Finished in 1st place at the Red Team CTF @ #DEFCON 31. @RedTeamVillage_
Started off playing the event solo, but I was joined in the finals by my fellow teammates from Team Europe, @sijsu and @s3np41k1r1t0 to get the win.
Thank you ThreatSims and @hackthebox_eu for the event!
Snake Yara detections have been added to MemProcFS memory forensics! Detect snake implants and other evil (such as cobalt strike) in notime with MemProcFS FindEvil!
Thank You @msuiche ๐
https://t.co/inOM3l1GIF
If you hadn't heard about this:
There is a debug build of some OG Xbox game that was found in an encrypted RAR. This password only took the small community less than a week to crack.
The @hashtopolis server peaked at 7517.92kh/s. That's equivalent to 75 Nvidia 3090 GPUs.
Today, I went looking for love ๐๐ฅฐ
I ended up finding (what appears to be) a new macOS backdoor/updater component: 'iWebUpdate' ...which has been around, undetected for 5 years! ๐๐พ๐
Read:
"Where there is love, there is ...malware?"
https://t.co/f6ShhiTaMf
@defcon The end result was this!
We successfully MITM-ed the badge communication and were able to reverse engineer the badge-badge communication. We were then able to emulate the badges with Python.
I wrote an IDA plugin that queries #ChatGPT and explains decompiled functions. It's still very bleeding edge, but you can find the code here and try it out:
https://t.co/lEelTimzvt
(Yes, the video was performed on a very basic case for simplicity's sake.)
I'll be teaching this tonight. Should be fun.
Everyone will be able to walk away able to scan for this exploit in their environment and then show how it can be weaponized to help give you the ability to patch for it.