03/05

Lord Of The Ring0 - Part 4 | The call back home - Ido Veltzman - Security Blog

https://idov31.github.io/2023/02/24/lord-of-the-ring0-p4.html
Lord Of The Ring0 - Part 4 | The call back home - Ido Veltzman - Security Blog

Obfuscating Rubeus using Codecepticon

https://www.pavel.gr/blog/obfuscating-rubeus-using-codecepticon
Obfuscating Rubeus using Codecepticon

https://www.sans.org/u/1p3q

https://www.sans.org/u/1p3q

New TPM 2.0 flaws could let hackers steal cryptographic keys

https://www.bleepingcomputer.com/news/security/new-tpm-20-flaws-could-let-hackers-steal-cryptographic-keys/
New TPM 2.0 flaws could let hackers steal cryptographic keys

What really is the Entry Point of a .NET Module? | Washi

https://washi.dev/blog/posts/entry-points/
What really is the Entry Point of a .NET Module? | Washi

ARM 64 Assembly Series — Data Processing (Part 1) | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/arm-64-assembly-series-data-processing-part-1-b6f6f877c56b
ARM 64 Assembly Series — Data Processing (Part 1) | by +Ch0pin🕷️ | Medium

Introduction to x64 Linux Binary Exploitation (Part 4)- Stack Canaries | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-4-stack-canaries-e9b6dd2c3127
Introduction to x64 Linux Binary Exploitation (Part 4)- Stack Canaries | by +Ch0pin🕷️ | Medium

Police Are Getting Help From Social Media Sites to Prosecute People for Abortion

https://www.businessinsider.com/police-getting-help-social-media-to-prosecute-people-seeking-abortions-2023-2
Police Are Getting Help From Social Media Sites to Prosecute People for Abortion

(PDF) A brief note on "Exonerating Morocco disproving the spyware"

https://www.researchgate.net/publication/368985450_A_brief_note_on_Exonerating_Morocco_disproving_the_spyware
(PDF) A brief note on "Exonerating Morocco disproving the spyware"

Introduction to x64 Linux Binary Exploitation (Part 5)- ASLR | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-5-aslr-394d0dc8e4fb
Introduction to x64 Linux Binary Exploitation (Part 5)- ASLR | by +Ch0pin🕷️ | Medium

ARM 64 Assembly Series — Branch. Previous posts: Basic definitions and… | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/arm-64-assembly-series-branch-9ce820987fc6
ARM 64 Assembly Series — Branch. Previous posts: Basic definitions and… | by +Ch0pin🕷️ | Medium

From on-prem to Global Admin without password reset - Cloudbrothers

https://cloudbrothers.info/en/prem-global-admin-password-reset/
From on-prem to Global Admin without password reset - Cloudbrothers

Introduction to x64 Linux Binary Exploitation (Part 2)—return into libc | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/introduction-to-x64-binary-exploitation-part-2-return-into-libc-c325017f465
Introduction to x64 Linux Binary Exploitation (Part 2)—return into libc | by +Ch0pin🕷️ | Medium

https://pastebin.com/raw/Bk1hu2d6

https://pastebin.com/raw/Bk1hu2d6

Introduction to x64 Linux Binary Exploitation (Part 1) | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-1-14ad4a27aeef
Introduction to x64 Linux Binary Exploitation (Part 1) | by +Ch0pin🕷️ | Medium

Week 10 – 2023 – This Week In 4n6

http://thisweekin4n6.com/2023/03/05/week-10-2023/
Week 10 – 2023 – This Week In 4n6

Introduction to x64 Linux Binary Exploitation (Part 3)- RoP Chains | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/introduction-to-x64-linux-binary-exploitation-part-3-rop-chains-3cdcf17e8826
Introduction to x64 Linux Binary Exploitation (Part 3)- RoP Chains | by +Ch0pin🕷️ | Medium

A New Vector For “Dirty” Arbitrary File Write to RCE · Doyensec's Blog

https://blog.doyensec.com//2023/02/28/new-vector-for-dirty-arbitrary-file-write-2-rce.html
A New Vector For “Dirty” Arbitrary File Write to RCE · Doyensec's Blog

diaphora/compilation_units.md at master · joxeankoret/diaphora · GitHub

https://github.com/joxeankoret/diaphora/blob/master/doc/articles/compilation_units.md
diaphora/compilation_units.md at master · joxeankoret/diaphora · GitHub

The Red Report 2023.pdf - Google ドライブ

https://drive.google.com/file/d/1Rp2QF4e5-zvdtPJApaiRQEGtscweb8SV/view
The Red Report 2023.pdf - Google ドライブ

New FiXS ATM Malware Targeting Mexican Banks

https://thehackernews.com/2023/03/new-fixs-atm-malware-targeting-mexican.html
New FiXS ATM Malware Targeting Mexican Banks

ARM 64 Assembly Series— Basic definitions and registers | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/arm-64-assembly-series-basic-definitions-and-registers-ec8cc1334e40
ARM 64 Assembly Series— Basic definitions and registers | by +Ch0pin🕷️ | Medium

ARM 64 Assembly Series — Load and Store | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/arm-64-assembly-series-load-and-store-6bfe9c1d1896
ARM 64 Assembly Series — Load and Store | by +Ch0pin🕷️ | Medium

ARM 64 Assembly Series — Offset and Addressing modes | by +Ch0pin🕷️ | Medium

https://valsamaras.medium.com/arm-64-assembly-series-offset-and-addressing-modes-aa48b65b4c99
ARM 64 Assembly Series — Offset and Addressing modes | by +Ch0pin🕷️ | Medium

Medium

https://valsamaras.medium.com/arm-64-assembl
Medium

fucked up looking computers on Twitter: "https://t.co/cfTxMrrygU" / Twitter

https://twitter.com/fuckeduppcs/status/1632004967988105217
fucked up looking computers on Twitter: "https://t.co/cfTxMrrygU" / Twitter

Bypass TCC via iCloud

https://wojciechregula.blog/post/bypass-tcc-via-icloud/
Bypass TCC via iCloud

FiXS, a new ATM malware that is targeting Mexican banksSecurity Affairs

https://securityaffairs.com/143022/malware/fixs-atm-malware-mexican-banks.html
FiXS, a new ATM malware that is targeting Mexican banksSecurity Affairs

Table of Geographical Locations - Win32 apps | Microsoft Learn

https://learn.microsoft.com/en-us/windows/win32/intl/table-of-geographical-locations
Table of Geographical Locations - Win32 apps | Microsoft Learn

Remote Code Execution via Prototype Pollution in Blitz.js | Sonar

https://www.sonarsource.com/blog/blitzjs-prototype-pollution/
Remote Code Execution via Prototype Pollution in Blitz.js | Sonar

Thousands of websites hacked as part of redirection campaignSecurity Affairs

https://securityaffairs.com/142975/hacking/ftp-credentials-traffic-redirection-campaign.html
Thousands of websites hacked as part of redirection campaignSecurity Affairs

FiXS the new ATM Malware in LATAM - Metabase Q

https://www.metabaseq.com/fixs-atms-malware/
FiXS the new ATM Malware in LATAM - Metabase Q

GitHub Security Lab audited DataHub: Here's what they found | The GitHub Blog

https://github.blog/2023-03-03-github-security-lab-audited-datahub-heres-what-they-found/
GitHub Security Lab audited DataHub: Here's what they found | The GitHub Blog

VirusTotal - File - 6019120f81c432820354fd7763baa7c6bd4611e92813a8b0e5edf0a342472f16

https://www.virustotal.com/gui/file/6019120f81c432820354fd7763baa7c6bd4611e92813a8b0e5edf0a342472f16/details
VirusTotal - File - 6019120f81c432820354fd7763baa7c6bd4611e92813a8b0e5edf0a342472f16