Date Author Title

REMOTE CODE EXECUTION

2021-02-13Guy BruneauvSphere Replication updates address a command injection vulnerability (CVE-2021-21976) - https://www.vmware.com/security/advisories/VMSA-2021-0001.html
2013-02-16Lorna HutchesonFedora RedHat Vulnerabilty Released
2012-03-16Russ McReeMS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2011-08-11Guy BruneauBlackBerry Enterprise Server Critical Update
2010-05-12Rob VandenBrinkAdobe Shockwave Update
2010-03-10Rob VandenBrinkMicrosoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7

REMOTE

2022-10-07/a>Xavier MertensCritical Fortinet Vulnerability Ahead
2021-05-14/a>Xavier Mertens"Open" Access to Industrial Systems Interface is Also Far From Zero
2021-02-13/a>Guy BruneauvSphere Replication updates address a command injection vulnerability (CVE-2021-21976) - https://www.vmware.com/security/advisories/VMSA-2021-0001.html
2020-09-29/a>Xavier MertensManaging Remote Access for Partners & Contractors
2020-08-22/a>Guy BruneauRemote Desktop (TCP/3389) and Telnet (TCP/23), What might they have in Common?
2019-09-24/a>Xavier MertensHuge Amount of remotewebaccess.com Sites Found in Certificate Transparency Logs
2017-11-25/a>Guy BruneauExim Remote Code Exploit
2015-10-12/a>Guy BruneauCritical Vulnerability in Multiple Cisco Products - Apache Struts 2 Command Execution http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2
2013-09-18/a>Rob VandenBrinkCisco DCNM Update Released
2013-02-16/a>Lorna HutchesonFedora RedHat Vulnerabilty Released
2012-08-22/a>Adrien de BeaupreApple Remote Desktop update fixes no encryption issue
2012-03-16/a>Russ McReeMS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2011-11-28/a>Tom ListonA Puzzlement...
2011-11-19/a>Pedro BuenoDragon Research Group (DRG) announced the white paper entitled "VNC: Threats and Countermeasures" : https://dragonresearchgroup.org/insight/vnc-tac.html
2011-08-11/a>Guy BruneauBlackBerry Enterprise Server Critical Update
2010-12-19/a>Raul SilesIntel's new processors have a remote kill switch (Anti-Theft 3.0)
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote Access Tools
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN and Remote Access Tools
2010-05-12/a>Rob VandenBrinkAdobe Shockwave Update
2010-03-15/a>Adrien de BeaupreSpamassassin Milter Plugin Remote Root Attack
2010-03-10/a>Rob VandenBrinkMicrosoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2010-02-02/a>Guy BruneauCisco Secure Desktop Remote XSS Vulnerability
2009-11-14/a>Adrien de BeaupreMicrosoft advisory for Windows 7 / Windows Server 2008 R2 Remote SMB DoS Exploit released
2009-11-12/a>Rob VandenBrinkWindows 7 / Windows Server 2008 Remote SMB Exploit
2008-05-06/a>Marcus SachsIndustrial Control Systems Vulnerability
2008-03-13/a>Jason LamRemote File Include spoof!?
2006-11-20/a>Joel EslerMS06-070 Remote Exploit

CODE

2023-12-06/a>Guy BruneauRevealing the Hidden Risks of QR Codes [Guest Diary]
2023-07-28/a>Xavier MertensShellCode Hidden with Steganography
2023-03-16/a>Xavier MertensSimple Shellcode Dissection
2023-03-07/a>Johannes UllrichHackers Love This VSCode Extension: What You Can Do to Stay Safe
2022-11-04/a>Xavier MertensRemcos Downloader with Unicode Obfuscation
2022-09-14/a>Xavier MertensEasy Process Injection within Python
2022-05-30/a>Xavier MertensNew Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme (CVE-2022-30190)
2022-02-26/a>Guy BruneauUsing Snort IDS Rules with NetWitness PacketDecoder
2022-01-22/a>Xavier MertensMixed VBA & Excel4 Macro In a Targeted Excel Sheet
2022-01-20/a>Xavier MertensRedLine Stealer Delivered Through FTP
2022-01-06/a>Xavier MertensMalicious Python Script Targeting Chinese People
2022-01-05/a>Xavier MertensCode Reuse In the Malware Landscape
2021-12-10/a>Xavier MertensPython Shellcode Injection From JSON Data
2021-10-20/a>Xavier MertensThanks to COVID-19, New Types of Documents are Lost in The Wild
2021-08-20/a>Xavier MertensWaiting for the C2 to Show Up
2021-02-13/a>Guy BruneauvSphere Replication updates address a command injection vulnerability (CVE-2021-21976) - https://www.vmware.com/security/advisories/VMSA-2021-0001.html
2021-01-18/a>Didier StevensDoc & RTF Malicious Document
2020-10-14/a>Xavier MertensNicely Obfuscated Python RAT
2020-09-02/a>Xavier MertensPython and Risky Windows API Calls
2020-08-06/a>Xavier MertensA Fork of the FTCode Powershell Ransomware
2020-07-27/a>Didier StevensAnalyzing Metasploit ASP .NET Payloads
2019-12-12/a>Xavier MertensCode & Data Reuse in the Malware Ecosystem
2019-10-27/a>Didier StevensUsing scdbg to Find Shellcode
2019-07-08/a>Didier StevensMachine Code? No!
2019-07-04/a>Didier StevensMachine Code?
2019-05-31/a>Didier StevensRetrieving Second Stage Payload with Ncat
2019-05-30/a>Didier StevensAnalyzing First Stage Shellcode
2019-05-06/a>Didier StevensText and Text
2019-05-01/a>Xavier MertensAnother Day, Another Suspicious UDF File
2019-04-23/a>Didier StevensMalicious VBA Office Document Without Source Code
2019-03-24/a>Didier StevensDecoding QR Codes with Python
2019-02-25/a>Didier StevensSextortion Email Variant: With QR Code
2019-01-02/a>Didier StevensMaldoc with Nonfunctional Shellcode
2018-09-24/a>Didier StevensAnalyzing Encoded Shellcode with scdbg
2018-09-08/a>Didier StevensVideo: Using scdbg to analyze shellcode
2018-09-03/a>Didier StevensAnother quickie: Using scdbg to analyze shellcode
2018-08-31/a>Jim ClausingQuickie: Using radare2 to disassemble shellcode
2018-06-04/a>Rob VandenBrinkDigging into Authenticode Certificates
2017-04-16/a>Johannes UllrichTool to Detect Active Phishing Attacks Using Unicode Look-Alike Domains
2016-11-24/a>Didier StevensExtracting Shellcode From JavaScript
2016-11-18/a>Didier StevensVBA Shellcode and Windows 10
2016-09-26/a>Didier StevensVBA and P-code
2015-09-21/a>Xavier MertensDetecting XCodeGhost Activity
2015-03-30/a>Didier StevensYARA Rules For Shellcode
2013-10-25/a>Johannes UllrichPHP.net compromise aftermath: Why Code Signing Beats Hashes
2013-08-04/a>Johannes UllrichBBCode tag "[php]" used to inject php code
2013-02-16/a>Lorna HutchesonFedora RedHat Vulnerabilty Released
2012-07-19/a>Mark BaggettA Heap of Overflows?
2012-04-26/a>Richard PorterPacketstorm Security and Metasploit have Exploit code for MS12-027
2012-04-25/a>Daniel WesemannBlacole's shell code
2012-03-16/a>Russ McReeMS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2012-03-11/a>Johannes UllrichAn Analysis of Jester's QR Code Attack. (Guest Diary)
2011-08-11/a>Guy BruneauBlackBerry Enterprise Server Critical Update
2011-08-03/a>Johannes UllrichMalicious Images: What's a QR Code
2011-03-07/a>Bojan ZdrnjaOracle padding attacks (Codegate crypto 400 writeup)
2010-05-12/a>Rob VandenBrinkAdobe Shockwave Update
2010-03-10/a>Rob VandenBrinkMicrosoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2010-02-08/a>Adrien de BeaupreWhen is a 0day not a 0day? Fake OpenSSh exploit, again.
2009-08-08/a>Guy BruneauXML Libraries Data Parsing Vulnerabilities
2009-05-29/a>Lorna HutchesonVMWare Patches Released
2008-07-22/a>Mari Nichols‘Cold Boot’ Attack Utility Tools
2008-06-10/a>Swa FrantzenRansomware keybreaking

EXECUTION

2022-05-30/a>Xavier MertensNew Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme (CVE-2022-30190)
2021-02-13/a>Guy BruneauvSphere Replication updates address a command injection vulnerability (CVE-2021-21976) - https://www.vmware.com/security/advisories/VMSA-2021-0001.html
2017-11-25/a>Guy BruneauExim Remote Code Exploit
2015-10-12/a>Guy BruneauCritical Vulnerability in Multiple Cisco Products - Apache Struts 2 Command Execution http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2
2013-09-18/a>Rob VandenBrinkCisco DCNM Update Released
2013-02-16/a>Lorna HutchesonFedora RedHat Vulnerabilty Released
2012-03-16/a>Russ McReeMS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2011-08-11/a>Guy BruneauBlackBerry Enterprise Server Critical Update
2010-05-12/a>Rob VandenBrinkAdobe Shockwave Update
2010-03-10/a>Rob VandenBrinkMicrosoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2009-08-08/a>Guy BruneauXML Libraries Data Parsing Vulnerabilities
2009-05-29/a>Lorna HutchesonVMWare Patches Released