Windows UEFI Bootkit in Rust by MemN0ps.
TLDR:- Bootkit that executes before ntoskrnl.exe and bypasses DSE using a simple .data pointer hook, sets up kernelmode manual mapper (redlotus.sys), controlled post-boot via a Rust-based use mode client.
https://t.co/YKY5KN6DAK
Ya biz muazzam bir A.I. etkinligi organize ediyoruz. Müthiş olacak! İstanbul'un göbeğinde teknik taktik konuşmalarla dolu harika bir gün hayal ediyorum!
Biletinizin alın abi bakın 300 TL bir kahve parası.
500 kişi limitimiz var ve şimdiden 50 bilet gitti. Benim ve bu yoldaki dostlarımın ne büyük bir öğrenci aşığı olduğumuz düşünülürse en fazla 300 kişi bilet alabilecek. 200 tane öğrenciye cebimizden hediye edicez.
Daha da kitabın ortasından konuşayım. Bu eventi sponsorla bile organize etmek istesek bilet parası 3-5k dan aşağı olmaz. Biz istiyoruz ki ya bi' kahve parası versin insanlar da gelsinler. 😘
Bana ve 20 yıldır bu hayattaki amacıma inanan şirketler, insanlar, kurumlar çıkacak ve sponsor olacaklardır. Eminim ben.
Daha da ortasından söyleyeyim. Şu etkinliği elden ele duyurmaya eli uzanmayanları, imtina edenleri de görüyorum. Biliyorum. Bu dostlarımızı evente kendim şahsen çağırıyor olacağım 😉😂
* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago.
* Full disclosure happening in less than 2 weeks (as agreed with devs).
* Still no CVE assigned (there should be at least 3, possibly 4, ideally 6).
* Still no working fix.
* Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot.
* Devs are still arguing about whether or not some of the issues have a security impact.
I've spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more.
Crowdstrike Analysis:
It was a NULL pointer from the memory unsafe C++ language.
Since I am a professional C++ programmer, let me decode this stack trace dump for you.
Here's CrowdStrike's advice if hosts are crashing:
1. Boot Windows into Safe Mode or the Windows Recovery Environment
2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
3. Locate the file matching “C-00000291*.sys”, and delete it.
4. Boot the host normally.
@bosunatiklama Bu tarz senaryolarda gönderici mail kısmında bulunan domain e çok hızlı bir şekilde whois sorgusu yapılabilir. Gün sonunda Gönderici Adı bir değişkendir. İlgili senaryo da gönderici adı Shopify yazmış olmasına rağmen bağlantılı olduğu domain 5 Nisan tarihinde alınmıştır.