Automation in Reverse Engineering: String Decryption https://synthesis.to/2021/06/30/automating_string_decryption.html
A good historic background of Pegasus, a weapon system by NSO Group and role of Israel 🇮🇱 (government) in supporting the cyber espionage and specifics to India 🇮🇳
Israeli government is trying to evade sanctioning NSO and similar companies under international pressure. Lobbying is not working for Israel. Public is aware and only thing in Israels favour is to stay quiet till the heat dies out.
https://youtu.be/0OWw8IEj9oQ
Israeli government is trying to evade sanctioning NSO and similar companies under international pressure. Lobbying is not working for Israel. Public is aware and only thing in Israels favour is to stay quiet till the heat dies out.
https://youtu.be/0OWw8IEj9oQ
CVE-2021-27850 Exploit
https://github.com/kahla-sec/CVE-2021-27850_POC
https://github.com/kahla-sec/CVE-2021-27850_POC
GitHub
GitHub - kahla-sec/CVE-2021-27850_POC: A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated…
A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution. - kahla-sec/CVE-2021-27850_POC
Fuzzing online udp protocols of online games to achieve RCE
http://blog.ret2.io/2021/07/21/wtf-snapshot-fuzzing/
http://blog.ret2.io/2021/07/21/wtf-snapshot-fuzzing/
RET2 Systems Blog
All Your Base Are [Still] Belong To Us
Axel ‘0vercl0k’ Souchet recently open-sourced a promising new snapshot-based fuzzer. In his own words: ”what the fuzz or wtf is a distributed, code-coverage ...
Supply-Chain ⛓ attack via Python.
As many as eight Python packages that were downloaded more than 30,000 times have been removed from the PyPI portal for containing malicious code, once again highlighting how software package repositories are evolving into a popular target for supply chain attacks.
https://thehackernews.com/2021/07/several-malicious-typosquatted-python.html
As many as eight Python packages that were downloaded more than 30,000 times have been removed from the PyPI portal for containing malicious code, once again highlighting how software package repositories are evolving into a popular target for supply chain attacks.
https://thehackernews.com/2021/07/several-malicious-typosquatted-python.html