Archive

Archive

1481 bookmarks
Custom sorting
Плохая прокладка – не только женская проблема. Как написать убойный прелендинг - CPA.RIP
Плохая прокладка – не только женская проблема. Как написать убойный прелендинг - CPA.RIP
Прелендинг – это история с неожиданными поворотами, трудностями и счастливым концом. И наша задача её не только создать, но и внедрить нативную рекламу, которая не вызовет отторжения. Содержание 1. Ошибка №1: переспам с названием 1.1. Пишем название в подписи под фотографией 1.2. Подзаголовки 1.3. Постскриптум 2. Ошибка №2: фейковые рекомендации 3. Ошибка №3: неправильная подача...
·cpa.rip·
Плохая прокладка – не только женская проблема. Как написать убойный прелендинг - CPA.RIP
Разбираем прокладки под микроскопом. Что там внутри? - CPA.RIP
Разбираем прокладки под микроскопом. Что там внутри? - CPA.RIP
В прошлой статье я рассказал о грубейших ошибках большинства прелендингов. И пообещал сделать подробный разбор трёх реальных прокладок, ведь практика эффективней теории. И держу своё обещание. Содержание 1. Прелендинг средства от гипертонии 1.1. Ошибка №1: нет логотипа в шапке 1.2. Ошибка №2: плохой заголовок 1.3. Ошибка №3: слабое вступление 1.4. Ошибка №4: резкий рекламный переход...
·cpa.rip·
Разбираем прокладки под микроскопом. Что там внутри? - CPA.RIP
Anti-Debug JS/WASM by Hand
Anti-Debug JS/WASM by Hand
Last week a friend of mine asked me to debug/RE some phishing emails that had been sent to them. These phishing emails were visually very clever and looked identical to the real site! But as I looked at the javascript I frankly became embarassed for the developer.
·remyhax.xyz·
Anti-Debug JS/WASM by Hand
Fuzzing RDP: Holding the Stick at Both Ends
Fuzzing RDP: Holding the Stick at Both Ends
Introduction This post describes the work we’ve done on fuzzing the Windows RDP client and server, the challenges of doing so, and some of the results. The Remote Desktop Protocol (RDP) by...
·cyberark.com·
Fuzzing RDP: Holding the Stick at Both Ends
The dying knight in the shiny armour
The dying knight in the shiny armour
TL;DR With Administrator level privileges and without interacting with the GUI, it’s possible to prevent Defender from doing its job while keeping it alive and without disabling tamper protection by redirecting the \Device\BootDevice NT symbolic link which is part of the NT path from where Defender’s WdFilter driver binary is loaded. This can also be used to make Defender load an arbitrary driver, which no tool succeeds in locating, but does not survive reboots. The code to do that is in APTortellini’s Github repository unDefender. Introduction Some time ago I had a chat with jonasLyk of the Secret Club hacker collective about a technique he devised to disable Defender without making it obvious it was disabled and/or invalidating its tamper protection feature. What I liked about this technique was that it employed some really clever NT symbolic links shenanigans I’ll try to outline in this blog post (which, coincidentally, is also the first one of the Advanced Persistent Tortellini collective :D). Incidentally, this techniques makes for a great way to hide a rootkit inside a Windows system, as Defender can be tricked into loading an arbitrary driver (that, sadly, has to be signed) and no tool is able to pinpoint it, as you’ll be able to see in a while. Grab a beer, and enjoy the ride lads! Win32 paths, NT paths and NT symbolic links When loading a driver in Windows there are two ways of specifying where on the filesystem the driver binary is located: Win32 paths and NT paths. A complete analysis of the subtle differences between these two kinds of paths is out of the scope of this article, but James Forshaw already did a great job at explaining it. Essentially, Win32 paths are a dumbed-down version of the more complete NT paths and heavily rely on NT symbolic links. Win32 paths are the familiar path we all use everyday, the ones with letter drives, while NT paths use a different tree structure on which Win32 paths are mapped. Let’s look at WdFilter’s specific example:
·aptw.tf·
The dying knight in the shiny armour
How to Hack Apple ID
How to Hack Apple ID
Everyone knows what’s inside a computer isn’t really real. It pretends to be, sure, hiding just under the pixels — but I promise you it…
·zemnmez.medium.com·
How to Hack Apple ID
Массовая отправка тикетов RISK_PAYMENT в 1 клик! - CPA.RIP
Массовая отправка тикетов RISK_PAYMENT в 1 клик! - CPA.RIP
После публикации предыдущей статьи про отправку тикетов на риск пеймент (РП) при пустом списке рекламных аккаунтов (РА), FB как-то уж быстро начал требовать прикрепленный документ к этой форме, что добавило лишних телодвижений. Я написал скрипт, который парсит у соц акка, все РА с РП и по нажатию одной кнопки отсылает тикеты на разбан РП по...
·cpa.rip·
Массовая отправка тикетов RISK_PAYMENT в 1 клик! - CPA.RIP
Эффективный поиск XSS-уязвимостей
Эффективный поиск XSS-уязвимостей
Про XSS-уязвимости известно давным-давно — казалось бы, нужен ли миру ещё один материал о них? Но когда Иван Румак, занимающийся тестированием безопасности, поделился методологией их поиска на нашей...
·habr.com·
Эффективный поиск XSS-уязвимостей
Remote code execution in cdnjs of Cloudflare
Remote code execution in cdnjs of Cloudflare
Preface (日本語版も公開されています。) Cloudflare, which runs cdnjs, is running a “Vulnerability Disclosure Program” on HackerOne, which allows hackers to perform vulnerability assessments. This article describes vulnerabilities reported through this program and published with the permission of the Cloudflare security team. So this article is not intended to recommend you to perform an unauthorized vulnerability assessment. If you found any vulnerabilities in Cloudflare’s product, please report it to Cloudflare’s vulnerability disclosure program. TL;DR There was a vulnerability in the cdnjs library update server that could execute arbitrary
·blog.ryotak.me·
Remote code execution in cdnjs of Cloudflare
Finding DOM Polyglot XSS in PayPal the Easy Way
Finding DOM Polyglot XSS in PayPal the Easy Way
Introduction Finding DOM XSS can be tricky when it's buried in thousands of lines of code. We recently developed DOM Invader to help tackle this using a combined dynamic+manual approach to vulnerabili
·portswigger.net·
Finding DOM Polyglot XSS in PayPal the Easy Way
Gaining access to SS7 - Part 1: Finding an access point. SCTP/SIGTRAN & SS7 Overview. Security Pen' Test Framework for the Diameter Protocol. Signaling Security in LTE Roaming
Gaining access to SS7 - Part 1: Finding an access point. SCTP/SIGTRAN & SS7 Overview. Security Pen' Test Framework for the Diameter Protocol. Signaling Security in LTE Roaming
Gaining access to SS7 - Part 1: Finding an access point : https://t.co/6P9EQGMLw1 SCTP/SIGTRAN & SS7 Overview : https://t.co/5uR7rhwwuE Security Pen' Test Framework for the Diameter Protocol: https://t.co/i3T6XBcam3 Signaling Security in LTE Roaming: https://t.co/Uc1kcK3kbo
·twitter.com·
Gaining access to SS7 - Part 1: Finding an access point. SCTP/SIGTRAN & SS7 Overview. Security Pen' Test Framework for the Diameter Protocol. Signaling Security in LTE Roaming
Counter-Strike Global Offsets: reliable remote code execution
Counter-Strike Global Offsets: reliable remote code execution
One of the factors contributing to Counter-Strike Global Offensive’s (herein “CS:GO”) massive popularity is the ability for anyone to host their own community server. These community servers are free to download and install and allow for a high grade of customization. Server administrators can create and utilize custom assets such as maps, allowing for innovative game modes.
·secret.club·
Counter-Strike Global Offsets: reliable remote code execution