TGViewer
Channel Public Channel
r0 Crew (Channel)

r0 Crew (Channel)

@r0_crew

Security Related Links:
- Reverse Engineering;
- Malware Research;
- Exploit Development;
- Pentest;
- etc;

Join to chat: @r0crew_bot 👈

Forum: https://forum.reverse4you.org
Twitter: https://twitter.com/R0_Crew
Subscribers
8.96K
Photos
35
Videos
1
Links
2K
Recent Posts 20 shown
Post #2122 12.2K

Forwarded from Malware Research / RedTeam / News

New blog on using CLR customizations to improve the OPSEC of your .NET execution harness. This includes a novel AMSI bypass that identified by author in 2023. By taking control of CLR assembly loads, we can load assemblies from memory with no AMSI scan.

https://securityintelligence.com/x-force/being-a-good-clr-host-modernizing-offensive-net-tradecraft/

Proof-of-concept for the AMSI bypass and an implementation of a CLR memory manager is on GitHub. We can implement custom memory routines and track all allocations made by the CLR.

https://github.com/passthehashbrowns/Being-A-Good-CLR-Host

#redteam #net #clr
Security Intelligence Being a good CLR host – Modernizing offensive .NET tradecraft Learn how red teams can modernize their use of .NET assemblies using CLR customizations.
  • ⚡ 10
  • ❤ 8
  • 👍 5
Post #2121 11.5K
Happy New Year! May every binary reveal its secrets, every challenge find its solution, and the Year of the Snake bring you stability, inspiration, and success!
  • 👍 21
  • ❤ 19
  • 🔥 11
  • 👏 1
Post #2119 12.8K
Attacking UNIX Systems via CUPS, Part I

CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177 have been assigned around these CUPS issues.

CVSS 9.9

This remote code execution issue can be exploited across the public Internet via a UDP packet to port 631 without needing any authentication, assuming the CUPS port is open through your router/firewall. LAN attacks are also possible via spoofing zeroconf / mDNS / DNS-SD advertisements.


https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/

A series of bugs in the CUPS printers discovery mechanism (cups-browsed) and in other components of the CUPS system, can be chained together to allow a remote attacker to automatically install a malicious printer (or hijack an existing one via mDNS) to execute arbitrary code on the target host as the lp user when a print job is sent to it.


https://gist.github.com/stong/c8847ef27910ae344a7b5408d9840ee1

#linux #rce #printer
  • ❤ 8
  • 🤣 8
  • 👍 5
  • 😐 4
  • 🔥 2
  • 🥰 2
  • 😁 2
  • 🤯 1
Post #2117 13K
Post #2114 7.04K
Post #2111 5.32K
SGN is a polymorphic binary encoder for offensive security purposes such as generating statically undetecable binary payloads. It uses a additive feedback loop to encode given binary instructions similar to LSFR. This project is the reimplementation of the original Shikata ga nai in golang with many improvements.

https://github.com/EgeBalci/sgn

#redteam #golang
GitHub GitHub - EgeBalci/sgn: SGN — polymorphic binary encoder SGN — polymorphic binary encoder. Contribute to EgeBalci/sgn development by creating an account on GitHub.
  • 🔥 3
  • 👍 2
  • 🤔 2
Post #2106 8.19K
Post #2105 8.66K
Keystone / Capstone Replacement

Nyxstone is a powerful assembly and disassembly library based on LLVM. It doesn’t require patches to the LLVM source tree and links against standard LLVM libraries available in most Linux distributions. Implemented as a C++ library, Nyxstone also offers Rust and Python bindings. It supports all official LLVM architectures and allows to configure architecture-specific target settings.

GitHub: https://github.com/emproof-com/nyxstone

Blog: https://www.emproof.com/introducing-nyxstone-an-llvm-based-disassembly-framework/
GitHub GitHub - emproof-com/nyxstone: Nyxstone: assembly / disassembly library based on LLVM, implemented in C++ with Rust and Python… Nyxstone: assembly / disassembly library based on LLVM, implemented in C++ with Rust and Python bindings, maintained by emproof.com - emproof-com/nyxstone
  • 👎 8
  • 👍 6
  • 🔥 6
Post #2104 8.1K
xVMP is an LLVM IR-based code virtualization tool, which fulfilled a scalable and virtualized instruction-hardened obfuscation. It supports multiple programming languages, and architectures. It is also compatible with existing LLVM IR-based obfuscation schemes (such as Obfuscator-LLVM).

xVMP is developer friendly. You only need to add annotations to the to-be-protected function in the source code, and xVMP can perform virtualization protection on the function during compilation.

https://github.com/GANGE666/xVMP

#virtualization #obfuscation #alekum
GitHub GitHub - GANGE666/xVMP Contribute to GANGE666/xVMP development by creating an account on GitHub.
  • 🔥 8
  • 👍 4
  • ❤ 1
Post #2103 9.86K
Mergen converts Assembly code into LLVM IR, a process known as lifting. It leverages the LLVM optimization pipeline for code optimization and constructs control flow through pseudo-emulation of instructions. Unlike typical emulation, Mergen can handle unknown values, easing the detection of opaque branches and theoretically enabling exploration of multiple code branches.

These capabilities facilitate the deobfuscation and devirtualization of obfuscated or virtualized functions. Currently in early development, Mergen already shows promise in devirtualizing older versions of VMProtect, with ambitions to support most x86_64 instructions.

https://github.com/NaC-L/Mergen

#llvm #lifting #vmprotect #tnaci
GitHub GitHub - NaC-L/Mergen: Deobfuscation via optimization with usage of LLVM IR and parsing assembly. Deobfuscation via optimization with usage of LLVM IR and parsing assembly. - NaC-L/Mergen
  • 👍 24
  • ❤ 9
  • 🥰 4
  • 👏 2
Older posts →

About this channel

How can I read @r0_crew without a Telegram account?
TGViewer shows the public web preview Telegram publishes for r0 Crew (Channel): recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does r0 Crew (Channel) have?
r0 Crew (Channel) (@r0_crew) has 8.96K subscribers on Telegram, refreshed roughly every 30 minutes.
Does r0 Crew (Channel) know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →