Post #1202
74
Channel Public Channel
AL Alaid TechThread
@offensive_thread
Vulnerability discovery, threat intelligence, reverse engineering, AppSec
- Subscribers
- 1.14K
- Photos
- 7
- Videos
- 2
- Links
- 1.4K
Showing posts older than #1203 · Back to latest
Older Posts 20 shown
Post #1201
69
Technical Review: A Deep Analysis of the Dirty Pipe Vulnerability
https://blog.aquasec.com/deep-analysis-of-the-dirty-pipe-vulnerability
https://blog.aquasec.com/deep-analysis-of-the-dirty-pipe-vulnerability
Post #1200
72
Exploring Prompt Injection Attacks
https://research.nccgroup.com/2022/12/05/exploring-prompt-injection-attacks/
Nccgroup Cyber Security Research Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts. https://research.nccgroup.com/2022/12/05/exploring-prompt-injection-attacks/
- 👍 2
Post #1199
75
Passive OS detection based on SYN packets without Transmitting any Data
https://github.com/activecm/smudge
https://github.com/activecm/smudge
Post #1198
73
Post #1197
70
Post #1196
66
Post #1195
65
Hooking System Calls in Windows 11 22H2 like Avast Antivirus. Research, analysis and bypass
https://the-deniss.github.io/posts/2022/12/08/hooking-system-calls-in-windows-11-22h2-like-avast-antivirus.html
the-deniss.github.io Hooking System Calls in Windows 11 22H2 like Avast Antivirus. Research, analysis and bypass In this post I’ll show Avast self-defense bypass: how I discovered a new undocumented way to intercept all system calls without a hypervisor and PatchGuard triggered BSOD, and, finally, based on the knowledge gained, implemented a bypass https://the-deniss.github.io/posts/2022/12/08/hooking-system-calls-in-windows-11-22h2-like-avast-antivirus.html
Post #1194
62
Post #1193
83
Post #1192
77
Novel Pipeline Vulnerability Discovered; Rust Found Vulnerable
https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust
https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust
Post #1191
291
[OpenAI ChatGPT] ChatGPT for programming, infosec, fuzzing and day to day use - Part1
https://youtu.be/PKOtDJIwCjM
YouTube [OpenAI ChatGPT] Mind blowing ChatGPT examples for programming, infosec, fuzzing and day to day use 00:00 Introduction
00:42 Chat GPT overview
02:20 Writing a song for hackers
04:00 Getting a rental agreement and name change application from ChatGPT
05:55 Programming
08:00 Security related things fuzzing, identifying vulnerabilities, writing a fuzzer etc.… https://youtu.be/PKOtDJIwCjM
Post #1190
179
Post #1189
82
A Journey into Fuzzing WebAssembly Virtual Machine
https://youtu.be/fnprmz2IBm0
YouTube A Journey into Fuzzing WebAssembly Virtual Machine [BHUSA 2022] 📥 Slides: https://fuzzinglabs.com/wp-content/uploads/2022/08/BHUSA22_fuzzing_webassembly_vm_patrick_ventuzelo.pdf
Since the MVP release in 2017, WebAssembly evolve gradually, bringing new adepts and new VM implementations over time. It’s now possible to… https://youtu.be/fnprmz2IBm0
Post #1188
98
Making Cobalt Strike harder for threat actors to abuse
https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse
https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse
Post #1187
98
Hyperpom: An Apple Silicon Fuzzer for 64-bit ARM Binaries
https://blog.impalabs.com/2211_hyperpom.html
https://blog.impalabs.com/2211_hyperpom.html
Post #1185
87
Post #1184
95
RC4 Is Still Considered Harmful
https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html?m=1
Blogspot RC4 Is Still Considered Harmful By James Forshaw, Project Zero I've been spending a lot of time researching Windows authentication implementations, specifically Kerberos... https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html?m=1
Post #1183
85
Post #1182
81