit was discovered, many Chinese users began mass-buying expensive gifts with Stars obtained through the bug.
However, most of the gifts and Stars are expected to be refunded once Telegram fixes the exploit. Many accounts that abused the exploit have already been deactivated, and using it could result in your account being frozen or permanently banned.
This media is not supported in your browser
VIEW IN TELEGRAM
👾8
ODR: Internals of Microsoft's New Native MCP Registration
https://www.originhq.com/research/msft-odr-mcp
https://www.originhq.com/research/msft-odr-mcp
Origin Technology
ODR: Internals of Microsoft's New Native MCP Registration | Origin Technology
Reverse engineering Odr.exe reveals how Windows On-Device Registry runs MCP, via undocumented COM interfaces, a SQL-backed consent database, and ETW audit.
😈2
FirmBurn:How Firmware Zero‑Day & SCSI PassThru Burned Iran Banks
FirmBurn: A technical deep dive into how a firmware zero‑day vulnerability dubbed FirmBurn, and SCSI PassThru were combined to wipe Iran’s banks. Analysis of an APT‑level wiper attack targeting Dell EMC storage systems.
https://aleeamini.com/firmburn-firmware-zero-day-scsi-passthru-burned-iran-banks-hack/
FirmBurn: A technical deep dive into how a firmware zero‑day vulnerability dubbed FirmBurn, and SCSI PassThru were combined to wipe Iran’s banks. Analysis of an APT‑level wiper attack targeting Dell EMC storage systems.
https://aleeamini.com/firmburn-firmware-zero-day-scsi-passthru-burned-iran-banks-hack/
💘7👍1💔1😈1
Source Byte
FirmBurn:How Firmware Zero‑Day & SCSI PassThru Burned Iran Banks FirmBurn: A technical deep dive into how a firmware zero‑day vulnerability dubbed FirmBurn, and SCSI PassThru were combined to wipe Iran’s banks. Analysis of an APT‑level wiper attack targeting…
This media is not supported in your browser
VIEW IN TELEGRAM
👾4😈1
Ai000 Cybernetics QLab
بعضیها فکر میکنند همین که روی کلاینت Sysmon نصب شد، دیگر از این به بعد حتی اگر کاربر عطسه هم بکند، لاگش میاد،
فارغ ازینکه sysmon قابلیت جمع اوری چه تلمتری هایی رو داره باید گفت سایتی که استفاده شده متاسفانه فاقد هرگونه دیتیل فنی هست و بیشتر جنبه تبلیغاتی داره
به طور مثال پادویش در رتبه بهتری از trend micro و bitdefender و carbon black قرار داره 😕
https://www.edr-telemetry.com/scores
به طور مثال پادویش در رتبه بهتری از trend micro و bitdefender و carbon black قرار داره 😕
https://www.edr-telemetry.com/scores
👍11👎6
Forwarded from Sec Note
گروهی تخصصی برای متخصصین آفنسیو و ردتیم با زبان فارسی
https://t.me/+drFBtbbrVDo5NjA0
اینجا قراره ریپورتهایی که منتشر میشه رو بررسی کنیم، تکنیکهای جدید رو استخراج کنیم و دربارهی مشکلات فنی و چالشهایی که سر راه اجراست بحث کنیم.
https://t.me/+drFBtbbrVDo5NjA0
Telegram
Seclog
Offensive brainstorming
👎7👍2
Forwarded from Sec Note
🔓 Dumping NTLM Hashes from Windows Memory via forensics tools
What can an attacker recover from a Windows memory image after gaining access to an endpoint?
#RedTeam #OffensiveSecurity
What can an attacker recover from a Windows memory image after gaining access to an endpoint?
In my new blog, I explored:
WinPmem → Volatility 3 → SYSTEM/SAM → NTLM
#RedTeam #OffensiveSecurity
💘4👍1
XSS_Private_Messages.rar
2 MB
credits : Dancho Danchev
🥰7