Post #718
58
Channel Public Channel
AL Alaid TechThread
@offensive_thread
Vulnerability discovery, threat intelligence, reverse engineering, AppSec
- Subscribers
- 1.14K
- Photos
- 7
- Videos
- 2
- Links
- 1.4K
Showing posts older than #719 · Back to latest
Older Posts 20 shown
Post #717
73
Post #716
57
Разбор и IOC'и Lazarus (Северная Корея) за октябрь 2019
https://github.com/StrangerealIntel/CyberThreatIntel/blob/master/North%20Korea/APT/Lazarus/23-10-19/analysis.md
GitHub StrangerealIntel/CyberThreatIntel Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups - StrangerealIntel/CyberThreatIntel https://github.com/StrangerealIntel/CyberThreatIntel/blob/master/North%20Korea/APT/Lazarus/23-10-19/analysis.md
Post #715
82
Twitter IOC Hunter
http://tweettioc.com/
http://tweettioc.com/
Forwarded from r0 Crew (Channel)
Solving iOS UnCrackable 1 Crackme Without Using an iOS Device https://serializethoughts.com/2019/10/28/solving-mstg-crackme-angr #ios #CTF #dukeBarman
serializethoughts Solving iOS UnCrackable 1 Crackme Without Using an iOS Device TL;DR: iOS UnCrackable Level 1 crackme application can be solved without using an iOS device using Angr’s dynamic execution engine. Post #713
86
Let's Make Windows Defender Angry: Antivirus can be an oracle!
https://speakerdeck.com/icchy/lets-make-windows-defender-angry-antivirus-can-be-an-oracle
https://speakerdeck.com/icchy/lets-make-windows-defender-angry-antivirus-can-be-an-oracle
Post #712
69
Post #711
52
Proof of Concept for "Wordpress <=5.2.3: viewing unauthenticated posts"
https://0day.work/proof-of-concept-for-wordpress-5-2-3-viewing-unauthenticated-posts/
0day.work Proof of Concept for \ A couple of days Wordpress released 5.2.4 with a few security patches. Props to J.D. Grimes who found and disclosed a method of viewing unauthenticated posts. caught my attention, but I couldn’t find a public Proof of Concept, so I set out to reverse engineer… https://0day.work/proof-of-concept-for-wordpress-5-2-3-viewing-unauthenticated-posts/
Post #710
55
pythonfuzz
coverage guided fuzz testing for python https://fuzzit.dev
https://github.com/fuzzitdev/pythonfuzz
coverage guided fuzz testing for python https://fuzzit.dev
https://github.com/fuzzitdev/pythonfuzz
Forwarded from r0 Crew (Channel)
"Leveraging KVM as a debugging platform" https://drive.google.com/file/d/1nFoCM62BWKSz2TKhNkrOjVwD8gP51VGK/view #debugger #hacklu #dukeBarman
Forwarded from r0 Crew (Channel)
KTRW: The journey to build a debuggable iPhone (performing single-step kernel debugging with LLDB and IDA Pro over USB)
Article: https://googleprojectzero.blogspot.com/2019/10/ktrw-journey-to-build-debuggable-iphone.html
Source: https://github.com/googleprojectzero/ktrw #ios #debugger #dukeBarman
Article: https://googleprojectzero.blogspot.com/2019/10/ktrw-journey-to-build-debuggable-iphone.html
Source: https://github.com/googleprojectzero/ktrw #ios #debugger #dukeBarman
Forwarded from r0 Crew (Channel)
Modern Binary Analysis with ILs:
An interesting talk on binary analysis problems and important aspects of an IL.
https://binary.ninja/presentations/Modern%20Binary%20Analysis%20with%20ILs.pdf
#re #binary #trietptm
An interesting talk on binary analysis problems and important aspects of an IL.
https://binary.ninja/presentations/Modern%20Binary%20Analysis%20with%20ILs.pdf
#re #binary #trietptm
Post #706
42
GTFOBins is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions.
https://gtfobins.github.io
https://gtfobins.github.io
Post #705
63
Forwarded from r0 Crew (Channel)
Windows 10 (RS1-19H2+) UAC bypass using EditionUpgradeManager undocumented autoelevated COM interface. Works together with environment variables spoofing,
https://gist.github.com/hfiref0x/de9c83966623236f5ebf8d9ae2407611
#re #redteam #uac #darw1n
https://gist.github.com/hfiref0x/de9c83966623236f5ebf8d9ae2407611
#re #redteam #uac #darw1n
Forwarded from r0 Crew (Channel)
The Evolution of Advanced Threats: REsearchers Arms Race https://www.platformsecuritysummit.com/2019/speaker/matrosov/ #hardware #PSEC #videos #dukeBarman
Post #702
54
Utilizing Reverse Proxies to Inject Malicious Code & Extract Sensitive Information
https://versprite.com/blog/application-security/reverse-proxy-attack/
https://versprite.com/blog/application-security/reverse-proxy-attack/
Post #701
38
Abusing Windows 10 Narrator's 'Feedback-Hub' URI for Fileless Persistence
https://giuliocomi.blogspot.com/2019/10/abusing-windows-10-narrators-feedback.html
Blogspot Abusing Windows 10 Narrator's 'Feedback-Hub' URI for Fileless Persistence Penetration testing
Web, Wireless, Network Security https://giuliocomi.blogspot.com/2019/10/abusing-windows-10-narrators-feedback.html
Post #700
40
Avira Antivirus 2019 (4 Services) - DLL Preloading and Potential Abuses (CVE-2019-17449)
https://safebreach.com/Post/Avira-Antivirus-2019-4-Services-DLL-Preloading-and-Potential-Abuses-CVE-2019-17449
SafeBreach BAS Resources, White Papers & Data Sheets | SafeBreach One-stop destination for breach and attack simulation white papers, solution briefs, case studies, webinars, and more. https://safebreach.com/Post/Avira-Antivirus-2019-4-Services-DLL-Preloading-and-Potential-Abuses-CVE-2019-17449
Post #699
138