Super Sheep (@[email protected])

1.1K posts

Super Sheep (@qutluch@infosec.exchange) banner
Super Sheep (@qutluch@infosec.exchange)

Super Sheep (@[email protected])

@Qutluch

When these frail shadows we inhabit now have quit the stage, we'll meet and raise a glass again together in Valhalla.

Ireland Katılım Temmuz 2010
3K Takip Edilen443 Takipçiler
Super Sheep (@qutluch@infosec.exchange)
Last year I got my HAM radio license and I've been really enjoying the hobby. For this weekend and St. Patrick's Day I'm going to be posting HAM radio information.
English
0
0
2
38
Super Sheep (@qutluch@infosec.exchange)
@allthingsida I've been using idasql through Claude Code for a few weeks now and it's amazing. For validation I use windbg-agent, also from Elias, and have Claude validate its own findings from a TTD trace file. Incredible power up in my RE arsenal.
English
0
0
3
60
Super Sheep (@[email protected]) retweetledi
ESET Research
ESET Research@ESETresearch·
#ESETresearch discovered unique toolset, we named QuietEnvelope, targeting the MailGates email protection system of Taiwanese company OpenFind. The toolset was uploaded in anarchive, named spam_log.7z, to VirusTotal from Taiwan 🇹🇼. It contains Perl scripts, three stealthy passive backdoors, an argument runner, and miscellaneous files. 1/7
ESET Research tweet media
English
3
50
172
27.4K
Super Sheep (@[email protected]) retweetledi
Brian in Pittsburgh
Brian in Pittsburgh@arekfurt·
Having read this now what's going on here is actually a lot more interesting than ordinary process injection. The PRC group here is bypassing FreeBSD's application control mechanism by abusing built-in functionality (Lolbins) to read and execute raw binary shellcode from disk. 🤨
Brian in Pittsburgh tweet mediaBrian in Pittsburgh tweet media
Dino A. Dai Zovi@dinodaizovi

This is an interesting case study because it concretely shows that you have to go further than allowlisting known/trusted executables, they also need runtime memory integrity protection/guarantees: cloud.google.com/blog/topics/th… Ideally, page-level integrity like iOS in your vm impl.

English
1
11
27
4.1K
sysxplore
sysxplore@sysxplore·
Scare a Linux user in less than 5 words 🐧👻
English
359
30
832
78.5K
Super Sheep (@[email protected]) retweetledi
herrcore
herrcore@herrcore·
Support us on Patreon 💕 Tools - x64dbg (x64dbg.com) - IDA (hex-rays.com/ida-free) - VMPDump (github.com/0xnobody/vmpdu…) Additional Learning Resources - Sandbox Tricks For Faster Reversing (youtube.com/watch?v=rDQmh1…) - MSVC Entry Point and Security Init Cookie (patreon.com/posts/why-is-p…) - Unpacking VMP - Full Series (patreon.com/collection/155…) Original packed sample: 8c1a72991fb04dc3a8cf89605fb85150ef0e742472a0c58b8fa942a1f04877b0 (malshare.com/sample.php?act…) Clean unpacked payload (fixed OEP): ff5757086c464d624f4a6674d65409fb6fa84ad5ac089583ebc994ba949458d7 (malshare.com/sample.php?act…)
YouTube video
YouTube
English
1
8
38
4.3K
Super Sheep (@[email protected]) retweetledi
fG!
fG!@osxreverser·
Cracking the Crackers Reversing the TNT team macOS crack library to understand if there is malware due to patching of pro-Ukraine support messages. With deobfuscators and dumper tools pushed to Github. Have fun :-] reverse.put.as/2025/03/13/cra…
English
2
39
115
9.9K
mRr3b00t
mRr3b00t@UK_Daniel_Card·
ok so It's not perfect, but this at least has UX in mind. Not bad for a few days work! still got about 9 days left of budget for my 6K (selling to myself at cost LOL )
mRr3b00t tweet media
English
5
4
90
8.1K