🔥Malware Analysis with @HuntressLabs 🔥
Watch as we analyse a bloated (1.5GB) Golang file and dynamically extract an Xworm payload.
We'll touch on Procmon, Process Hacker, Entropy Analysis, Debloating, Breakpoints, Debuggers and lots more🤠
[1/14] 🧵
#Malware#Golang
Do you want to learn YARA to track malware but don't know where to start?
In anticipation of #100DaysofYARA we're giving away 3 free seats to AND's YARA Course!
To enter, reply to this tweet with what malware you want to track. Most creative responses by Friday 2023-11-24 win!
How I dropped a crit 0day XXE to full read SSRF in less than 6 hours.
- Pentest customer had a 3rd party paid software that looked promising, IIS + Java + some jsp public files.
- Googled some time ago and couldn't find a copy.
- Last month I found .iso links in a Chinese forum 👀
- After unzip some installers inside a .cab file I found finally all public facing files.
- I spent a bunch of hours looking for JSP files and nothing promising, then I decided to import the META-INF directory with all .classes from Java to be decompiled with Jadx-UI
- I found more attack surface looking for @WebServlet({"path"})
- Since they were many and I was too lazy, I just copy pasted each servlet into ChatGPT and asked to craft HTTP Requests to this code
- After going through multiple Servlets I was stuck with what it was looking to be a blind SSRF; then I saw a POST in the same servlet that was checking a XML content-type
- Then the crafted HTTP Request was sent to burp scanner to just fuzz XXE payloads, it popped up instantly.
- After some digging it resulted in Java 1.8 with file:// or netdoc disabled (I would have loved to get keys from web.config and try some viewstate RCE), anyways I was able to leak the aws metadata through SSRF.
- Checked in https://t.co/1lWNjRYq0q and roughly 500-1k customers from many companies were affected, vendor was notified and issuing a patch soon.
Just read the blog posts from @infosec_au it will improve drastically your white box skills :)
Everything you need to become a skilled Web3 Security Researcher.
→ 12 MORE hours of the free @intogateway Web3 Security Course ←
Totaling 23+ hours of EVERYTHING Web3 Security + curated projects & assignments to solidify the knowledge.
Here's everything in Part 2️⃣ 🧵
I am pleased to announce new version of Open Source Surveillance. It includes new GUI, icons, charts and completely fresh engine. Register and try it on https://t.co/sXiTUvAmZt Demo version includes Flickr and Surveillance Cameras. #OSINT#intelligence#privacy#infosec
Okta was breached via their support infrastructure yet again. This time, they only found out because of a customer escalation, which they failed to act on for at least 16 days 🤯. A 🧵 of my takeaways... 1/n https://t.co/70Sdk5EyBx
Three resources I always recommend to new security researchers:
• Patrick's Courses: To get you started
• Secureum: To get a broad perspective
• DefiHackLabs: To study from real exploits
To this day, these 3 have shaped my progress & impacted my success more than any other.
How to stand out as a solo auditor:
- find bugs
- write poc's for all your findings
- constantly share your story
- seek constructive feedback
- have transparent pricing
- come up with quotes quickly
- always learn new stuff
- consistently push yourself out of your comfort zone
- connect with auditors you admire & learn from their experience
- give back to the community by helping beginners
https://t.co/ZAXhqYZEYy
Search in data leaks database (14, 491, 682, 918 records) by:
First/Last name
Password
IP Address
Phone
VIN
City
and other fields.
(use of the service may violate the laws of your country)
I am immensely proud of my husband’s incredible journey with HIBP. From its modest beginnings, HIBP has evolved into an indispensable resource for millions worldwide, all thanks to @troyhunt unwavering dedication to cyber security. https://t.co/bF3TKOCnlM