How DopplePaymer Hunts & Kills Windows Processes | CrowdStrike
In 2019, our intelligence team reported ProcessHacker being hijacked to kill a list of targeted processes. Explore more on DoppelPaymer implementation here.
Yours Truly, Signed AV Driver: Weaponizing an Antivirus Driver | Aon
As we head into 2022, ransomware groups continue to plague our digital environment with new and interesting techniques to bypass Antivirus (AV) and Endpoint Detection and Response (EDR) solutions and ensuring the successful execution of their ransomware payloads. In December 2021, Stroz Friedberg’s Incident Response Services team engaged in a Digital Forensics and Incident […]
Как сделать свой токен на базе Binance Smart Chain - CPA.RIP
Как сделать свой токен криптовалюту на базе сети Binance Smart Chain, пошаговая инструкция. Содержание 1. Создание кошелька MetaMask 1.1. Резервная копия seed-фразы 1.2. Как подключить MetaMask к Binance Smart Chain 1.3. Пополнение кошелька MetaMask 1.3.1. Пополнение через биржу Binance 1.3.2. Пополнение через обменники 2. Выпуск собственного токена 2.1. Добавляем токен в кошелек 2.2. Публикация контракта...
Java Naming and Directory Interface (JNDI) is a Java API that allows clients to discover and look up data and objects via a name. These objects can be stored in different naming or directory services, such as Remote Method Invocation (RMI), Common Object Request Broker Architecture (CORBA), Lightweight Directory Access Protocol (LDAP), or Domain Name Service (DNS).
Windows 10 RCE: The exploit is in the link | Positive Security
Chaining a misconfiguration in IE11/Edge Legacy with an argument injection in a Windows 10/11 default URI handler and a bypass for a previous Electron patch, we developed a drive-by RCE exploit for Windows 10. The main vulnerability in the ms-officecmd URI handler has not been patched yet and can also be triggered through other browsers (requires confirmation of an inconspicuous dialog) and desktop applications that allow URI opening.
AppLocker – Case study – How insecure is it really? – Part 1
I often hear that AppLocker is not very safe and it is easy to bypass. Since I really like AppLocker and I recommend it to customers, I decided to do this blogpost series and go over the different …
Stealing Data in Great style – How to Use CSS to Attack Web Application. - research.securitum.com
This article will show you an example of how you can use the ability to inject your own CSS rules into a web application to exfiltrate data. This attack can be particularly practical for stealing tokens that protect against CSRF attacks. In this text we will see that CSS injections can be used to steal ...
Technical Advisory – Apple XAR – Arbitrary File Write (CVE-2021-30833)
XAR is a file archive format used in macOS, and is part of various file formats, including .xar, .pkg, .safariextz, and .xip files. XAR archives are extracted using the xar command-line utility. XAR was initially developed under open source, however, the original project appears to be no longer maintained. Apple maintains their own branch of XAR for macOS, which is published on the Apple Open Source website. The xar utility suffers from a logical vulnerability which allows files to be extracted outside of the intended destination folder, resulting in arbitrary file write anywhere on the filesystem (permissions allowing).
Доклад Александра Слобоженко и Семена Лаврова с конференции MAC 2021 на тему «Facebook 2021, залив и масштабирование от Traffic Devils» - CPA.RIP
Александр Слобоженко, основатель медиабаинговой команды «Traffic Devils» и Семён Лавров, руководитель баинга, сделали сухой разбор арбитража трафика в Facebook на примере свежего мощного кейса. Содержание 1. Схема залива в Facebook 2. Возможные проблемы 3. Кейс 4. Аналитика по ГЕО 5. Релевантность крео и прилы 6. Разбор креатива 7. Подходы к крео Схема залива в Facebook...
This post is a technical analysis of a recently disclosed Chrome JIT vulnerability (CVE-2021-30632) that was believed to be exploited in the wild. This vulnerability was reported by an anonymous researcher and was patched on September 13, 2021 in Chrome version 93.0.4577.82. I’ll cover the root cause analysis of the bug, as well as detailed exploitation.
Mistuned Part 1: Client-side XSS to Calculator and More
Ever since Pointer Authentication Code (PAC) has been introduced, iPhone remained standing for more than two years on various pwn contests until TianfuCup 2020 (Project Zero has reported a remote zero click exploit in 2019). Ant Security and Qihoo 360 used two different bug chains respectively to successfully gained remote code execution with userspace sandbox escape on iPhone 11 with iOS 14.2.