Category: SANS Internet Storm Center, InfoCON: green

Lost in the Cloud: Akamai DNS Outage, (Thu, Jul 22nd)

This article has been indexed from SANS Internet Storm Center, InfoCON: green As we already got a number of notes from readers: Currently, Akamai's DNS service appears to experience an outage that affects numerous other large websites. Read the…

Video: CyberChef BASE85 Decoding, (Sun, Jul 18th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green In this video, I show how to decode the sample of Xavier's diary entry “Multiple BaseXX Obfuscations” with CyberChef. Read the original article: Video: CyberChef BASE85 Decoding, (Sun,…

BASE85 Decoding With base64dump.py, (Sat, Jul 17th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green Xavier's diary entry “Multiple BaseXX Obfuscations” covers a malicious script that is encoded with different “base” encodings. Xavier starts with my tool base64dump.py, but he can not do…

Multiple BaseXX Obfuscations, (Fri, Jul 16th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green I found an interesting malicious Python script during my daily hunting routine. The script has a VT score of 2/58[1] (SHA256: 6990298edd0d66850578bfd1e1b9d42abfe7a8d1deb828ef0c7017281ee7c5b7). Its purpose is to perform the…

Microsoft July 2021 Patch Tuesday, (Tue, Jul 13th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green This month we got patches for 117 vulnerabilities. Of these, 13 are critical, 6 were previously disclosed and 4 are being exploited according to Microsoft. Read the original…

Microsoft Releases Patches for CVE-2021-34527, (Wed, Jul 7th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green Microsoft today released patches for CVE-2021-34527, the vulnerability also known as “printnightmare”. Patches are currently available for these versions of Windows: Read the original article: Microsoft Releases Patches…

Python DLL Injection Check, (Tue, Jul 6th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green They are many security tools that inject DLL into processes running on a Windows system. The classic examples are anti-virus products. They like to inject plenty of code…

Finding Strings With oledump.py, (Sat, Jul 3rd)

This article has been indexed from SANS Internet Storm Center, InfoCON: green In diary entry “CFBF Files Strings Analysis” I show how to extract strings from CFBF/ole files with my tool oledump.py. Read the original article: Finding Strings With oledump.py,…

Kaseya VSA Users Hit by Ransomware, (Fri, Jul 2nd)

This article has been indexed from SANS Internet Storm Center, InfoCON: green We are aware that some MSSP's customers (Managed Security Services Providers) have been hit by a ransomware. It seems that four(4) MSSP's have been affected until now. The…

“inception.py”… Multiple Base64 Encodings, (Fri, Jul 2nd)

This article has been indexed from SANS Internet Storm Center, InfoCON: green “Inception” is a very nice SF movie in which, if you did not watch it, dreams are implemented in people's minds to help to get access to sensitive information…

CFBF Files Strings Analysis, (Mon, Jun 28th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green The Office file format that predates the OOXML format, is a binary format based on the CFBF format. I informally call this the ole file format. Read the…

DIY CD/DVD Destruction, (Sun, Jun 27th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green I have some personal CDs & DVDs to dispose of. And I don't want them to reamain (easily) readable. Read the original article: DIY CD/DVD Destruction, (Sun, Jun…

Is this traffic bAD?, (Fri, Jun 25th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green It seems like every time I take a handler shift lately, I'm talking about an uptick of traffic on another port and I'm not breaking that trend today.…

Do you Like Cookies? Some are for sale!, (Thu, Jun 24th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green Cookies… These small pieces of information are always with us. Since the GDPR was kicked off in Europe, we are flooded by pop-ups asking if we accept “cookies”.…

Mitre CWE – Common Weakness Enumeration, (Mon, Jun 21st)

This article has been indexed from SANS Internet Storm Center, InfoCON: green If you are involved in the security industry  you are at least somewhat familiar with the Mitre ATT&CK framework, the very useful, community driven, knowledgebase of attack threat…

Update: mac-robber.py, (Sun, Jun 13th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green Almost 4 years ago, I wrote a python version of mac-robber. I use it fairly regularly at $dayjob. This past week, one of my co-workers was using it,…

Keeping an Eye on Dangerous Python Modules, (Fri, Jun 11th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green With Python getting more and more popular, especially on Microsoft Operating systems, it's common to find malicious Python scripts today. I already covered some of them in previous…

Microsoft June 2021 Patch Tuesday, (Tue, Jun 8th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green This month we got patches for 50 vulnerabilities. Of these, 5 are critical, 2 were previously disclosed and 6 is already being exploited according to Microsoft. Read the…

Strange goings on with port 37, (Thu, Jun 3rd)

This article has been indexed from SANS Internet Storm Center, InfoCON: green Similar to Yee Ching's diary on Thursday, I noticed an oddity in the Dshield data last weekend (which I had hoped to discuss in a diary on Wednesday,…

Russian Dolls VBS Obfuscation, (Fri, Jun 4th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green We received an interesting sample from one of our readers (thanks Henry!) and we like this. If you find something interesting, we are always looking for fresh meat!…

Quick and dirty Python: nmap, (Mon, May 31st)

This article has been indexed from SANS Internet Storm Center, InfoCON: green Continuing on from the “Quick and dirty Python: masscan” diary, which implemented a simple port scanner in Python using masscan to detect web instances on TCP ports 80…

VMware Security Advisory VMSA-2021-0010, (Tue, May 25th)

This article has been indexed from SANS Internet Storm Center, InfoCON: green VMware has issued a critical security advisory VMSA-2021-0010 (CVSSv3 score ranging from 6.5-9.8). The products affected are VMware vCenter Server and VMware Cloud Foundation, and addresses CVE-2021-21985 and…