Microsoft has significantly expanded the ability of Windows 11 to recover independently: the computer can now get a fix itself if it stopped booting, returning to the state a few hours ago or completely reinstalling the system along with the right drivers from the cloud. The company combined new...
What do you need to disassemble programs
For reverse engineering from scratch, three components will suffice: Ghidra, Java Development Kit and virtual machine. Read more in our article on binary vulnerability analysis.
Ghidra – free disassembler (translates machine code into assembly...
Ret2win: basic operating equipment buffer overflow
Ret2win is the simplest binary operating scenario on CTF. In the binary is a function (usually win(), flag(), shell()), which no one causes. The task is to overwhelm the buffer on the stack, overwrite the return address of this function and...
The developer gave Claude the task of checking the implementation of corporate login through SAML and for a month found vulnerabilities that allowed you to enter other people's accounts, disclose data and disable services. Some of the problems found have not yet been corrected.
The technical...
The critical vulnerability of GitLab did not have time to stay public and two days before it began to be used in real attacks. The problem of CVE-2026-19478 (9.7 Critical) allows you to change and delete publicly available projects and user data without an account, and after the demo code...
Google has started to distribute a new mode to Android for users who want to install apps from developers without a confirmed identity. The company retained the freedom of installation, but it will not be possible to enable such a mode instantly: before lifting the restriction, the smartphone...
Hackers have started using a critical Windows vulnerability that allows you to remotely run code on a computer without an account and any action on the part of the user. The U.S. Cybersecurity and Infrastructure Protection Agency (CISA) confirmed the real attacks and required the U.S. federal...
Armored Likho has noticeably rebuilt its malicious arsenal and began using the new remote access Trojan BusySnake RAT, capable of working in Windows, Linux and macOS. Kaspersky experts discovered three versions of the malware at once and traced how the developers consistently changed the...
One transition through a specially prepared link was enough for Microsoft Copilot Personal to start reading the connected mail, calendar and files without additional actions, and then send the found data to an external server. Varonis Threat Labs called the CoSnitch vulnerability chain.
The...
Determination of the type of hash before starting John
Before you start hacking the John the Ripper hash, you need to understand what exactly lies in the file. The automatic definition of the format in John works, but not always correct. On the CTF, I saw situations where John defined...
What you need to know about Burp Suite before the first web CTF
Burp Suite is an intercept proxy and a set of tools for analyzing web traffic, sharpened to search for vulnerabilities of web applications. For a CTF player on a web category, this is the main working tool. Without it, half of the...
SvelteKit developers are preparing a major framework update and simultaneously promoting a new approach to data exchange between the browser and the server. The focus was on remote functions, allowing you to call server logic almost as ordinary functions directly from the components, maintaining...
The service of searching people ClarityCheck promised to users private and safe checking of photos, but more than 9 million files with adults and children were available on the Internet without a password.
The problem was discovered by the security specialist Jeremaya Fowler. According to him...
The American telecommunications and media company Comcast taught home Wi-Fi to notice movement without cameras and individual sensors. The WiFi Motion feature analyzes the changes in the radio signal between the router and the connected devices and alerts the owner to the activity in the house...
SSRF Mechanics Attacks on Web Application
Web applications constantly go for data to other servers: download previews at the link, check the presence of the product through the internal API, generate PDF from custom HTML. Server-Side Request Forgery (CWE-918 by MITRE classification) occurs when...
Why CTF player multiplexer terminal
A typical CTF session is simultaneous operation in four or six terminals. In one, the port scanner spins, in the second, the listing of directories, the third listens to the incoming shell, in the fourth, notes are written or the exploit is launched. Without...