fa
Feedback
Source Byte

Source Byte

رفتن به کانال در Telegram

هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187

نمایش بیشتر
8 322
مشترکین
-224 ساعت
-157 روز
-6230 روز
آرشیو پست ها
if you want to using Function stomping technique you have to know this about windows:
Kernel32.dll, a common DLL, might have different addresses in two processes(ASLR), but functions like VirtualAlloc, exported from Kernel32.dll, will have the same address in both processes.
example: Link

[ Testing LFI in Windows: How I (never) got a $30000 bounty ] Another great post by adeadfed! https://adeadfed.com/posts/test
[ Testing LFI in Windows: How I (never) got a $30000 bounty ] Another great post by adeadfed! https://adeadfed.com/posts/testing-lfi-in-windows-how-i-never-got-a-30000-bounty/

One of the "essential" windows auditing tools, add my other favorites like rpcview, process hacker, sysinternals, ghidra, wireshark xpe viewer, windbg, imhex and visual studio. Get James Forshaw's NtObjectManager thing too, seems useful for parsing MIDL like rpcviewer. PipeViewer - A Tool That Shows Detailed Information About Named Pipes In Windows https://github.com/cyberark/PipeViewer credit : Eviatar Gerzi #tweet , source

A very good introductory series of articles examining the process of driver development for Windows (NT): Part 1, part 2,.... (The material is old, but gold) #windows #drivers

مردان واقعی از دیس اسمبلر قاسمی استفاده میکنند
مردان واقعی از دیس اسمبلر قاسمی استفاده میکنند

Practical_Cryptography_Algorithms_and_Implementations_using_Azad.pdf2.37 MB

photo content

+3
Scorpio-Windows.Internals.(2020).part1.rar1024.00 MB

Scorpio-Windows.Internals.(2020)

https://github.com/BlackHat-Ashura/Reflective_DLL_Injection Program to Inject a DLL into a process from memory

List of callbacks and codes that we can use them to execute shellcode (Alternative Shellcode Execution Via Callbacks) https://github.com/aahmad097/AlternativeShellcodeExec #malware_dev

photo content

Zero EAT touch way to retrieve function addresses https://github.com/MzHmO/SymProcAddress

+3
Scorpio_Advanced_Windows_Kernel_Programming_w_Pavel_Yosifovich_2023.rar1024.00 MB

Repost from 1N73LL1G3NC3
💋 GamingServiceEoP by [ Filip Dragović @filip_dragovic ] Exploit for arbitrary folder move in GamingService component of Xbox. GamingService is not default service. If service is installed on system it allows low privilege users to escalate to system.