Christian W

104 posts

Christian W

Christian W

@_Wra7h

maldev hobbyist. glasses. mustache.

Присоединился Ekim 2019
271 Подписки662 Подписчики
Christian W ретвитнул
vx-underground
vx-underground@vxunderground·
Hacking is boring. Wanna know what's fun? Browsing MSDN documentation at 2 o'clock in the morning, looking for APIs to potentially abuse in malware. It'll also probably never go in the wild and it'll go unappreciated for several months or even years. That's where the fun is
English
17
55
965
52.6K
Christian W
Christian W@_Wra7h·
I assume this has something to do with the cert not being included during hash generation for signing. So the underlying logic probably excluded the "DataDirectory[4].Size" amount of bytes starting from the cert offset when the call checks the modified dll - but could be wrong.
Christian W tweet media
English
1
0
2
225
Christian W
Christian W@_Wra7h·
Fun Win10 bug(?): LoadEnclaveImage (supposedly) requires a signed/valid image. However, if I modified the size of DataDirectory[4].Size in SgrmEnclave_secure.dll to include any add'l data I wanted to append to the cert, it would bypass the validation check and get loaded. 1/?
English
1
3
6
1.5K
Octoberfest7
Octoberfest7@Octoberfest73·
Bonus unhinged Paint 3D visualization:
Octoberfest7 tweet media
English
3
0
11
1.3K
Octoberfest7
Octoberfest7@Octoberfest73·
Man, the feeling of finally solving a big blocker in a project after 5 days of thinking/tinkering >>>
English
1
0
19
2.4K
checkymander (Alpha Mon)
checkymander (Alpha Mon)@checkymander·
If you had an AI assistant for your c2 platform, what kind of things would you expect it to be able to do?
English
14
1
10
3.7K
vx-underground
vx-underground@vxunderground·
Our friend @nikhil_mitt hooked us up with MORE stuff to giveaway for the holiday season. We've got 3 vouchers for the CARTP (Azure Red Teaming course). He's the real MVP. Thank you so much 🙏 Comment below for a chance to win Course details: alteredsecurity.com/azureadlab
English
491
57
422
49.7K
vx-underground
vx-underground@vxunderground·
Hello, are you a nerd who likes malware? Us too! Our sponsor @MalDevAcademy has hooked us up with 3 lifetime licenses to their courses. Thank you to @mrd0x for the gifts! Leave a comment below for a chance to win!
English
740
50
630
87K
Samuel
Samuel@VK_cyber_·
@_Wra7h It was down a few days ago, and then came back up the same day.
English
1
0
1
108
Christian W
Christian W@_Wra7h·
Is pinvoke[.]net dead or just down?
English
1
0
1
539
Christian W
Christian W@_Wra7h·
@techspence Used it for a little bit and it was neat but the 10MB helloworld.exe it produced really highlighted that it wasn’t great for postex actions on target.
English
0
0
3
99
spencer
spencer@techspence·
Do people actually _enjoy_ writing code in Go? 😅
English
26
0
19
8.6K
Christian W
Christian W@_Wra7h·
- MATLAB Coder doesn't like loadlibrary()/calllib(). Instead I had to use "coder.cinclude(<header>)" and "coder.ceval(<api>, <arg1>, <arg2>, ...)" in order to leverage Windows APIs. Example: hThread = coder.ceval('CreateThread', [], 0x0, hAlloc, [], 0x0, []); 3/?
English
1
0
2
389
Christian W
Christian W@_Wra7h·
@PerS1541026 I wasn't worried too much about the thread handle at the time. Though I did just test/update the gist to call CloseHandle.
Christian W tweet media
English
0
0
1
216
D3vS3c0p5
D3vS3c0p5@PerS1541026·
@_Wra7h Yeah, forget cleanup 😀
English
1
0
0
244
Christian W
Christian W@_Wra7h·
Matlab shellcode loader. ew.
Christian W tweet media
English
6
14
117
22.1K