Article: Ask and you shall receive - published over 9 years ago. Content: I get emails from readers asking for specific malware samples and thought I would make a mini post about it. Yes, I often obtain samples from various sources for my own research. I am sometimes too lazy/busy to post them but don't mind sharing. If you are looking for a particular sample, feel free to ask. I might have it. Send MD5 (several or few s... https://contagiodump.blogspot.com/2015/03/ask-and-you-shall-receive.html Published: 2015 03 09 01:08:00 Received: 2024 03 13 18:00:19 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
Article: Thousand ways to backdoor a Windows domain (forest) - published over 9 years ago. Content: When the Kerberos elevation of privilege (CVE-2014-6324 / MS14-068) vulnerability has been made public, the remediation paragraph of the following blog post made some waves: http://blogs.technet.com/b/srd/archive/2014/11/18/additional-information-about-cve-2014-6324.aspx "The only way a domain compromise can be remediated with a high level of certainty is... https://jumpespjump.blogspot.com/2015/03/thousand-ways-to-backdoor-windows.html Published: 2015 03 05 21:04:00 Received: 2023 03 31 10:02:48 Feed: Jump ESP, jump! Source: Jump ESP, jump! Category: Cyber Security Topic: Cyber Security |
|
Article: FREAK vulnerability weakens secure Web sites - published over 9 years ago. Content: http://www.livehacking.com/2015/03/04/freak/ Published: 2015 03 04 09:24:02 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
Article: WP-Slimstat vulnerability exposes WordPress websites to SQL injection attacks - published over 9 years ago. Content: http://www.livehacking.com/2015/02/25/wp-slimstat-vulnerability/ Published: 2015 02 25 11:37:19 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: Collection of Pcap files from malware analysis - published almost 10 years ago. Content: Update: Feb 19. 2015 We have been adding pcaps to the collection so remember to check out the folder ( Pcap collection) for the recent pcaps. I had a project to test some malicious and exploit pcaps and collected a lot of them (almost 1000) from various public sources. You can see them in the PUBLIC folder. The credits go to the authors of the pcaps lis... https://contagiodump.blogspot.com/2013/04/collection-of-pcap-files-from-malware.html Published: 2015 02 20 04:39:00 Received: 2023 03 31 08:41:26 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Article: iOS Masque Attack Revived: Bypassing Prompt for Trust and App URL Scheme Hijacking - published almost 10 years ago. Content: In November of last year, we uncovered a major flaw in iOS we dubbed “Masque Attack” that allowed for malicious apps to replace existing, legitimate ones on an iOS device via SMS, email, or web browsing. In total, we have notified Apple of five security issues related to four kinds of Masque Attacks. Today, we are sharing Masque Attack II in the ... https://www.fireeye.com/blog/threat-research/2015/02/ios_masque_attackre.html Published: 2015 02 19 19:00:00 Received: 2022 05 23 16:06:47 Feed: FireEye Blog Source: FireEye Blog Category: Cyber Security Topic: Cyber Security |
|
Article: Equation samples - from the Kaspersky Report and additional - published almost 10 years ago. Content: Here are a few samples from the report by Kaspersky Lab "Equation: The Death Star of Malware Galaxy" and additional samples of the same family. The full list is belowDownload all the samples listed below. Email me if you need the password (New link)List of filesFiles from the report:File NameMD5Size_SD_IP_CF.dll_03718676311DE33DD0B8F4F18CFFD48803718676311de3... http://contagiodump.blogspot.com/2015/02/equation-samples-from-kaspersky-report.html Published: 2015 02 17 06:22:00 Received: 2021 06 06 09:04:40 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Article: Google backpedals on its arbitrary vulnerability disclosure policy - published almost 10 years ago. Content: http://www.livehacking.com/2015/02/14/google-backpedals-on-its-arbitrary-vulnerability-disclosure-policy/ Published: 2015 02 14 10:58:46 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: 3004375 - Update for Windows Command Line Auditing - Version: 1.0 - published almost 10 years ago. Content: Revision Note: V1.0 (February 10, 2015): Advisory published.Summary: Microsoft is announcing the availability of an update for supported editions of Windows 7, Windows 8, Windows Server 2008R2 and Windows Server 2012 that expands the Audit Process Creation policy to include the command information passed to every process. This is a new feature that provides ... https://technet.microsoft.com/en-us/library/security/3004375 Published: 2015 02 10 18:00:00 Received: 2022 04 14 18:03:38 Feed: Latest Security Advisories Source: Latest Security Advisories Category: Alerts Topic: Vulnerabilities |
Article: Oracle Security Alert for CVE-2016-0603 - 5 February 2016
- published almost 10 years ago. Content: http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0603-2874360.html Published: 2015 02 05 19:30:54 Received: 2021 06 06 09:03:27 Feed: Oracle Security Alerts Source: Oracle Security Alerts Category: Alerts Topic: Vulnerabilities |
|
Article: Cross Site Scripting vulnerability found in IE 11 - published almost 10 years ago. Content: http://www.livehacking.com/2015/02/04/cross-site-scripting-vulnerability-found-in-ie-11/ Published: 2015 02 04 09:46:59 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: Blind Return Oriented Programming (BROP) Attack - published almost 10 years ago. Content: submitted by /u/turnersr [link] [comments] https://www.reddit.com/r/vrd/comments/2u7wxo/blind_return_oriented_programming_brop_attack/ Published: 2015 01 30 18:06:05 Received: 2021 06 06 11:29:11 Feed: Vulnerability Research and Development Source: Vulnerability Research and Development Category: Alerts Topic: Vulnerabilities |
Article: Apple updates iOS, OS X and Apple TV in monster patch release - published almost 10 years ago. Content: http://www.livehacking.com/2015/01/28/apple-updates-ios-os-x-and-apple-tv/ Published: 2015 01 28 12:56:01 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: Google discloses three more zero-day vulnerabilities, this time for OS X - published almost 10 years ago. Content: http://www.livehacking.com/2015/01/23/google-discloses-three-more-zero-day-vulnerabilities-this-time-for-os-x/ Published: 2015 01 23 07:45:27 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: Oracle Critical Patch Update Advisory - January 2015
- published almost 10 years ago. Content: http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html Published: 2015 01 20 19:30:54 Received: 2021 06 06 09:03:27 Feed: Oracle Security Alerts Source: Oracle Security Alerts Category: Alerts Topic: Vulnerabilities |
Article: The Devil is in the Constants: Bypassing Defenses in Browser JIT Engines by Michalis Athanasakis, Elias Athanasopoulos, Michalis Polychronakis, Georgios Portokalidis, and Sotiris Ioannidis [PDF] - published almost 10 years ago. Content: submitted by /u/turnersr [link] [comments] https://www.reddit.com/r/vrd/comments/2sppvi/the_devil_is_in_the_constants_bypassing_defenses/ Published: 2015 01 17 06:44:33 Received: 2021 06 06 11:29:11 Feed: Vulnerability Research and Development Source: Vulnerability Research and Development Category: Alerts Topic: Vulnerabilities |
|
Article: Preventing Use-after-free with Dangling Pointers Nullification by Byoungyoung Lee, Chengyu Song, Yeongjin Jang, and Tielei Wang [PDF] - published almost 10 years ago. Content: submitted by /u/turnersr [link] [comments] https://www.reddit.com/r/vrd/comments/2sppt4/preventing_useafterfree_with_dangling_pointers/ Published: 2015 01 17 06:43:25 Received: 2021 06 06 11:29:11 Feed: Vulnerability Research and Development Source: Vulnerability Research and Development Category: Alerts Topic: Vulnerabilities |
|
Article: Hacking freemium games - the evolution of PC game cheating - published almost 10 years ago. Content: This post is going to be a rather strange post compared to previous ones. But bear with me, in the middle of the post you will see why this post fits the IT security topic. I'm also terribly sorry for not posting recently, but I was busy with my SPSE and SLAE certification. Both are recommended for Python and Assembly noobs like me. But back to this post... https://jumpespjump.blogspot.com/2015/01/hacking-freemium-games-evolution-of-pc.html Published: 2015 01 14 19:47:00 Received: 2024 03 12 23:22:34 Feed: Jump ESP, jump! Source: Jump ESP, jump! Category: Cyber Security Topic: Cyber Security |
Article: Microsoft to fix Windows vulnerability that Google publicly disclosed last week - published almost 10 years ago. Content: http://www.livehacking.com/2015/01/13/microsoft-to-fix-windows-vulnerability-that-google-publicly-disclosed-last-week/ Published: 2015 01 13 07:43:54 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
Article: How I Evolved your Fuzzer: Techniques for Black-Box Evolutionary Fuzzing by Fabien Duchene [PDF] - published almost 10 years ago. Content: submitted by /u/turnersr [link] [comments]... https://www.reddit.com/r/vrd/comments/2s812x/how_i_evolved_your_fuzzer_techniques_for_blackbox/ Published: 2015 01 12 23:55:46 Received: 2021 06 06 11:29:11 Feed: Vulnerability Research and Development Source: Vulnerability Research and Development Category: Alerts Topic: Vulnerabilities |
|
Article: Video archives of security conferences and workshops - published almost 10 years ago. Content: Just some links for your enjoyment List of security conferences in 2014 Video archives: AIDE (Appalachian Institute of Digital Evidence) 2013 2012 2011 Blackhat 2012 or 2012 torrent Botconf 2013 Bsides BSides DC 2014 BSides Chicago 2014 BSides Nashville 2014 BSides Augusta 2014 BSides Huntsville 2014 BSides Las Vegas 2014 BSidesDE 2013 BSid... https://contagiodump.blogspot.com/2015/01/video-archives-of-security-conferences.html Published: 2015 01 05 04:11:00 Received: 2024 03 13 18:00:19 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Article: Episode #180: Open for the Holidays! - published almost 10 years ago. Content: Not-so-Tiny Tim checks in with the ghost of Christmas present: I know many of you have been sitting on Santa's lap wishing for more Command Line Kung Fu. Well, we've heard your pleas and are pushing one last Episode out before the New Year! We come bearing a solution for a problem we've all encountered. Ever try to delete or modify a file and receive an e... http://blog.commandlinekungfu.com/2014/12/episode-180-open-for-holidays.html Published: 2014 12 31 12:00:00 Received: 2023 03 31 08:44:32 Feed: Command Line Kung Fu Source: Command Line Kung Fu Category: News Topic: Security Tooling |
Article: Android Browser Cross Scheme Data Exposure + Intent Scheme Attack - published almost 10 years ago. Content: tl;dr This exploit is an issue present in Android browser < 4.4 and several other android browsers which allows an attacker to read sqlite cookie database file and hence exposing all cookies. Along with it we also talk about a Cross Scheme Data exposure attack in Android < 4.4. Introduction During my research on ASOP (Stock Browser) I found out th... http://www.rafayhackingarticles.net/2014/12/android-browser-cross-scheme-data.html Published: 2014 12 29 10:00:00 Received: 2024 02 17 13:21:47 Feed: Ethical Hacking - Rafayhackingarticles Source: Ethical Hacking - Rafayhackingarticles Category: Cyber Security Topic: Cyber Security |
|
Article: Bad Meets evil - PHP meets Regular Expressions - published almost 10 years ago. Content: twi This article would briefly discuss the reason why Regular Expressions might not be suitable for filtersand how things could turn miserably bad when PHP comes is used with Regular Expressions. The post would then continue with the write-up of a relevant scenario based challenge, and finally will conclude with the author’s opinion on the topic. Common... http://www.rafayhackingarticles.net/2014/12/bad-meets-evil-php-meets-regular.html Published: 2014 12 25 11:33:00 Received: 2024 02 17 13:21:47 Feed: Ethical Hacking - Rafayhackingarticles Source: Ethical Hacking - Rafayhackingarticles Category: Cyber Security Topic: Cyber Security |
Article: Apple updates OS X’s NTP server to address recently disclosed NTP vulnerabilities - published almost 10 years ago. Content: http://www.livehacking.com/2014/12/23/apple-updates-os-xs-to-address-ntp-vulnerabilities/ Published: 2014 12 23 08:39:04 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: Common Attacks Against Modems - published almost 10 years ago. Content: 0x01: Introduction to Modems The term DSL modem is technically used to describe "a modem which connects to a single computer, through a USB port or is installed in a computer PCI slot". The more common DSL router which combines the function of a DSL modem and a home router is a standalone device which could be connected to multiple computers through m... http://www.rafayhackingarticles.net/2014/12/common-attacks-against-modems.html Published: 2014 12 14 19:40:00 Received: 2024 02 17 13:21:47 Feed: Ethical Hacking - Rafayhackingarticles Source: Ethical Hacking - Rafayhackingarticles Category: Cyber Security Topic: Cyber Security |
|
Article: Microsoft fixes 24 security vulnerabilities in December’s Patch Tuesday - published almost 10 years ago. Content: http://www.livehacking.com/2014/12/10/microsoft-fixes-24-security-vulnerabilities-in-decembers-patch-tuesday/ Published: 2014 12 10 07:34:11 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
Article: OphionLocker. New ransomware on the scene - published almost 10 years ago. Content: This malware was discovered by a honeypot triggered during a malvertising campaign. The campaign used the RIG exploit kit. Interesting features of this ransomware: Uses elliptic curve cryptography for the encryption of files. (I believe this is the first ransomware to use such methods) Spread using an EK all variants were FUD at time ... http://trojan7malware.blogspot.com/2014/12/ophionlocker-new-ransomware-on-scene.html Published: 2014 12 09 19:46:00 Received: 2023 03 31 23:02:32 Feed: Trojan7Malware Source: Trojan7Malware Category: Cyber Security Topic: Cyber Security |
|
Article: Sony hack shows that the company kept passwords stored in a folder called “Password” - published almost 10 years ago. Content: http://www.livehacking.com/2014/12/05/sony-hacks-shows-that-the-company-kept-passwords-stored-in-a-folder-called-password/ Published: 2014 12 05 10:48:59 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
Article: Apple patches security flaws in iOS 8, OS X 10.10 and Apple TV 7 - published about 10 years ago. Content: http://www.livehacking.com/2014/11/18/apple-patches-security-flaws-in-ios-8-os-x-10-10-and-apple-tv-7/ Published: 2014 11 18 07:15:30 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: AlienSpy Java RAT samples and traffic information - published about 10 years ago. Content: AlienSpy Java based cross platform RAT is another reincarnation of ever popular Unrecom/Adwind and Frutas RATs that have been circulating through 2014. It appears to be used in the same campaigns as was Unrccom/Adwind - see the references. If C2 responds, the java RAT downloads Jar files containing Windows Pony/Ponik loader. The RAT is crossplatform and ... https://contagiodump.blogspot.com/2014/11/alienspy-java-rat-samples-and-traffic.html Published: 2014 11 17 21:16:00 Received: 2024 03 13 18:00:19 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Article: OnionDuke samples - published about 10 years ago. Content: Research: F-Secure: OnionDuke: APT Attacks Via the Tor Network Download Download. Email me if you need the password (new link) File attributes Size: 219136 MD5: 28F96A57FA5FF663926E9BAD51A1D0CB Size: 126464 MD5: C8EB6040FD02D77660D19057A38FF769 Size: 316928 MD5: D1CE79089578DA2D41F1AD901F7B1014 Vir... https://contagiodump.blogspot.com/2014/11/onionduke-samples.html Published: 2014 11 16 03:58:00 Received: 2024 03 13 18:00:20 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
Article: 3010060 - Vulnerability in Microsoft OLE Could Allow Remote Code Execution - Version: 2.0 - published about 10 years ago. Content: Revision Note: V2.0 (November 11, 2014): Advisory updated to reflect publication of security bulletin.Summary: Microsoft has completed the investigation into a public report of a vulnerability. We have issued Microsoft Security Bulletin MS14-064 to address this issue. For more information about this issue, including download links for an available security u... https://technet.microsoft.com/en-us/library/security/3010060 Published: 2014 11 11 18:00:00 Received: 2022 04 14 18:03:38 Feed: Latest Security Advisories Source: Latest Security Advisories Category: Alerts Topic: Vulnerabilities |
|
Article: Bypass hardware firewalls - published about 10 years ago. Content: This is just a collection of links about my DEF CON 22 presentation, and the two tools I released: Slides: http://www.slideshare.net/bz98/defcon-22-bypass-firewalls-application-white-lists-secure-remote-desktops-in-20-seconds Tools: https://github.com/MRGEffitas/Write-into-screen https://github.com/MRGEffitas/hwfwbypass Presentation video from Hacktivity:... https://jumpespjump.blogspot.com/2014/11/bypass-hardware-firewalls.html Published: 2014 11 09 14:05:00 Received: 2024 03 12 23:22:34 Feed: Jump ESP, jump! Source: Jump ESP, jump! Category: Cyber Security Topic: Cyber Security |
|
Article: Most businesses do not understand data breach risks - published about 10 years ago. Content: Research by HP has uncovered a lack of understanding among businesses of the risks associated with data breaches. More than 70% of US and UK executives surveyed by the Ponemon Institute said that their organisation does not understand fully the dangers of breaches, while less than half of top executives and board members are kept informed about the response ... https://penturalabs.wordpress.com/2014/11/07/most-businesses-do-not-understand-data-breach-risks/ Published: 2014 11 07 16:19:54 Received: 2021 06 06 09:04:46 Feed: Pentura Labs's Blog Source: Pentura Labs's Blog Category: Cyber Security Topic: Cyber Security |
|
Article: Using SystemTap to determine the exploitability of unbound memory overflows - published about 10 years ago. Content: submitted by /u/pwnwaffe [link] [comments] https://www.reddit.com/r/vrd/comments/2lkagk/using_systemtap_to_determine_the_exploitability/ Published: 2014 11 07 08:23:18 Received: 2021 06 06 11:29:11 Feed: Vulnerability Research and Development Source: Vulnerability Research and Development Category: Alerts Topic: Vulnerabilities |
Article: Wirelurker for OSX, iOS (Part I) and Windows (Part II) samples - published about 10 years ago. Content: PART II Wirelurker for Windows (WinLurker) Research: Palo Alto Claud Xiao: Wirelurker for Windows Sample credit: Claud Xiao PART I Research: Palo Alto Claud Xiao WIRELURKER: A New Era in iOS and OS X MalwarePalo Alto |Claud Xiao - blog post WirelurkerWirelurker Detector https://github.com/PaloAltoNetworks-BD/WireLurkerDetector Sample credit: Clau... https://contagiodump.blogspot.com/2014/11/wirelurker-for-osx-ios-part-i-and.html Published: 2014 11 07 01:57:00 Received: 2024 03 13 18:00:20 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Article: How Unified Device Management Is Critical to BYOD Enterprises - published about 10 years ago. Content: https://www.securitymagazine.com/articles/85876-how-unified-device-management-is-critical-to-byod-enterprises Published: 2014 11 01 04:00:00 Received: 2021 04 25 02:14:07 Feed: Security Magazine – Reports Source: Security Magazine Category: Reports Topic: Cyber Security |
|
Article: Email addresses stolen from CurrentC - published about 10 years ago. Content: http://www.livehacking.com/2014/10/31/email-addresses-stolen-from-currentc/ Published: 2014 10 31 10:07:54 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
Article: Research Reveals Cost of Online Fraud to UK - published about 10 years ago. Content: This week has been Get Safe Online Week and to coincide with the event, the National Fraud Intelligence Bureau researched cyber-crime in the UK. The research found that over the last year, the ten biggest online scams cost victims over £670m – although the actual figure is thought to be significantly higher than that due to unreported crimes. A separate poll... https://penturalabs.wordpress.com/2014/10/30/research-reveals-cost-of-online-fraud-to-uk/ Published: 2014 10 30 10:21:43 Received: 2021 06 06 09:04:46 Feed: Pentura Labs's Blog Source: Pentura Labs's Blog Category: Cyber Security Topic: Cyber Security |
|
Article: Kmart hit by card hack attack - published about 10 years ago. Content: It’s been revealed that a data breach at US retail chain Kmart that compromised card details lasted over a month. The discount department store said that the malware was discovered last week but had been operating since early September. Based on its investigation so far, the company said that it believes credit and debit cards were exposed but that no person... https://penturalabs.wordpress.com/2014/10/22/kmart-hit-by-card-hack-attack/ Published: 2014 10 22 15:20:17 Received: 2021 06 06 09:04:46 Feed: Pentura Labs's Blog Source: Pentura Labs's Blog Category: Cyber Security Topic: Cyber Security |
|
Click to Open Code Editor