the grugq's newsletter

Subscribe
Archives
September 8, 2024

September 8, 2024

September 8, 2024

Cracking an old ZIP file to help open source the ANC's "Operation Vula" secret crypto code

This is quite cool.

John Graham-Cumming's blog: Cracking an old ZIP file to help open source the ANC's "Operation Vula" secret crypto code

It's not often that you find yourself staring at code that few people have ever seen, code that was an important part in bringing down the a...


#SpyNews - week 36 (September 1-7):
A summary of 91 espionage-related stories from week 36 coming from ๐Ÿ‡ณ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ท๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ป๐Ÿ‡ณ๐Ÿ‡ณ๐Ÿ‡ด๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ฉ๐Ÿ‡ฟ๐Ÿ‡ฒ๐Ÿ‡ฆ๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡พ๐Ÿ‡ช๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ญ๐Ÿ‡บ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ณ๐Ÿ‡ฟ๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ณ๐Ÿ‡จ๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ท๐Ÿ‡ด๐Ÿ‡ท๐Ÿ‡ธ๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡ฆ๐Ÿ‡ฑ๐Ÿ‡ต๐Ÿ‡ญ๐Ÿ‡ฎ๐Ÿ‡ฉ๐Ÿ‡ถ๐Ÿ‡ฆ๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡ป๐Ÿ‡ง๐Ÿ‡พ๐Ÿ‡น๐Ÿ‡ผ๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡ฉ๐Ÿ‡ฐ๐Ÿ‡ช๐Ÿ‡ช๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡จ๐Ÿ‡ฑ๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡จ๐Ÿ‡ฟ๐Ÿ‡จ๐Ÿ‡ฉ๐Ÿ‡ฆ๐Ÿ‡ด๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ฒ๐Ÿ‡ฌ๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ‡ธ๐Ÿ‡ฐ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡ณ๐Ÿ‡ต๐Ÿ‡ธ๐Ÿ‡ฌ๐Ÿ‡ญ๐Ÿ‡ฐ๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡ช๐Ÿ‡ฌ๐Ÿ‡ฑ๐Ÿ‡พ https://t.co/r2KcrQFSkD#Espionage #OSINT #HUMINT #SIGINT #Spy

โ€” Spy Collection (@SpyCollection1) September 8, 2024


Series by @quarkslab on dynamically hooking Golang programs

Part 1: https://t.co/RYjBvVHQi9
Part 2: https://t.co/gzuyIThaNW
Part 3: https://t.co/vgKvJphE2x#golang #infosec pic.twitter.com/TePvShzkyG

โ€” 0xor0ne (@0xor0ne) September 8, 2024


Passport

Forwarding TCP ports through Passkey servers to bypass censorship.

GitHub - c-skills/passport

Contribute to c-skills/passport development by creating an account on GitHub.


WHOSE BODY WAS IT??? pic.twitter.com/nTlBibw3Px

โ€” SarcasticRover (@SarcasticRover) September 8, 2024


Hypervisors are way more useful than you think.

A great example is the AVF (Android Virtualization Framework). This recently-added feature allows code to execute inside it's own VM, with isolated memory space from the host.

Imagine a banking app written with AVF in mind. Evenโ€ฆ pic.twitter.com/Lrs0d8Xwv1

โ€” LaurieWired (@lauriewired) September 7, 2024


imagine that.https://t.co/M5Gk7BZvdA https://t.co/G2Qj9K1okw pic.twitter.com/AbSggDOrzK

โ€” Jโฉœโƒmieโžก๏ธBSides๐Ÿ…โ“žVโ“ (@jamieantisocial) September 7, 2024


Listening to Richard Moore & Bill Burns at Kenwood House. https://t.co/nNE7FiOEvA pic.twitter.com/fYCnmebkH4

โ€” Shashank Joshi (@shashj) September 7, 2024


ChromeKatz: Dump cookies and credentials directly from Chrome/Edge process memory https://t.co/uZpm3XGKu2

โ€” Spiros Fraganastasis (@m3g9tr0n) September 7, 2024


> What Chainanalysis does is, get the cheapest VPS in OVH and setup a reverse proxy to some real nodes. Then they advertise it on https://t.co/aBjCDU8FQ2 etc. and use it to trace TXs to IPs.
< I see. So they see the tx. It looks to the wallet like it's a real node, but they areโ€ฆ

โ€” Rotten (@rottenwheel1) September 8, 2024


crash.js will just crash with an OOB writehttps://t.co/J6ny4k8Mhk
leak_hole.js will use the OOB access to leak the hole objecthttps://t.co/vwGCQrEaqz
Exploit:https://t.co/t6sz0tw01q https://t.co/s5WadrXM5c

โ€” xvonfers (@xvonfers) September 7, 2024

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X