SilentMoonwalk – PoC Implementation Of A Fully Dynamic Call Stack Spoofer
PoC Implementation of a fully dynamic call stack spoofer TL;DR SilentMoonwalk is a PoC implementation of a fully dynamic call stack spoofer, implementing a technique to remove the original caller from the call stack, using ROP to desynchronize unw…
Mifare Desfire authentication process / cloning protection
I am trying to write a small explanation for a customer, who wants to understand why his Mifare Desfire transponders are safe from being cloned.
I was trying to search for an easy scheme or text that explains how the authetication process …
Taiwanese PC Company MSI Falls Victim to Ransomware Attack
Taiwanese PC company MSI (short for Micro-Star International) officially confirmed it was the victim of a cyber attack on its systems.
The company said it “promptly” initiated incident response and recovery measures after detecting “network anomalies.”…
Iran-Based Hackers Caught Carrying Out Destructive Attacks Under Ransomware Guise
The Iranian nation-state group known as MuddyWater has been observed carrying out destructive attacks on hybrid environments under the guise of a ransomware operation.
That’s according to new findings from the Microsoft Threat Intelligence team, which …
Apple Releases Updates to Address Zero-Day Flaws in iOS, iPadOS, macOS, and Safari
Apple on Friday released security updates for iOS, iPadOS, macOS, and Safari web browser to address a pair of zero-day flaws that are being exploited in the wild.
The two vulnerabilities are as follows –
CVE-2023-28205 – A use after free issue in WebK…
Researchers Discover Critical Remote Code Execution Flaw in vm2 Sandbox Library
The maintainers of the vm2 JavaScript sandbox module have shipped a patch to address a critical flaw that could be abused to break out of security boundaries and execute arbitrary shellcode.
The flaw, which affects all versions, including and prior to …
[webapps] Icinga Web 2.10 – Arbitrary File Disclosure
Icinga Web 2.10 – Arbitrary File Disclosure
[webapps] X2CRM v6.6/6.9 – Stored Cross-Site Scripting (XSS) (Authenticated)
X2CRM v6.6/6.9 – Stored Cross-Site Scripting (XSS) (Authenticated)
[webapps] Restaurant Management System 1.0 – SQL Injection
Restaurant Management System 1.0 – SQL Injection