ActiveX Exploitation in 2019 :: Instantiation is not Scripting
But didn’t Microsoft kill ActiveX? I hear you asking. Well they almost did. As most security practitioners know, ActiveX has had a long history of exploitati...
Scammers are abusing the YouTube policy violation system by filing fake copyright infringements against content creators until their channel is close to being suspended. These scammers then hold the c…
0x03 Learning about Universal Links and Fuzzing URL Schemes on iOS with Frida
Ever wondered what happens under-the-hood when you click on a telephone number on a webpage or email? Or why is it possible that you click on a link to the Android Play or Apple App Store and it opens…
My last blog post was like 1 year old so I thought I would quickly write something interesting with a bug I found recently on Twitter (Periscope). The bug (CSRF) itself is not particuarly impressive b…
Всем привет, друзья) Тема безопасности и анонимности телеграма до сих пор постоянно обсуждается. И сегодня я хочу рассказать вам о том, каким образом можно украть доступ к телеграмму другого человека.…
TL;DR - By adding two parameters to any Google Search URL, you can replace search results with a Knowledge Graph card of your choice. A malicious user can use this to generate false information or ‘fa…
We open-sourced a fault injection tool, KRF, that uses kernel-space syscall interception. You can use it today to find faulty assumptions (and resultant bugs) in your programs. Check it out! This post…
# 1. Background The Steam Chat client is a particularly interesting system to attack because it's built using a modern set of technologies with strong security characteristics. It's built on...
Scanning the Windows files for possible persistence mechanisms I came across a few interesting strings inside the Natural Language Development Platform 6 library (NaturalLanguage6.dll): StemmerDLLPath…
I want to believe that all of you know about ImageMagick and its Tragick. This issue was found in the end of the April, 2016 and due to many processing plugins depends on the ImageMagick library this …
XSSing Google Code-in thanks to improperly escaped JSON data
Google Code-in is an online programming competition for students hosted by Google that takes place every year. When I was signing up for a second time, I put a payload into all the text fields. I didn…
New Exploit Kit "Novidade" Found Targeting Home and SOHO Routers - TrendLabs Security Intelligence B…
We identified a new exploit kit we named Novidade that targets home or small office routers by changing their Domain Name System (DNS) settings via cross-site request forgery (CSRF), enabling attacks …
This talk was presented at bugSWAT. Video of the talk is at https://youtu.be/B5ZyYTKp4gc Talk features: Password manager issue with iframe/CSP sandbox https://crbug.com/825258, https://bugzilla.mozill…
Microsoft Account Takeover Vulnerability Affecting 400 Million Users
During our first security investigation for critical vulnerabilities affecting Microsoft, we came across multiple vulnerabilities that, when chained together, allow an attacker to take over any Micros…
A Fuzzing Drill Hits the Motherlode Research By: Yoav Alon, Netanel Ben-Simon Introduction The year 2017 was an inflection point in the vulnerability landscape. The number of new vulnerabilities repor…
Chrome OS exploit: WebAsm, Site Isolation, crosh, crash reporter, cryptohomed - chromium - …
[ WebAsm OOB ArrayBuffer ] WebAsm instance builder reads imports from an attacker-controlled object in v8/src/wasm/wasm-module.cc:1625 ProcessImports(). Imports can be getters, which run while the ins…