19 Jan 2025, 08:50 UTC≈11,400 views23 reactionsread 12 August 2026 Forwarded from @malware_research
New blog on using CLR customizations to improve the OPSEC of your .NET execution harness. This includes a novel AMSI bypass that identified by author in 2023. By taking control of CLR assembly loads, we can load assemblies from memory with no AMSI scan.
https://securityintelligence.com/x-force/being-a-good-clr-host-modernizing-offensive-net-tradecraft/
Proof-of-concept for the AMSI bypass and an implementation of a…
⚡10❤8👍5
1 Jan 2025, 00:01 UTC≈10,800 views51 reactionsread 12 August 2026 Photo
Happy New Year! May every binary reveal its secrets, every challenge find its solution, and the Year of the Snake bring you stability, inspiration, and success!
👍21❤19🔥11
15 Nov 2024, 13:37 UTC≈12,900 views22 reactionsread 12 August 2026 Complete list of LPE exploits for Windows (starting from 2023)
https://github.com/MzHmO/Exploit-Street
#windows #expdev #lpe
❤13👍3🤯3🥱2🤣1
27 Sept 2024, 07:37 UTC≈12,400 views31 reactionsread 12 August 2026 Attacking UNIX Systems via CUPS, Part I
CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177 have been assigned around these CUPS issues.
CVSS 9.9
This remote code execution issue can be exploited across the public Internet via a UDP packet to port 631 without needing any authentication, assuming the CUPS port is open through your router/firewall. LAN attacks are also possible via spoofing zeroconf /…
🤣8❤7👍5😐4🔥2🥰2😁2🤯1
26 Sept 2024, 07:37 UTC≈9,490 views15 reactionsread 12 August 2026 0-Click exploit in MediaTek Wi-Fi chipsets affects routers and smartphones / Exploiting (CVE-2024-20017) 4 different ways
https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html
#expdev #poc
❤10👍4🔥1
3 Sept 2024, 10:58 UTC≈12,700 views18 reactionsread 12 August 2026 Native function and Assembly Code Invocation
https://research.checkpoint.com/2022/native-function-and-assembly-code-invocation/
#reverse #idapro
🔥11👍4🥰2🤝1
27 Aug 2024, 20:33 UTC≈8,280 views14 reactionsread 12 August 2026 Exploiting the Windows Kernel via Malicious IPv6 Packets (CVE-2024-38063)
https://malwaretech.com/2024/08/exploiting-CVE-2024-38063.html
#expdev #poc
👍12😍2
26 Aug 2024, 15:13 UTC≈8,590 views14 reactionsread 12 August 2026 POC for trigerring CVE-2024-38063 (RCE in tcpip.sys)
https://github.com/ynwarcs/CVE-2024-38063
#expdev #poc
❤10👍4
23 Aug 2024, 13:59 UTC≈6,910 views5 reactionsread 12 August 2026 C++ Unwind Exception Metadata: a Hidden Reverse Engineering Bonanza
https://www.msreverseengineering.com/blog/2024/8/20/c-unwind-metadata-1
#reverse #cpp #type #reconstruction #hints
🔥5
23 Aug 2024, 13:31 UTC≈5,800 views6 reactionsread 12 August 2026 V8 Sandbox escape/bypass/violation and VR collection
https://github.com/xv0nfers/V8-sbx-bypass-collection
#v8 #sandbox #escape
🔥6
23 Aug 2024, 13:01 UTC≈5,130 views9 reactionsread 12 August 2026 How to Bypass Golang SSL Verification
https://www.cyberark.com/resources/threat-research-blog/how-to-bypass-golang-ssl-verification
#golang #ssl #bypass #reverse #web #pentest
🤔5👏2❤1🔥1
22 Aug 2024, 10:55 UTC≈5,230 views7 reactionsread 12 August 2026 SGN is a polymorphic binary encoder for offensive security purposes such as generating statically undetecable binary payloads. It uses a additive feedback loop to encode given binary instructions similar to LSFR. This project is the reimplementation of the original Shikata ga nai in golang with many improvements.
https://github.com/EgeBalci/sgn
#redteam #golang
🔥3👍2🤔2
Showing the 12 most recent of 20 posts we hold for @R0_Crew. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.