Search results

  1. Depov

    SSRF vulnerability in CTF: bypassing filters in practice

    Intelligence: Searching for SSRF vulnerabilities in CTF tasks The first rule is not to pick the blind forms. SSRF hides anywhere the application accepts the URL and makes a server request for it. CWE-918 puts it this way: “the web server receives a URL or similar request from an upstream and...
  2. Depov

    Format string vulnerability: from %p to shell

    Virtual vulnerability mechanic: how one argument gives arbitrary read and write Format string attack occurs in exactly one scenario: the programmer transmits the user input to the first argument in printf() or a related function (sprintf, fprintf, snprintf, syslog). The function awaits a format...
  3. Depov

    How This Picture Could Hack You (.webP Exploit)

  4. Depov

    Windows Task Manager has learned to track neurochips. New columns show load on NPU and video card blocks

    The Windows task manager got a new opportunity: the system utility now shows which programs the neuroprocessor and specialized neural blocks of the graphics card use. The new metrics help to understand where Windows is sending AI computing, and to notice a situation where the application instead...
  5. Depov

    Are you hoping for an antivirus in the work network? SilkParasite spy campaign has proven the uselessness of standard scanners

    Bitdefender specialists discovered a long spy campaign against the state structures of Central Asia, in which the attackers used seven remote management programs. Five of them were not previously described anywhere, and some of the tools were probably created with the help of artificial...
  6. Depov

    Chinese hackers hit IBM reality show. 2 fake companies and 0 suspicions from Beijing's best burglars

    IBM specialists lured Mustang Panda hackers into fake corporate networks and watched their actions live for several days. The operators did not recognize the trap, deployed the previously unknown backdoor Havencode, sought credentials and in one case even stole specially prepared documents for...
  7. Depov

    Elite hackers attacked their own conference. One of them played and recorded the whole scheme

    Black Hat and DEF CON conference participants began to be lured into fake projects through Google Docs, and then try to infect their computers with malware. One of the targets was a Huntress specialist who recognized the deception and continued to communicate with the attacker to trace how the...
  8. Depov

    1 AI assistant instead of the encoder command. The neural network writes exploits and collects backdoors for Chinese hackers

    The Chinese-speaking group UAT-10147 has turned artificial intelligence from a code writing assistant into a full-fledged tool for attacks. Attackers instruct AI to look for vulnerabilities, prepare means of exploitation, check their work and help to fix themselves on servers, and the backdoor...
  9. Depov

    N4D is posing as the Linux kernel. Inside is a malware hunting PostgreSQL, MySQL, Redis

    The N4D malware continues to evolve and now uses open MCP servers as a starting point to penetrate infrastructure. Datadog Security Labs has discovered a new version of the malware go-titan, which itself is looking for available tools, launches commands and tries to spread to other systems. The...
  10. Depov

    CTF steganography: looking for hidden data in files

    Determine the real type of file: file utility and magic bytes The first rule of CTF steganography is not to trust the extension. File challenge.txt may be a PNG image, and photo.jpg – ZIP archive with flag inside. The authors of the Tasks replace the extensions constantly - cheap and angry, but...
  11. Depov

    SUID and sudo on CTF

    How SUID is Linux bit and why it is dangerous SUID (Set User ID) is a special bit of access rights that causes the Linux kernel to run a binary file not on behalf of the current user, but on behalf of the file owner. When the owner is root, any user of the system performs a binary with the...
  12. Depov

    SQL injection in CTF: from search to sqlmap

    Manual detection of sql injection in CTF assignment Searching for sql injections manually starts with one symbol – a single quotation mark. There is a form of login, search field or GET-parameter like ?id=1 – insert ' and look at the server reaction. It's not "try luck" is a diagnosis. By the...
  13. Depov

    Netcat and socat for CTF: Connections, Shells and Files

    Netcat: connection to remote server in CTF Netcat and pwn tasks – basic workflow Netcat (nc) is a utility for reading and writing data through TCP and UDP connections. It is often referred to as the “Swiss knife” of network utilities, and here without exaggeration: scanning ports, transferring...
  14. Depov

    0.01% Know How Malware REALLY Started

  15. Depov

    Is this The MOST Secure OS? (FBI Hates it)

  16. Depov

    Wireshark for CTF: looking for flags in PCAP

    Protocol Hierarchy – traffic map Menu Statistics → Protocol Hierarchy – the first window after downloading PCAP. Here you can see the percentage distribution of protocols by the number of packages and the volume of data. What to look for: Unencrypted protocols among the TLS array. In a typical...
  17. Depov

    Cryptography in CTF: Breaking RSA and classic ciphers

    Classic Ciphers: Cryptoanalysis in Crypto CTF Tasks Almost every Jeopardy-CTF includes a couple of tasks on classic wildcards. The point is to weed out those who do not know the basic tools. Spending more than five minutes on them is stealing time from the tucks, which give real points...
  18. Depov

    Grok hacked itself: the cipher forced AI to leak someone else's correspondence

    A regular request to retell the web page may end with the transmission of the history of Grok correspondence to a foreign server. Adversa AI researchers have found a way to hide malicious commands from protective filters with encryption, and then make Grok itself decrypt the instructions and...
  19. Depov

    The 22-year-old hacker forced Linux to spy on Apple Find My network

    The researcher managed to make Apple Find My work where the company does not officially provide for such an opportunity. A 22-year-old specialist under the pseudonym Zerotistic registered a computer with Linux in the Apple infrastructure as a compatible device, and then received and decrypted...
Top Bottom