🍞BAKING 🍞
I had a ton of people ask me about the super cool and badass malware sample my beloved colleague sent me. I also had a ton of people me to share more details on it.
Here are some FAQ:
1. What does it do?
It's an Information Stealer, but it's super fancy
2. Does it have a name?
Yes, as of like, last Tuesday (I have no idea when it was named, I'm just talking shit). It's officially called RevStealer by my peers. There is limited information it at the moment.
3. How long have you been bonking it?
I invested about 4 hours over the time span of a few days, I think. I wish I had more free time for bonkings, but I don't
4. Can you share it?
Yes, I am sharing it now. I'm pushing it to prod now. It's under /Samples/Families/RevStealer. I encourage you to bonk it too. It's really cool and fun to explore. I haven't had enough time to explore it and appreciate it, but I enjoyed it.
5. Can you share hashes?
Initial .zip:
251aa2b0831d88a6f796bb6ca01d0242c11476b2fc6a5baa3f9c64a9134cd61d
Stage 1 (packer, stager): d23b9609b06ab23243543ee0d8ff0d4c1966530576fa37bb2ecde97309ebbc9e
Stage 2 (in-memory payload):
724b400afcec2064a3477abd9a117103abfb51f7f7c8acd9c429fcdabd656ffc
Decoy (maybe?):
851383fb22dcb1d16367839178271eef6504199b8ca60405e1698879696e49d4
6. Who is it attributed to?
I have no idea. My colleagues have speculations, but nothing is solid yet.
Pic unrelated (or maybe it is).
التقرير رُفع فوراً للجهة المعنية وتم الترقيع بنجاح. الحل الجذري الذي أوصيت به: استبدال التسمية بمعرفات عشوائية معقدة كـ UUIDv4 مع فرض فحص الملكية والصلاحيات من طرف السيرفر (Server-side ownership checks) في كل طلب
مساكم الله بالخير جميعاً ✋ حبيت أشارككم اليوم Write-up سريع ومختلف: كيف قادتني "ثانية واحدة" لتخطي كل القيود المفروضة في منصة والوصول لمستنداتها المحجوبة
كواليس فحص أمني (Security Audit) ركزت فيه على عقلية الـ Logic Flaws وكيف تحولت ملاحظة بسيطة إلى Critical IDOR.
الثغرة هنا هي Broken Access Control فادحة. الحظر مطبق كـ "ديكور" على الـ UI فقط، بينما السيرفر في الـ Backend لا يفحص صلاحية من يطلب الملف.
التصنيف: Critical
CWE-639: Authorization Bypass Through User-Controlled Key
OWASP Top 10: Broken Access Control
الحمدلله دائماً وأبداً.... وحش الويب ال eWPTX v3 صارت في الجيب
مرحلة كنت أشوفها حلم بعيد وصعب في بداياتي ، اليوم قلت اختبر نفسي و صارت واقع بعد ساعات طويلة تجاوزت أقوى اختبار اختراق ويب متقدم من @Inesecurity، والقادم أجمل بإذن الله🎁.
#eWPTXv3#Cybersecurity#INE