IM
IronMonkey Threat Research
LIVE
|
Articles 27,186
|
CVEs 349,550
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,154 articles — Page 885 of 906
maxwelldulin ·

Crow is an async C++ HTTP/WebSocket library for creating flash web services. The framework implemented pipelining, which is async HTTP. This allows for different workers to get multiple HTTP...

maxwelldulin ·

Timestamps (block.timestamp) are used for logic. Actions such as sending ETH and entropy are common uses for timestamps because they create some randomness. Block timestamps are quite flexible,...

maxwelldulin ·

New Free DAO is a DeFi project hosted by the Binance Smart Chain (BSC). The New Free DAO contracts are not open source, making them hard to audit but a determined attacker could hit it still. The...

maxwelldulin ·

Wintermute is an Automated Market Maker (AMM). The hack wasn't anything that Wintermute actually did wrong. This time, it was a Vanity wallet generator called Profanity. Using this, it can...

Maxwell Dulin's Resources ·

The solution Aurora has built as an EVM implementation on NEAR is called the Aurora Engine, and it is implemented as a smart contract on the NEAR blockchain. This allows for EVM compatible...

Energy Healthcare and Public Health
Orange Cyberdefense ·

I built some infrastructure that you could deploy and use to easily tunnel from arbitrary sources over a proxy such as SOCKS, using anything that can run WireGuard. This is convenient in cases...

Information Technology
Kaspersky ICS CERT (English) ·

The UMAS protocol, in its implementation prior to the version in which the CVE-2021-22779 vulnerability was fixed, had significant shortcomings that had a critical effect on the security of...

Publications
Maxwell Dulin's Resources ·

Firecracker is an open source Virtual Machine Monitor (VMM) by AWS written in Rust. The purpose of this project is to allow for multi-tenant services to run on one machine. Firecracker is built on...

Information Technology
maxwelldulin ·

The Tesla charge port is vulnerable to a simple replay attack. The author of this post analyzed the signal deeper. Using GQRX, they captured the signal. From reading the FCC ID, this runs at...

Communications
maxwelldulin ·

The Titan M chip was put onto Pixels in 2018. This chips main purpose is to reduce the attack surface for attackers. This chip is on a separate SoC that runs its own special firmware and...

maxwelldulin ·

The package shell-quote's whole existence is around handling commands securely on the server-side. The main way the escaping was done, was via regex. The Regex had a hilarious bug in it. It was...

Blue Team Archives - Black Hills Information Security, Inc. ·

Noah Heckman // Windows Vista didn’t have many fans in the Windows community (to put it lightly). It beaconed in a new user interface, file structure, and a bunch of […] The post Why You Really...

Author Blue Team
Blue Team Archives - Black Hills Information Security, Inc. ·

Carrie Roberts // PowerShell’s Constrained Language (CLM) mode limits the functionality available to users to reduce the attack surface. It is meant to be used in conjunction with application...

Commercial Facilities Blue Team General InfoSec Tips & Tricks
Cloud Threat Landscape ·

On 2022-09-26, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.

Cloud Threat Landscape ·

Fast Company took its website offline after its content management system (CMS) was hacked to display stories and push out Apple News notifications containing obscene and racist comments.A...

maxwelldulin ·

The PS5 has a major bug bounty program. The author decided to look into this device, being a legend in the playstation hacking scene. After looking at the attack surface, they decided to look at...

maxwelldulin ·

Bitbucket is a service similar to Github. The authors of this post were after an RCE bug. Since they know that many platforms will end up with calls to git, they wanted a way to trace this. To...

Information Technology Nuclear
maxwelldulin ·

OneSev is a self-hosted Git server with many other features like CI/CD, code search and many other things. Since it is open source, this was a good target for an audit. A user is allowed to set...

Critical Manufacturing Energy
maxwelldulin ·

Roulette is an over the board game that is similar to Wheel of Fortune. Since these are spun by hand of the person running the board, the author asked "is this good randomness?" In the game, there...

Silver Fox Transportation Systems Government Facilities
maxwelldulin ·

FreeBSD supports asynchronous I/O (AIO) with POSIX syscalls. Naturally, with asynchronous actions, reference counts are important to make sure objects aren't deleted too early. The code path used...

maxwelldulin ·

Gitlab is version control with many other services, such as CI/CD and many other things. DecompressedArchiveSizeValidator is a function that is used to check the size of a archive before...

Wiz Blog | RSS feed ·

Recognition in the Cyber category honors Wiz for its exceptional technology partnership with one of the world’s leading financial institutions

Financial Services Information Technology
maxwelldulin ·

The author found a vulnerability with the usage of Linux containers and permissions. The standard Linux permissions are read (r), write (w) and execute (x). These permissions are put onto the...

Information Technology
Cloud Threat Landscape ·

A hacker reportedly stole ~11mil records of customer PII (dated 2017) from Optus, an Australian telco company. The data was disclosed and put on sale in late September 22’. According to...

Wiz Blog | RSS feed ·

Before it was patched, #AttachMe could have allowed attackers to access and modify any other users' OCI storage volumes without authorization, thereby violating cloud isolation. Upon disclosure,...

Information Technology
Wiz Blog | RSS feed ·

Leonid Belkind, CTO of Torq, and Itay Arbel, PM at Wiz, explain how organizations can build a coherent Cyber Security Incident Response Plan using Wiz CDR to analyze cloud events and threat alerts...

Information Technology
Kaspersky ICS CERT (English) ·

Events in the cybersecurity world, including ICS, were intense in H1 2022.

Critical Manufacturing Publications
Kaspersky ICS CERT ·

The statistical data presented in the report was received from ICS computers protected by Kaspersky products that Kaspersky ICS CERT categorizes as part of the industrial infrastructure at organizations.

Critical Manufacturing Publications
Curated Intelligence ·

Community Feature - @cPeterrIn this blog post, Curated Intelligence member Chuong Dong shared his findings after reverse engineering the PLAY ransomware's code obfuscation and encryption...

Commercial Facilities Financial Services
Cloud Threat Landscape ·

Beginning in early September 2022, an unknown threat actor successfully compromised tens of thousands of websites mainly aimed at East Asian audiences, redirecting hundreds of thousands of their...