r0 Crew (Channel)

Description
Security Related Links:
- Reverse Engineering;
- Malware Research;
- Exploit Development;
- Pentest;
- etc;

Join to chat: @r0crew_bot 👈

Forum: https://forum.reverse4you.org
Twitter: https://twitter.com/R0_Crew
Advertising
We recommend to visit

Community chat: https://t.me/hamster_kombat_chat_2

Twitter: x.com/hamster_kombat

YouTube: https://www.youtube.com/@HamsterKombat_Official

Bot: https://t.me/hamster_kombat_bot
Game: https://t.me/hamster_kombat_bot/

Last updated 2 months, 1 week ago

Your easy, fun crypto trading app for buying and trading any crypto on the market

Last updated 2 months ago

Turn your endless taps into a financial tool.
Join @tapswap_bot


Collaboration - @taping_Guru

Last updated 2 weeks, 4 days ago

1 year, 2 months ago

Finding and exploiting process killer drivers with LOL for 3000$

In this article, I will introduce some kernel driver/internals theory and explain how to use the data in LOLDrivers to find interesting drivers. Finally, I will present 2 examples of vulnerable drivers and explain how to quickly reverse them and create a PoC to exploit them.

https://alice.climent-pommeret.red/posts/process-killer-driver/

#redteam #loldrivers #windows

alice.climent-pommeret.red

Finding and exploiting process killer drivers with LOL for 3000$

This article describes a quick way to find easy exploitable process killer drivers. There are many ways to identify and exploit process killer drivers. This article is not exhaustive and presents only one (easy) method. Lately, the use of the BYOVD technique…

1 year, 2 months ago

Living Off The Land Drivers is a curated list of Windows drivers used by adversaries to bypass security controls and carry out attacks. The project helps security professionals stay informed and mitigate potential threats.

https://www.loldrivers.io/

#redteam #loldrivers #windows

1 year, 2 months ago

Debugging Windows Isolated User Mode (IUM) Processes

In this blog post discussed how to debug Windows' Isolated User Mode (IUM) processes, also known as Trustlets, using the virtual TPM of Microsoft Hyper-V as our target.

https://blog.quarkslab.com/debugging-windows-isolated-user-mode-ium-processes.html

#reverse #windows #trustlets

Quarkslab

Debugging Windows Isolated User Mode (IUM) Processes

1 year, 4 months ago

Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game

https://decoded.avast.io/janvojtesek/dota-2-under-attack-how-a-v8-bug-was-exploited-in-the-game/

#gamehack #expdev #reverse #v8 #exploit

Avast Threat Labs

Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game - Avast Threat Labs

Avast discovered an exploit for CVE-2021-38003 was used in the wild to attack Dota 2 players. This exploit achieved remote code execution on other players' machines by taking advantage of Dota's usage of an outdated V8 version. In response to Avast's findings…

Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game
1 year, 4 months ago
1 year, 4 months ago

CASR – collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity. It is based on ideas from exploitable and apport.

https://github.com/ispras/casr

GitHub

GitHub - ispras/casr: Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity.

Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity. - GitHub - ispras/casr: Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate...

CASR – collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity. It is based on ideas from exploitable and …
1 year, 5 months ago

UserComment is a plugin to display user-added comments in disassembly and pseudocode views.

https://forum.reverse4you.org/t/usercomment-an-ida-plugin-to-show-user-added-comments/19747

#reverse #idapro #plugin

R0 CREW

UserComment: An IDA plugin to show user-added comments

UserComment is a plugin to display user-added comments in disassembly and pseudocode views. Provides a comment window, displaying user-added comments, including comments in assembly code and pseudocode. Support for different types of comments (common comments…

UserComment is a plugin to display user-added comments in disassembly and pseudocode views.
1 year, 10 months ago
***✨***Happy New Year!***✨***

✨Happy New Year!✨

Take care of yourself and those close to you!

2 years, 3 months ago

IDA Pro 8.0 released!

  • Golang 1.18
  • iOS 16 dyld shared cache support
  • ARC decompiler
  • Better firmware analysis
  • FLAIR pattern generator (makepat)

https://hex-rays.com/products/ida/news/8_0/

Hex-Rays

Welcome to IDA 8.0!

A powerful disassembler and a versatile debugger

2 years, 4 months ago

At the beginning of 2020, we discovered the Red Unlock technique that allows extracting Intel Atom Microcode. We were able to research the internal structure of the microcode and then x86 instruction implementation. Also, we recovered a format of microcode updates, algorithm and the encryption key used to protect the microcode

https://github.com/chip-red-pill/MicrocodeDecryptor

#tools #reverse #intel #interlnals #microcode #Aligner

We recommend to visit

Community chat: https://t.me/hamster_kombat_chat_2

Twitter: x.com/hamster_kombat

YouTube: https://www.youtube.com/@HamsterKombat_Official

Bot: https://t.me/hamster_kombat_bot
Game: https://t.me/hamster_kombat_bot/

Last updated 2 months, 1 week ago

Your easy, fun crypto trading app for buying and trading any crypto on the market

Last updated 2 months ago

Turn your endless taps into a financial tool.
Join @tapswap_bot


Collaboration - @taping_Guru

Last updated 2 weeks, 4 days ago