[Exploitation]
⦿ Playing in the (Windows) Sandbox - Alex Ilgayev
https://research.checkpoint.com/2021/playing-in-the-windows-sandbox/
⦿ Bug discovery diaries: Abusing VoIPmonitor for Remote Code Execution - Alfred Farrugia
⦿ Constraint-guided Directed Greybox Fuzzing - Gwangmu Lee & Woochul Shim
https://lifeasageek.github.io/papers/gwangmu-cafl.pdf
⦿ Exchange attack chain CVE-2021-26855&CVE-2021-27065 analysis - HuanGMz
https://paper.seebug.org/1501/
⦿ CVE-2021-1732: win32kfull xxxCreateWindowEx callback out-of-bounds - iamelli0t
https://iamelli0t.github.io/2021/03/25/CVE-2021-1732.html
⦿ macOS: Integer overflow in CoreGraphics leading to out-of-bounds write when rendering fonts - Ivan Fatric
https://bugs.chromium.org/p/project-zero/issues/detail?id=2130
⦿ ProxyLogon vulnerability analysis - Mail Exchange RCE (Perfect combination CVE-2021–26855 + CVE-2021–27065) - Jang
⦿ One day short of a full chain: Part 1 - Android Kernel arbitrary code execution - Man Yue Mo
https://securitylab.github.com/research/one_day_short_of_a_fullchain_android
⦿ One day short of a full chain: Part 2 - Chrome sandbox escape - Man Yue Mo
https://securitylab.github.com/research/one_day_short_of_a_fullchain_sbx
⦿ Alternative Code Execution - S4R1N
https://github.com/S4R1N/AlternativeShellcodeExec
⦿ Using Syscalls to Inject Shellcode on Windows - solomonsklash
https://www.solomonsklash.io/syscalls-for-shellcode-injection.html
⦿ Exploiting XPC in AntiVirus - Wojciech Regula & Csaba Fitzl
https://www.slideshare.net/CsabaFitzl/exploiting-xpc-in-antivirus
⦿ EXPRACE: Exploiting Kernel Races through Raising Interrupts - Yoochan Lee & Chanwoo Min
https://lifeasageek.github.io/papers/yoochan-exprace.pdf
[Web]
[Network]
[Cyber Operation, Malware]
⦿ New Mirai Variant Targeting Network Security Devices - Vaibhav Singhal, Ruchna Nigam
https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities
[리버싱, 펜테스팅, 분석]
⦿ Detecting Manual Syscalls from User Mode - jack-ullrich
https://winternl.com/detecting-manual-syscalls-from-user-mode/
⦿ How to extract Python source code from Py2App packed Mach-O Binaries - taha karim
[CTF, Wargame]
[기타]
[툴]
'기타' 카테고리의 다른 글
주요 뉴스 (2021.04 - 2주) (0) | 2021.04.20 |
---|---|
주요 뉴스 (2021.03 - 5주) (0) | 2021.04.01 |
주요 뉴스 (2021.03 - 3주) (0) | 2021.03.18 |
주요 뉴스 (2021.03 - 2주) (0) | 2021.03.16 |
주요 뉴스 (2021.03 - 1주) (0) | 2021.03.08 |