ImageTragick
Jackin tor
INFILTRATE 2016: Pwning Adobe Reader - Sebastian Apelt on Vimeo
COM Scriptlet Registry Only Backing | Bandit.reg == Admin Rights | Bandit2.
A day in the life of a pentester: How I owned your domain in 4 hours : HowT
Arrived onsite, sat down, plugged in. Started **Responder** (https://github.com/SpiderLabs/Responder), start **nbtscan**ning /24 *...
Project Zero: Return to libstagefright: exploiting libutils on Android
Posted by Mark Brand, Invalidator of Unic�o�d�e I’ve been investigating different fuzzing approaches on some Android devices recently, ...
Detecting analysts before installing the malware – Broken Browser
With the help of a beautiful piece of code, malware authors can detect installed applications straig
A Tale Of Another SOP Bypass In Android Browser < 4.4
Learn how to Ethically hack, Learn what it takes for a hacker to hack!
XSS to RCE in Atlassian Hipchat | Matt Austin
Object Oriented Exploitation: New techniques in Windows mitigation by…
New techniques to bypass CFG and 32-bit ASLR. Video at: https://www.youtube.com/watch?v=mZU8o057n80
DEFCON-23-Hariri-Spelman-Gorenc-Abusing-Adobe-Readers-JavaScript-APIs.pdf
PATCH ANALYSIS OF MS16-063 (JSCRIPT9.DLL) | THEORI
Last week, Microsoft released the MS16-063 security bulletin for their monthly Patch Tuesday (June 2016) security updates. It addressed vulnerabilities that affected Internet Explorer. Among other things, the patch fixes a memory corruption vulnerability in jscript9.dll related to TypedArray and DataView.
Practical Reverse Engineering Part 2 - Scouting the Firmware · Hack The Wor
RPO Gadgets
If you are here because you thought the title meant Return Oriented Programming (ROP), then sorry for the clickbait. I wanted to introduce a techninque to help exploit Relative Path Overwrite (RPO) when XSS is not an option by chaining "gadgets". This will be the first part of
us-16-Weston-Windows-10-Mitigation-Improvements.pdf
eu-16-Shen-Rooting-Every-Android-From-Extension-To-Exploitation
Flash local-with-filesystem Bypass in navigateToURL - Pastebin.com
How To Avoid Implement An Exploit Friendly JIT
Slides for BlueHat v16, Slightly modified version.
The Art of Reverse Engineering Flash Exploits - YouTube
Exploiting Internet Explorer’s MS15-106, Part I: VBScript Filter Type Confu
In October 13, 2015 Microsoft published security bulletin MS15-106, addressing multiple vulnerabilities in Internet Explorer. Zero Day Initiative published advisory ZDI-15-521 for one of those vulnerabilities affecting IE: Microsoft Windows VBScript Filter Function Remote Code Execution Vulnerability (CVE-2015-6055), so I decided to take a shot at it. Quoting ZDI's advisory:
http://arxiv.org/pdf/1507.06955v1.pdf
On (OAuth) token hijacks for fun and profit part #1 (Google/Microsoft integration)
Here we go again.... I have already blogged about (OAuth) token hijacks [1] [2] , but hey, things happens and re-happens :) In the past...
The avast! Series
I spent some time quite a while ago looking into avast! and, after about a year, I am going to post about the issues that were found, and fi...
Windows 10’s New Browser Microsoft Edge: Improved, But Also New Risks
Last week we discussed how Microsoft Edge, the new browser in Windows 10, represented a significant increase in the security over Internet Explorer. However, there are also new potential threat vectors that aren’t present in older versions. Integrated plug-ins Microsoft Edge has now integrated two widely used plug-ins into the browser itself: Adobe Flash and a PDF reader....
Server-Side Template Injection
Template engines are widely used by web applications to present dynamic data via web pages and emails. Unsafely embedding user input in templates enables Server-Side Template Injection, a frequently c
Remote Shell over the Internet, hacking Internet Explorer over SMB
This demo shows Internet Explorer hacked over SMB, leading to complete compromise (remote Meterpreter Shell). As Demonstrated by Jonathan Brossard and Hormaz...
Exploit
Sudo 1.8.14 (RHEL 5/6/7 / Ubuntu) - 'Sudoedit' Unauthorized Privilege Escalation. CVE-2015-5602. Local exploit for Linux platform
Finding Vulnerabilities in Core WordPress: A Bug Hunter’s Trilogy, Part I
Check Point researchers outline a vulnerability discovered in core WordPress
SMB : Sharing more than just your files
V v8c4b
