@bquintero Deja de propagar que las mujeres no son capaces por si solas de presentarse por su nivel, si una mujer quiere monta 10 virustotals, machismo puro y duro
1\ #MalwareAnalysis Evasion Tip: TLS Callback functions
Used by malware authors as windows will execute this function BEFORE the “start” of the program (as per PE header). This means when you load an exe into a disassembler, the malicious code has already run.
Created a small Python script to recover the 84 hashes of blacklisted extensions, names and paths of the #BlackMatter#ransomware.
All the hashes were cracked using a dictionary file created with config values from #Darkside samples.
https://t.co/b8SkicSBz9
This is neat, @cube0x8 has x64 support working for loadlibrary! That allows a native Linux process to dlopen() a 64-bit dll, really useful for fuzzing. Let us know if you want to help test.
https://t.co/QTAqL4V46C
I developed a Remote Code Execution PoC exploit for the Exim Use-After-Free that was recently disclosed (as part of @qualys 21Nails advisory). Tested just on Exim 4.92. PoC available: https://t.co/Su55rIZpgj
Desde Málaga para el mundo. “The choice of Malaga to host this new Google hub is not accidental. This region has great talent, a vibrant startup ecosystem and incubators and accelerators of companies that have been cultivating the technological...” https://t.co/rHbFtLIKOV
I were able in collaboration with @bl4sty to create a working Proof of Concept exploit for the new sudo CVE-2021-3156.
Tested just in Ubuntu 20.04.1 LTS, in other distros offsets may change. PoC available: https://t.co/kXYiNVV053
2021-01-25:🆕#REvil#Ransomware
Debug Version 2.0.3 Jan 11, 2021
"ver":515,"sub":"6545"
1⃣To reach more target files for encryption:
SetEveryoneAccess(...)➡️SetEntriesInAcl(...) API
2⃣'FakeGetProcAddress' to get the address of an exported function from DLL
h/t @malwrhunterteam
@es_ncl el día 23 de agosto publicasteis un tweet en el que decíais que este año había novedades importantes, una de ellas que la competición estaba abierta a estudiantes de ciclos formativos, sin especificar que solo para estudiantes de ciclos superiores.
Abro hilo
⬇️⬇️