HackerOne – Telegram
HackerOne
11K subscribers
644 photos
31 videos
79 files
2.74K links
Community : @Sec0x01
@Bug0x
Download Telegram
Malware writer likes to use ptrace(), why and how?

because with ptrace(), you can essentially redirect the debuggee to call malloc(), and given the newly allocated memory, insert a new program into the newly allocated memory (making sure the pages are marked readable and executable), and redirect some existing codes to that memory for execution and then let the debuggee continue execution.

PoC:

https://github.com/gaffe23/linux-inject

https://shunix.com/shared-library-injection-in-android/
embedded-operating-systems-2nd.rar
10.6 MB
Embedded Operating Systems: A Practical Approach, 2nd Edition 2018
HackerOne
https://t.co/xUX8nzLLgo https://t.co/5eICcCYyPA
this is not a vulnerability telegram desktop, this is a extension spoofing in windows,

if you need more info, please check youtube link,

https://www.youtube.com/watch?v=FzWuOwjK7-I