https://t.co/pWpa1tp2KX
Hey guys, I posted a really cool zine in pure TXT about Unhooking Linux EDR, attacking the cleanup_module function, to be able to remove any hook from an EDR for example. Feel free to read.
I'm happy to share that I received an €800 reward for a vulnerability report in a Kaspersky Endpoint Security for Linux program, submitted through Yogosha. After further review, the report was reassessed and the value of the research was recognized.
#linux#bugbounty
Today my new Hack The Box Sherlock, ShadowMonarch, was officially published. Its a hard-level malware analysis challenge, and Im really excited to finally share it with you all.
https://t.co/IgkbmlFEKC
#backdoor#malware#linux#apt
> be @github
> be acquired by @Microsoft
> get annoyed because @ChaoticEclipse0 published 0-days or because @xploitrsturtle2 published github's compromise evidences / proofs that github was successfully breached
> start a ban-wave targeting any "hacker related profile"
> ban me on Monday around 4am without any notices
> let my appeal ticket rot forever under some infinite SLA with zero explanation for the ban
> lock me out from updating dozens of open-source repos i contribute to
dude, i know i don’t have a profile full of followers, stars, famous projects or hype-driven repos, and i’m still learning so i can publish better work, but what kind of insane policy is this?
randomly banning security researchers with no warning, no reason, not even a basic email explaining what happened, just because @msftsecresponse has beef with some other security researcher? are triagers’ egos really that weak?
i’ve already seen multiple people on X getting hit by the same thing (like @yebtimothy, @MiroslavSraga, @CollinsCaxton4, @wavey0x and another guy that i forgot his username here on X), so i’m definitely not the only one.
now imagine everyone else who doesn’t want to go public and is just taking this garbage silently, GEEZ
Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window
Full research: https://t.co/bZFOyMptG5
#rootkit#linux#edr#poc
Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window
Full research: https://t.co/bZFOyMptG5
#rootkit#linux#edr#poc
I analyzed Trend Micro Deep Security Agent for Linux and found that a local event storm can force bmhook/tmhook reload cycles, opening a repeatable temporary protection bypass window.
Full write-up:
https://t.co/bZFOyMptG5
#linux#edr#rootkit#cybersec#security#research
Kernel Rootkit is a new Telegram community for Linux/Windows rootkit research, ring0/ring3, stealth, defense, forensics and reverse engineering.
Join us, share knowledge and collaborate.
https://t.co/pZNOWPT2FF
#rootkits#security#windows#linux#cyber#malware#forensics
I analyzed Trend Micro Deep Security Agent for Linux and found that a local event storm can force bmhook/tmhook reload cycles, opening a repeatable temporary protection bypass window.
Full write-up:
https://t.co/bZFOyMptG5
#linux#edr#rootkit#cybersec#security#research
Linux Kaspersky 0day: unloading LKMs directly from userspace.
Kaspersky rejected my report, so I'll be publishing the full technical write-up soon
#Linux#Kernel#0day#VulnerabilityResearch
We're looking for a cover for the next issue of Phrack!
Retro sci-fi, terminals, dystopian systems, chrome futures, hacker manuals from an alternate timeline.
Make something timeless and strange.
Send your work or idea to [email protected]
Deadline June 30th
Phrack wants your art!
The theme for this issue is retro sci-fi / old-school cybernetic futures.
CRT glow, vector grids, space paranoia, BBS aesthetics, analog cyberpunk, forgotten futures. But we accept all kinds of contributions :)
ANSI, illustration, collage, renders, weird experiments.
Send it to: [email protected]
Deadline June 30th
@heyZeus131313 You're mixing unrelated things. Residential proxies explain IP origin, not who wrote the code. The rootkits mentioned are Brazilian, and there are others as well this is about authorship and technical scene, not attack location.
Brazil is a Linux kernel rootkit factory.
Diamorphine, Brokepkg, KoviD, Reptile and now Singularity. Some of the most well-known Linux kernel rootkits came from Brazilian researchers.
Brazil has a crazy strong scene in linux rootkit development