Found 1481 bookmarks
Newest
How anti-cheats detect system emulation
How anti-cheats detect system emulation
Overview As our first article addressing the various methods of detecting the presence of VMMs, whether commercial or custom, we wanted to be thorough and associate it with our research on popular anti-cheat vendors. To kick off the article it’s important for those outside of the game hacking arena to understand the usage of hypervisors for cheating, and the importance of anti-cheats staying on top of cheat providers using them. This post will cover a few standard detection methods that can be used for both Intel/AMD; offering an explanation, a mitigation, and a general rating of efficacy. ...
·secret.club·
How anti-cheats detect system emulation
trichimtrich/turnproxy
trichimtrich/turnproxy
turn server - into something you can - see - through 🏙 - trichimtrich/turnproxy
·github.com·
trichimtrich/turnproxy
Abusing Safari's webarchive file format
Abusing Safari's webarchive file format
tldr: For now, don't open .webarchive files, and check the Metasploit module, Apple Safari .webarchive File Format UXSS Safari's webarchive format saves all the resources in a web page - images, scripts, stylesheets - into a single file. A flaw exists in the security model behind webarchives that allows us
·blog.rapid7.com·
Abusing Safari's webarchive file format
Как создать крутой рекламный текст: 8 советов от одного из лучших американских копирайтеров
Как создать крутой рекламный текст: 8 советов от одного из лучших американских копирайтеров
Период самоизоляции – хорошее время для приобретения новых знаний. Новинка издательства «Альпіна Паблішер» «Как создать крутой рекламный текст. Принципы выдающегося американского копирайтера» как раз
·mc.today·
Как создать крутой рекламный текст: 8 советов от одного из лучших американских копирайтеров
(Не)очевидный OSINT в Twitter
(Не)очевидный OSINT в Twitter
Twitter — достаточно старый, но при этом все еще популярный у широкой аудитории сервис микроблогов, которым активно пользуются как рядовые пользователи, так и...
·habr.com·
(Не)очевидный OSINT в Twitter
Не показываются объявления на поиске Google/Яндекса: 15 возможных причин
Не показываются объявления на поиске Google/Яндекса: 15 возможных причин
Настроили и запустили контекстную рекламу, а показов нет… Или они были, но пропали. Не спешите пинать техподдержку рекламных систем — пройдитесь по чек-листу. С...
·habr.com·
Не показываются объявления на поиске Google/Яндекса: 15 возможных причин
Exploiting directory permissions on macOS
Exploiting directory permissions on macOS
This research started around summer time in 2019, when everything settled down after my talk in 2019, where I detailed how did I gained root privileges via a benign App Store application, that I developed. That exploit used a symlink to achieve this, so I though I will make a more general approach and see if this type of vulnerability exists in other places as well on macOS systems. As it turns out it does exists, and not just on macOS directly but also on other apps, it appears to be a very fruitful of issue, without too much effort I found 5 exploitable bugs on macOS, 3 in Adobe installer...
·theevilbit.github.io·
Exploiting directory permissions on macOS
Руководство по созданию призыва к действию
Руководство по созданию призыва к действию
К концу этой статьи вы сможете понять, как на самом деле работает внимание, и превратить посетителей вашего сайта или приложения в потенциальных клиентов
·ux.pub·
Руководство по созданию призыва к действию
Get Your Weather Images Straight From The Satellite
Get Your Weather Images Straight From The Satellite
[Josh] has a series called Ham Radio Crash Course and a recent installment covers how you can grab satellite images directly from weather satellites. This used to be more of a production than it is…
·hackaday.com·
Get Your Weather Images Straight From The Satellite
Оценка конкурентности поисковых запросов по вариациям поисковой выдачи
Оценка конкурентности поисковых запросов по вариациям поисковой выдачи
Оценка степени конкуренции по ключевому запросу является одной из сакральных задач поисковой оптимизации. Надежда обнаружить незамеченный конкурентами запрос с...
·habr.com·
Оценка конкурентности поисковых запросов по вариациям поисковой выдачи
Unicode is Awesome
Unicode is Awesome
A curated list of delightful Unicode tidbits, packages and resources. Foreword Unicode is Awesome! Prior to Unicode, international communication was grueling- everyone had defined their separate extended character set in the upperhalf of ASCII (called Code Pages) that would conflict- Just think, German speakers coordinating with Korean speakers over which
·eng.getwisdom.io·
Unicode is Awesome
Chaining Three Bugs to Get RCE in Microsoft AttackSurfaceAnalyzer
Chaining Three Bugs to Get RCE in Microsoft AttackSurfaceAnalyzer
This is a blog post about how I found three vulns and chained them to get RCE in the Microsoft AttackSurfaceAnalyzer (ASA moving forward) GUI version. ASA uses Electron.NET which binds the internal Kestrel web server to 0.0.0.0. If permission is given to bypass the Windows OS firewall (or if used on an OS without one), a remote attacker can connect to it and access the application. The web application is vulnerable to Cross-Site Scripting (XSS). A remote attacker can submit a runID with embedded JavaScript that is executed by the victim using the ASA Electron application. Electron.NET does ...
·parsiya.net·
Chaining Three Bugs to Get RCE in Microsoft AttackSurfaceAnalyzer
Public disclosure on CVE-2020-8818 [Unauthorized Payments Hijacking + Order Status Spoofing]
Public disclosure on CVE-2020-8818 [Unauthorized Payments Hijacking + Order Status Spoofing]
Lack of origin authentication (CWE-346) at IPN callback processing function allow (even unauthorized) attacker to remotely replace critical plugin settings (merchant id, secret key etc) with known to him and therefore bypass payment process (eg. spoof order status by manually sending IPN callback request with a valid signature but without real payment) and/or receive all subsequent payments (on behalf of the store).
·github.com·
Public disclosure on CVE-2020-8818 [Unauthorized Payments Hijacking + Order Status Spoofing]
Demystifying Browsers
Demystifying Browsers
I started building browser extensions more than 22 years ago, and I started building browsers directly just over 16 years ago. At this point, I think it’s fair to say that I’m entering …
·textslashplain.com·
Demystifying Browsers
Конец эпохи Trident
Конец эпохи Trident
tl;dr Я бы сказал, что Microsoft на несколько световых лет опередила всех в разработке инструментов для проектирования сложных веб-сайтов. Сейчас эти технологии...
·habr.com·
Конец эпохи Trident
Как (и зачем) бесплатно парсить ключи и объявления конкурентов из Яндекс.Директ и Google Ads
Как (и зачем) бесплатно парсить ключи и объявления конкурентов из Яндекс.Директ и Google Ads
Перед запуском контекстной рекламы полезно посмотреть на ключевые слова и объявления конкурентов. Так вы пополните семантику и получите новые идеи для текстов о...
·habr.com·
Как (и зачем) бесплатно парсить ключи и объявления конкурентов из Яндекс.Директ и Google Ads
Похек Wi-Fi встроенными средствами macOS
Похек Wi-Fi встроенными средствами macOS
TL;DR Встроенные средства macOS позволяют выполнить некоторые атаки на Wi-Fi-сети. В статье описывается, как с помощью встроенного в Macbook Wi-Fi адаптера Air...
·habr.com·
Похек Wi-Fi встроенными средствами macOS