Found 1481 bookmarks
Newest
How to build a high-performance network fuzzer with LibAFL and libdesock
How to build a high-performance network fuzzer with LibAFL and libdesock
We explain how we built a fuzzer for network applications that we tried to make as efficient and as effective as possible. We utilized custom mutators and input passing over shared memory and found that it gave us a huge speed and coverage boost compared to other network fuzzers.
·lolcads.github.io·
How to build a high-performance network fuzzer with LibAFL and libdesock
Make Self-XSS Great Again
Make Self-XSS Great Again
Disclaimer: This article is intended for security professionals conducting authorized testing within the scope of a contract. The author is not responsible for any damage caused by the application of the provided information. The distribution of malicious programs, disruption of system operation, and violation of the confidentiality of correspondence are pursued by law. Introduction Many security researchers are familiar with the frustrating experience of discovering an XSS vulnerability that requires complex actions within an account, effectively making it only reproducible on the attacker’s account and thus losing its practical value.
·blog.slonser.info·
Make Self-XSS Great Again
A Look in the Mirror - The Reflective Kerberos Relay Attack
A Look in the Mirror - The Reflective Kerberos Relay Attack
It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While researching relay attacks, the bane of Active …
·blog.redteam-pentesting.de·
A Look in the Mirror - The Reflective Kerberos Relay Attack
Walkthrough of shellcode reflective DLL injection (sRDI)
Walkthrough of shellcode reflective DLL injection (sRDI)
Shellcode reflective DLL injection (sRDI) still stands as a relatively stealthy technique in the Windows malware scene despite its age. What differentiates it from simpler DLL injection methods is that it doesn’t leave apparent traces to the targeted system’s disk, which is why it has a chance to bypass basic defensive solutions relying on e.g. signature detection. Steps Execution is passed to the loader from a separate injector, that injects the shellcode containing both loader and payload into the target process’s memory space (e.g. with VirtualAlloc). The reflective loader parses the process’s kernel32.dll to calculate the addresses of the functions required for relocation and execution. The loader allocates a continuous region of memory to load its own image into. The loader relocates itself into the allocated memory region with the help of its headers. The loader resolves the imports and patches them into the relocated image’s Import Address Table according to the previously gotten function addresses. The loader applies appropriate protections on each relocated section. The loader calls the relocated image’s entry point DllMain with DLL_PROCESS_ATTACH. Implementation The complete implementation can be found from a Gitea repository. The following explanations focus on the loader itself as the supporting components (process injector, shellcode generator, and payload) are basically just pasted from existing implementations mentioned in the references.
·golfed.xyz·
Walkthrough of shellcode reflective DLL injection (sRDI)
Advanced SMS Phishing Attacks Against Modern Android-based Smartphones
Advanced SMS Phishing Attacks Against Modern Android-based Smartphones
Research By: Artyom Skrobov, Slava Makkaveev Introduction Check Point Researchers have identified a susceptibility to advanced phishing attacks in certain modern Android-based phones, including models by Samsung, Huawei, LG and Sony. In these attacks, a remote agent can trick users into accepting new phone settings that, for example, route all their Internet traffic through a […]
·research.checkpoint.com·
Advanced SMS Phishing Attacks Against Modern Android-based Smartphones
Sleep with one eye open: how Librarian Ghouls steal data by night
Sleep with one eye open: how Librarian Ghouls steal data by night
According to Kaspersky, Librarian Ghouls APT continues its series of attacks on Russian entities. A detailed analysis of a malicious campaign utilizing RAR archives and BAT scripts.
·securelist.com·
Sleep with one eye open: how Librarian Ghouls steal data by night
The Risks of the #MonikerLink Bug in Microsoft Outlook and the Big Picture - Check Point Research
The Risks of the #MonikerLink Bug in Microsoft Outlook and the Big Picture - Check Point Research
Introduction Recently, Check Point Research released a white paper titled “The Obvious, the Normal, and the Advanced: A Comprehensive Analysis of Outlook Attack Vectors”, detailing various attack vectors on Outlook to help the industry understand the security risks the popular Outlook app may bring into organizations. As mentioned in the paper, we discovered an interesting […]
·research.checkpoint.com·
The Risks of the #MonikerLink Bug in Microsoft Outlook and the Big Picture - Check Point Research
Achieving Persistent Client-Side Attacks with a Single WeChat Message
Achieving Persistent Client-Side Attacks with a Single WeChat Message
From White House staff to battlefield journalists, instant messaging (IM) applications are indispensable communication tools for countless individuals. Whether it’s WhatsApp, Telegram, WeChat, or QQ, they have become the “digital arteries” of modern society, carrying core activities such as social interaction, payments, and office work for billions of users. Their security directly affects personal privacy, financial assets, and even national security. In fact, security research on IM platforms has been ongoing for years. In 2019, Project Zero disclosed CVE-2019-8641 in iMessage[1], a memory corruption issue. Since iMessage automatically parses rich media content in messages, an attacker could achieve remote code execution by sending a specially crafted file without user interaction, gaining complete control over the target iPhone.
·darknavy.org·
Achieving Persistent Client-Side Attacks with a Single WeChat Message