Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Diaries by Keyword - SANS Internet Storm Center Diaries by Keyword


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title

COLD BOOT UTILITY CODE

2008-07-22Mari Nichols‘Cold Boot’ Attack Utility Tools

COLD

2013-10-04/a>Johannes UllrichThe Adobe Breach FAQ
2013-05-09/a>John BambenekAdobe Releases 0-day Security Advisory for Coldfusion, Exploit Code Available. Advisory here: http://www.adobe.com/support/security/advisories/apsa13-03.html
2013-01-05/a>Guy BruneauAdobe ColdFusion Security Advisory
2012-06-12/a>Swa FrantzenAdobe June 2012 Black Tuesday patches
2011-12-13/a>Johannes UllrichDecember 2011 Adobe Black Tuesday
2011-02-09/a>Mark HofmanAdobe Patches (shockwave, Flash, Reader & Coldfusion)
2010-02-02/a>Guy BruneauAdobe ColdFusion Information Disclosure
2009-07-05/a>Bojan ZdrnjaMore on ColdFusion hacks
2009-07-03/a>Adrien de BeaupreFCKEditor advisory
2009-07-02/a>Bojan ZdrnjaCold Fusion web sites getting compromised
2008-07-22/a>Mari Nichols‘Cold Boot’ Attack Utility Tools

BOOT

2013-11-22/a>Rick WannerPort 0 DDOS
2011-07-02/a>Pedro BuenoBootkits, they are back at full speed...
2010-11-01/a>Manuel Humberto Santander PelaezCheckpoint UTM-1 edge VPN boxes worldwide did an unscheduled reboot
2009-10-06/a>Adrien de BeaupreCyber Security Awareness Month - Day 6 ports 67&68 udp - bootp and dhcp
2008-07-22/a>Mari Nichols‘Cold Boot’ Attack Utility Tools

UTILITY

2008-07-22/a>Mari Nichols‘Cold Boot’ Attack Utility Tools

CODE

2019-07-08/a>Didier StevensMachine Code? No!
2019-07-04/a>Didier StevensMachine Code?
2019-05-31/a>Didier StevensRetrieving Second Stage Payload with Ncat
2019-05-30/a>Didier StevensAnalyzing First Stage Shellcode
2019-05-06/a>Didier StevensText and Text
2019-05-01/a>Xavier MertensAnother Day, Another Suspicious UDF File
2019-04-23/a>Didier StevensMalicious VBA Office Document Without Source Code
2019-03-24/a>Didier StevensDecoding QR Codes with Python
2019-02-25/a>Didier StevensSextortion Email Variant: With QR Code
2019-01-02/a>Didier StevensMaldoc with Nonfunctional Shellcode
2018-09-24/a>Didier StevensAnalyzing Encoded Shellcode with scdbg
2018-09-08/a>Didier StevensVideo: Using scdbg to analyze shellcode
2018-09-03/a>Didier StevensAnother quickie: Using scdbg to analyze shellcode
2018-08-31/a>Jim ClausingQuickie: Using radare2 to disassemble shellcode
2018-06-04/a>Rob VandenBrinkDigging into Authenticode Certificates
2018-02-12/a>Didier StevensAnalyzing compressed shellcode
2017-04-16/a>Johannes UllrichTool to Detect Active Phishing Attacks Using Unicode Look-Alike Domains
2016-11-24/a>Didier StevensExtracting Shellcode From JavaScript
2016-11-18/a>Didier StevensVBA Shellcode and Windows 10
2016-09-26/a>Didier StevensVBA and P-code
2015-09-21/a>Xavier MertensDetecting XCodeGhost Activity
2015-03-30/a>Didier StevensYARA Rules For Shellcode
2013-10-25/a>Johannes UllrichPHP.net compromise aftermath: Why Code Signing Beats Hashes
2013-08-04/a>Johannes UllrichBBCode tag "[php]" used to inject php code
2013-02-16/a>Lorna HutchesonFedora RedHat Vulnerabilty Released
2012-07-19/a>Mark BaggettA Heap of Overflows?
2012-04-26/a>Richard PorterPacketstorm Security and Metasploit have Exploit code for MS12-027
2012-04-25/a>Daniel WesemannBlacole's shell code
2012-03-16/a>Russ McReeMS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2012-03-11/a>Johannes UllrichAn Analysis of Jester's QR Code Attack. (Guest Diary)
2011-08-11/a>Guy BruneauBlackBerry Enterprise Server Critical Update
2011-08-03/a>Johannes UllrichMalicious Images: What's a QR Code
2011-03-07/a>Bojan ZdrnjaOracle padding attacks (Codegate crypto 400 writeup)
2010-05-12/a>Rob VandenBrinkAdobe Shockwave Update
2010-03-10/a>Rob VandenBrinkMicrosoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2010-02-08/a>Adrien de BeaupreWhen is a 0day not a 0day? Fake OpenSSh exploit, again.
2009-08-08/a>Guy BruneauXML Libraries Data Parsing Vulnerabilities
2009-05-29/a>Lorna HutchesonVMWare Patches Released
2008-07-22/a>Mari Nichols‘Cold Boot’ Attack Utility Tools
2008-06-10/a>Swa FrantzenRansomware keybreaking