Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
wetw0rk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
wetw0rk
2mo ago
Have you ever wondering if the order of operations when voilated can lead to a vulnerability? Maybe the thought never crossed your mind? Either way this week we exploit a binary that did not account for the order of operations - more specif
2.
▲
by
wetw0rk
2mo ago
Straight to the point on what you need to know!
3.
▲
by
wetw0rk
2mo ago
Looking for a smooth introduction to ARM exploitation? Wanna learn ARM assembly? Well lucky for you this week we'll be looking at another pwnable challenge! However this time we're switching architectures! We'll be exploiting
4.
▲
by
wetw0rk
3mo ago
If you're looking for an exploit development tutorial for absolute beginners this week we're looking at what I would consider just that! This week we look at the "random" binary exploitation challenge hosted on pwnable[.
5.
▲
by
wetw0rk
3mo ago
This week we'll be looking at another beginner friendly exploit development tutorial! More specifically we'll be looking at the "passcode" binary exploitation challenge hosted on pwnable[.]kr! This challenge covers multi
6.
▲
Introduction to the DOM for Vulnerability Researchers
(youtube.com)
3 points
by
wetw0rk
3mo ago
|
0 comments
7.
▲
Introduction to the DOM for Vulnerability Researchers
(youtube.com)
2 points
by
wetw0rk
4mo ago
|
1 comments
8.
▲
by
wetw0rk
4mo ago
Wu-Tang, wetw0rk7, RET2 Systems, Inc., and last but not least Center for Cyber Security Training IS FOR THE CHILDREN!!! This week I'm following along RET2 Systems, Inc.'s free portion of their "Fundamentals of Browser Exploit
9.
▲
by
wetw0rk
1y ago
Long gone are the days of only a small number of Command and Control Servers (C2’s) being deployed by adversaries in our environments. How can we as Red Teamers, Penetration Testers, and Ethical Hackers be one step ahead of those wanting to
10.
▲
by
wetw0rk
1y ago
GOOOOD MORRRRNING HACKER NEWS!!! Incase some of you missed it this year at Black Hat Arsenal I presented Sickle a payload development framework that I designed for both Red Team Operators and Exploit Developers. However, it has modules that
11.
▲
by
wetw0rk
2y ago
The last of the Windows Kernel Exploitation series, thank you all for your support!
12.
▲
by
wetw0rk
2y ago
In this demo I load the KoviD Rootkit onto the operating system when exploiting a Linux RCE vulnerability. Full writeup coming soon!
13.
▲
by
wetw0rk
2y ago
Last week we learned a basic overview of Type Confusion vulnerabilities and exploited one against the Windows 7 Kernel. This week we will be exploiting the same vulnerability against a more modern build of Windows - Windows 11 (x64)! Out of
14.
▲
by
wetw0rk
2y ago
So far within the Windows Kernel tutorial series we have exploited the following vulnerabilities against Windows 7 (x86) and Windows 11 (x64): - Stack Overflow - Heap Use-After-Free - Write-What-Where However, we still have a few more bugs
15.
▲
by
wetw0rk
2y ago
What better way to kick off the new year than to learn something new! So far in the Windows Kernel Exploitation series we have exploited a Stack Overflow and Use-After-Free vulnerability. This week we’ll be learning about a new bug class th
16.
▲
by
wetw0rk
2y ago
Shellcode generation is now supported and I've added 9 new payloads including a reflective loader for Linux on both AARCH64 and x64! Along with a new module asm_shell which supports x86, x64, and AARCH64! In the future I plan to add su
17.
▲
Sickle v3.1.0 Is Out
(github.com)
2 points
by
wetw0rk
2y ago
|
1 comments
18.
▲
0x02 – Introduction to Windows Kernel Use After Frees (UaFs)
(wetw0rk.github.io)
6 points
by
wetw0rk
2y ago
|
1 comments
19.
▲
by
wetw0rk
2y ago
Hello my fellow Hackers (Red, Blue, Purple and everything in between): This week I'm releasing a tutorial on how to exploit a Use-After-Free (UaF) against Windows 7 (x86) to provide a nice primer to UaF's before getting to modern
20.
▲
Reflectively Loading ELFs, may we never touch Disk
(github.com)
2 points
by
wetw0rk
2y ago
|
1 comments
21.
▲
by
wetw0rk
2y ago
I recently pushed an update to Sickle that generates shellcode to perform reflective ELF loading. If you're unfamiliar with what exactly this is, to give you a quick high-level overview; an attacker uses these techniques to map an exec
22.
▲
by
wetw0rk
2y ago
Thank you!
23.
▲
by
wetw0rk
2y ago
Yes the violet phosphorus technique works on the default configuration of the latest build :)
24.
▲
by
wetw0rk
2y ago
If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now. We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then? Truthfully a lot, but the core fundame