TheShadowBrokers

InfoSec Week 6, 2018

A buffer overflow vulnerability in older Starcraft version enabled modders to create new maps, so Blizzard tasked reverse engineer to safely emulate the bug in the newer, fixed version. The author says it all: 'This is a tale about what dedication to backward compatibility implies.'

Posted

#Weekly-News

InfoSec Week 19, 2017

You have probably heard about the WannaCry/WannaCrypt/WannaWhatever worm spreading ransomware, because of the sensation created by parties profiting from the scare tactics. But also because it is using really good spreading technique - exploiting MS17-010 SMB vulnerability leaked from the NSA. Some post-mortem analysis of the first version (with the killswich) and TheShadowBrokers blog are listed below. Crypto is working, so no trivial decrypter is probable, except if the keys are published.

Posted

#Weekly-News

InfoSec Week 15, 2017

Interesting blog about the generic unpacking of the Locky malware using Radare r2pipe, python and the Windows 7 VM.

Posted

#Weekly-News

InfoSec Week 14, 2017

The Cisco Talos team has analyzed ROKRAT remote administration tool targeting South Koreans by spear phishing campaign.

Posted

#Weekly-News