fa
Feedback
r0 Crew (Channel)

r0 Crew (Channel)

رفتن به کانال در Telegram

Security Related Links: - Reverse Engineering; - Malware Research; - Exploit Development; - Pentest; - etc; Join to chat: @r0crew_bot 👈 Forum: https://forum.reverse4you.org Twitter: https://twitter.com/R0_Crew

نمایش بیشتر
9 248
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-67 روز
-3130 روز

در حال بارگیری داده...

ابر برچسب‌ها
هیچ داده‌ای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
آوریل '25
آوریل '25
+35
در 0 کانال‌ها
مارس '25
+58
در 0 کانال‌ها
Get PRO
فوریه '25
+62
در 0 کانال‌ها
Get PRO
ژانویه '25
+270
در 0 کانال‌ها
Get PRO
دسامبر '24
+103
در 1 کانال‌ها
Get PRO
نوامبر '24
+223
در 0 کانال‌ها
Get PRO
اکتبر '24
+207
در 1 کانال‌ها
Get PRO
سپتامبر '24
+84
در 2 کانال‌ها
Get PRO
اوت '24
+3
در 2 کانال‌ها
Get PRO
ژوئیه '24
+12
در 1 کانال‌ها
Get PRO
ژوئن '24
+2
در 0 کانال‌ها
Get PRO
مه '24
+6
در 0 کانال‌ها
Get PRO
آوریل '24
+11
در 0 کانال‌ها
Get PRO
مارس '24
+502
در 0 کانال‌ها
Get PRO
فوریه '24
+84
در 0 کانال‌ها
Get PRO
ژانویه '24
+104
در 0 کانال‌ها
Get PRO
دسامبر '23
+150
در 1 کانال‌ها
Get PRO
نوامبر '23
+85
در 0 کانال‌ها
Get PRO
اکتبر '23
+165
در 0 کانال‌ها
Get PRO
سپتامبر '23
+1 142
در 0 کانال‌ها
Get PRO
اوت '23
+432
در 0 کانال‌ها
Get PRO
ژوئیه '23
+130
در 0 کانال‌ها
Get PRO
ژوئن '23
+85
در 0 کانال‌ها
Get PRO
مه '23
+60
در 0 کانال‌ها
Get PRO
آوریل '23
+75
در 0 کانال‌ها
Get PRO
مارس '23
+68
در 0 کانال‌ها
Get PRO
فوریه '23
+67
در 0 کانال‌ها
Get PRO
ژانویه '23
+89
در 0 کانال‌ها
Get PRO
دسامبر '22
+91
در 0 کانال‌ها
Get PRO
نوامبر '22
+114
در 0 کانال‌ها
Get PRO
اکتبر '22
+124
در 0 کانال‌ها
Get PRO
سپتامبر '22
+106
در 0 کانال‌ها
Get PRO
اوت '22
+144
در 0 کانال‌ها
Get PRO
ژوئیه '22
+144
در 0 کانال‌ها
Get PRO
ژوئن '22
+131
در 0 کانال‌ها
Get PRO
مه '22
+157
در 0 کانال‌ها
Get PRO
آوریل '22
+124
در 0 کانال‌ها
Get PRO
مارس '22
+159
در 0 کانال‌ها
Get PRO
فوریه '22
+121
در 0 کانال‌ها
Get PRO
ژانویه '22
+139
در 0 کانال‌ها
Get PRO
دسامبر '21
+80
در 0 کانال‌ها
Get PRO
نوامبر '21
+127
در 0 کانال‌ها
Get PRO
اکتبر '21
+132
در 0 کانال‌ها
Get PRO
سپتامبر '21
+162
در 0 کانال‌ها
Get PRO
اوت '21
+283
در 0 کانال‌ها
Get PRO
ژوئیه '21
+147
در 0 کانال‌ها
Get PRO
ژوئن '21
+120
در 0 کانال‌ها
Get PRO
مه '21
+111
در 0 کانال‌ها
Get PRO
آوریل '21
+131
در 0 کانال‌ها
Get PRO
مارس '21
+244
در 0 کانال‌ها
Get PRO
فوریه '21
+148
در 0 کانال‌ها
Get PRO
ژانویه '21
+223
در 0 کانال‌ها
Get PRO
دسامبر '20
+5 326
در 0 کانال‌ها
تاریخ
رشد مشترکین
اشارات
کانال‌ها
18 آوریل+1
17 آوریل+1
16 آوریل+1
15 آوریل+3
14 آوریل+4
13 آوریل+1
12 آوریل+2
11 آوریل+1
10 آوریل+2
09 آوریل+4
08 آوریل+5
07 آوریل0
06 آوریل+3
05 آوریل+1
04 آوریل0
03 آوریل+3
02 آوریل+3
01 آوریل0
پست‌های کانال
Repost from N/a
New blog on using CLR customizations to improve the OPSEC of your .NET execution harness. This includes a novel AMSI bypass that identified by author in 2023. By taking control of CLR assembly loads, we can load assemblies from memory with no AMSI scan. https://securityintelligence.com/x-force/being-a-good-clr-host-modernizing-offensive-net-tradecraft/ Proof-of-concept for the AMSI bypass and an implementation of a CLR memory manager is on GitHub. We can implement custom memory routines and track all allocations made by the CLR. https://github.com/passthehashbrowns/Being-A-Good-CLR-Host #redteam #net #clr

2
Happy New Year! May every binary reveal its secrets, every challenge find its solution, and the Year of the Snake bring you s
Happy New Year! May every binary reveal its secrets, every challenge find its solution, and the Year of the Snake bring you stability, inspiration, and success!
3 346
3
Complete list of LPE exploits for Windows (starting from 2023) https://github.com/MzHmO/Exploit-Street #windows #expdev #lpe
3 849
4
Attacking UNIX Systems via CUPS, Part I CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177 have been assigned around these CUPS issues. CVSS 9.9 This remote code execution issue can be exploited across the public Internet via a UDP packet to port 631 without needing any authentication, assuming the CUPS port is open through your router/firewall. LAN attacks are also possible via spoofing zeroconf / mDNS / DNS-SD advertisements. https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ A series of bugs in the CUPS printers discovery mechanism (cups-browsed) and in other components of the CUPS system, can be chained together to allow a remote attacker to automatically install a malicious printer (or hijack an existing one via mDNS) to execute arbitrary code on the target host as the lp user when a print job is sent to it. https://gist.github.com/stong/c8847ef27910ae344a7b5408d9840ee1 #linux #rce #printer
5 799
5
0-Click exploit in MediaTek Wi-Fi chipsets affects routers and smartphones / Exploiting (CVE-2024-20017) 4 different ways https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html #expdev #poc
5 251
6
Native function and Assembly Code Invocation https://research.checkpoint.com/2022/native-function-and-assembly-code-invocation/ #reverse #idapro
9 063
7
Exploiting the Windows Kernel via Malicious IPv6 Packets (CVE-2024-38063) https://malwaretech.com/2024/08/exploiting-CVE-2024-38063.html #expdev #poc
5 781
8
POC for trigerring CVE-2024-38063 (RCE in tcpip.sys) https://github.com/ynwarcs/CVE-2024-38063 #expdev #poc
6 166
9
C++ Unwind Exception Metadata: a Hidden Reverse Engineering Bonanza https://www.msreverseengineering.com/blog/2024/8/20/c-unwind-metadata-1 #reverse #cpp #type #reconstruction #hints
4 910
10
V8 Sandbox escape/bypass/violation and VR collection https://github.com/xv0nfers/V8-sbx-bypass-collection #v8 #sandbox #escape
4 113
11
How to Bypass Golang SSL Verification https://www.cyberark.com/resources/threat-research-blog/how-to-bypass-golang-ssl-verification #golang #ssl #bypass #reverse #web #pentest
3 682
12
SGN is a polymorphic binary encoder for offensive security purposes such as generating statically undetecable binary payloads. It uses a additive feedback loop to encode given binary instructions similar to LSFR. This project is the reimplementation of the original Shikata ga nai in golang with many improvements. https://github.com/EgeBalci/sgn #redteam #golang
3 768
13
Shoggoth is an open-source project based on C++ and asmjit library used to encrypt given shellcode, PE, and COFF files polymorphically. https://github.com/frkngksl/Shoggoth #redteam
3 745
14
LayeredSyscall – Abusing VEH to Bypass EDRs https://whiteknightlabs.com/2024/07/31/layeredsyscall-abusing-veh-to-bypass-edrs #redteam #edr #hook #bypass
3 936
15
DJI - The ART of obfuscation https://blog.quarkslab.com/dji-the-art-of-obfuscation.html #reverse #mobile #android #obfuscation
5 357
16
The installation package for IDA Pro 9.0 Beta 2 available without password. https://out5.hex-rays.com/beta90_6ba923/ Forum fo
The installation package for IDA Pro 9.0 Beta 2 available without password. https://out5.hex-rays.com/beta90_6ba923/ Forum for discussion: https://forum.reverse4you.org/t/ida-pro-9-0-beta/20459 Chat for discussion: https://t.me/r0_chat/1 #tools #reverse #idapro #windows #linux #macos
6 995
17
Thread-Name Calling - A new process injection technique using Thread Name. The code to be injected is passed as a thread description to the target. https://research.checkpoint.com/2024/thread-name-calling-using-thread-name-for-offense/ #redteam #inject
6 876
18
Keystone / Capstone Replacement Nyxstone is a powerful assembly and disassembly library based on LLVM. It doesn’t require patches to the LLVM source tree and links against standard LLVM libraries available in most Linux distributions. Implemented as a C++ library, Nyxstone also offers Rust and Python bindings. It supports all official LLVM architectures and allows to configure architecture-specific target settings. GitHub: https://github.com/emproof-com/nyxstone Blog: https://www.emproof.com/introducing-nyxstone-an-llvm-based-disassembly-framework/
7 562
19
xVMP is an LLVM IR-based code virtualization tool, which fulfilled a scalable and virtualized instruction-hardened obfuscation. It supports multiple programming languages, and architectures. It is also compatible with existing LLVM IR-based obfuscation schemes (such as Obfuscator-LLVM). xVMP is developer friendly. You only need to add annotations to the to-be-protected function in the source code, and xVMP can perform virtualization protection on the function during compilation. https://github.com/GANGE666/xVMP #virtualization #obfuscation #alekum
7 126
20
Mergen converts Assembly code into LLVM IR, a process known as lifting. It leverages the LLVM optimization pipeline for code optimization and constructs control flow through pseudo-emulation of instructions. Unlike typical emulation, Mergen can handle unknown values, easing the detection of opaque branches and theoretically enabling exploration of multiple code branches. These capabilities facilitate the deobfuscation and devirtualization of obfuscated or virtualized functions. Currently in early development, Mergen already shows promise in devirtualizing older versions of VMProtect, with ambitions to support most x86_64 instructions. https://github.com/NaC-L/Mergen #llvm #lifting #vmprotect #tnaci
8 742