en
Feedback
Orca Cyber Weapons

Orca Cyber Weapons

Open in Telegram

Orca Cyber Weapons: Security Research World check our community if you are interesting about Security Researching https://t.me/VulnerabilityResearchers - кибербезопасность

Show more
464
Subscribers
No data24 hours
+87 days
+2830 days
Posts Archive
Repost from 1N73LL1G3NC3
CVE-2025-21333 Windows Hyper-V LPE Exploit for a zero-day vulnerability in Windows Hyper-V that enables attackers to gain SYS
CVE-2025-21333 Windows Hyper-V LPE Exploit for a zero-day vulnerability in Windows Hyper-V that enables attackers to gain SYSTEM privileges on affected Windows devices. The PoC demonstrates an attack targeting the vkrnlintvsp.sys driver, leveraging an overwrite in the I/O Ring buffer entry to gain arbitrary read/write capabilities in the Windows kernel.

LummaC2 Stealer – a so-called "premium" malware, but let me break it down for you: it’s nothing more than a poorly crafted in
LummaC2 Stealer – a so-called "premium" malware, but let me break it down for you: it’s nothing more than a poorly crafted info stealer. Advertised as targeting browsers, crypto wallets, and 2FA data, but a closer inspection reveals hardcoded paths, weak obfuscation, and laughable anti-analysis tricks. All those so-called "advanced features"? More like beginner-level coding with a dash of skiddy mentality. From pathetic API hashing to predictable file paths, this thing is a disaster. We reverse-engineered it, exposed its secrets, and here’s the reality: it's as low-quality as it gets. And hey, no surprise – it's marketed to lazy attackers looking for easy money. If this is the best they can do, it’s no match for even the most basic AV. https://github.com/x86byte/LummaC2-Stealer

LummaC2 extracted binaries by reversing & LummaC2 Stealer Analysis https://github.com/x86byte/LummaC2-Stealer

Demystifying Physical Memory Primitive Exploitation on Windows https://0dr3f.github.io/Demystifying_Physical_Memory_Primitive_Exploitation_on_Windows

SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux Kernel https://stefangast.eu/papers/slubstick.pdf

38C3 - Reverse engineering U-Boot for fun and profit https://youtu.be/tnVD30fM5Tg yb : @mediacccde

SigGraph: Brute Force Scanning of Kernel Data Structure Instances Using Graph-based Signatures, the 17th Network and Distributed System Security Symposium, 2011. link : https://www.cs.purdue.edu/homes/xyzhang/Comp/ndss11.pdf Reuse-Oriented Camouflaging Trojan: Vulnerability Detection and Attack Construction, the 40th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, 2010. link : https://www.cs.purdue.edu/homes/xyzhang/Comp/dsn10.pdf Automatic Reverse Engineering of Data Structures from Binary Execution, the 17th Network and Distributed System Security Symposium, 2010. link : https://www.cs.purdue.edu/homes/xyzhang/Comp/ndss10.pdf Deriving Program Input Syntactic Structure from Execution, 16th ACM SIGSOFT Symposium on Foundations of Software Engineering, 2008. link : https://www.cs.purdue.edu/homes/xyzhang/Comp/fse08.pdf Convicting Remote Exploitable Vulnerabilities: An Efficient Input Provenance Based Approach, IEEE/IFIP International Conference on Dependable Systems and Networks, 2008. link : https://www.cs.purdue.edu/homes/xyzhang/Comp/dsn08.pdf Automatic Protocol Format Reverse Engineering Through Context-Aware Monitored Execution, Network and Distributed System Security Symposium, 2008. link : https://www.cs.purdue.edu/homes/xyzhang/Comp/NDSS08.pdf

"Flare-On is a fascinating reverse engineering challenge where participants delve into complex puzzles hidden in binaries and scripts. It tests your problem-solving abilities as you dissect obfuscated code and uncover the underlying logic. For those passionate about security research and the latest exploitation tactics, diving deep into expert discussions and resources can greatly expand your knowledge. Check out insightful blog posts for more detailed solutions: flare-on-11-task-5 flare-on-11-task-7 flare-on-11-task-9 flare-on-11-task-10 Additionally, some great videos by @gf_256 (on x.com) cover reverse engineering insights: Let's Reverse Engineer: Flare-On 2023 Challenges 1–4 Flare-On 2024: Challenge 4 Reverse Engineering Live Flare-On 2024: Challenges 1-3 Reverse Engineering Live Flare-On 2024 Solutions and Commentary Flare-On 2024: Challenge 5 Reverse Engineering Live Flare-On 2024: Challenge 6 Reverse Engineering Live Flare-On 2024: Challenge 7 Reverse Engineering Live Flare-On 2024: Challenge 8 Reverse Engineering Live Flare-On 2024: Challenge 9 Reverse Engineering (Part 1) Flare-On 2024: Challenge 9 Reverse Engineering (Part 2) Flare-On 2024: Challenge 10 Reverse Engineering Live For those who crave a deeper understanding of the security landscape, exploring communities like Orca Cyber Weapons offers a wealth of knowledge and collaboration opportunities among like-minded professionals."

Repost from Orca Cyber Weapons
"Comprehensive roadmap for mastering reverse engineering and malware analysis. From beginner to expert level, explore resources and practical exercises." https://github.com/x86byte/RE-MA-Roadmap/