Do Attackers Pay More Attention to IPv6?, (Sat, Jul 29th)

IPv6 has always been a hot topic&#;x26;#;x21; Available for years, many ISP&#;x26;#;39;s deployed IPv6 up to their residential customers. In Belgium, we were for a long time, the top-one country with IPv6 deployment because all big players provided IPv6 connectivity. In today&#;x26;#;39;s operating systems, IPv6 will be used first if your computer sees “RA” packets (for “router advertisement” [1]) and can get an IPv6 address. This will be totally transparent. That&#;x26;#;39;s why many people think that they don&#;x26;#;39;t use IPv6 but they do&#;x26;#;x21;

Continue reading Do Attackers Pay More Attention to IPv6?, (Sat, Jul 29th)→

Posted in Uncategorized

ShellCode Hidden with Steganography, (Fri, Jul 28th)

When&#;x26;#;xc2;&#;x26;#;xa0;hunting, I&#;x26;#;39;m often surprised by the interesting pieces of code that you may discover… Attackers (or pentesters/redteamers) like to share scripts on VT to evaluate the detection rates against many antivirus products. Sometimes, you find something cool stuffs.

Continue reading ShellCode Hidden with Steganography, (Fri, Jul 28th)→

Posted in Uncategorized

Suspicious IP Addresses Avoided by Malware Samples, (Wed, Jul 26th)

Modern malware samples implement a lot of anti-debugging and anti-analysis techniques.&#;x26;#;xc2;&#;x26;#;xa0;The idea is to slow down the malware analyst&#;x26;#;39;s job&#;x26;#;xc2;&#;x26;#;xa0;or, more simply, to bypass security solutions like sandboxes.&#;x26;#;xc2;&#;x26;#;xa0;These days, I see more and more malware samples written in Python that have these built-in capabilities.&#;x26;#;xc2;&#;x26;#;xa0;One of them is&#;x26;#;xc2;&#;x26;#;xa0;the detection of “suspicious” IP addresses.

Continue reading Suspicious IP Addresses Avoided by Malware Samples, (Wed, Jul 26th)→

Posted in Uncategorized

JQ: Another Tool We Thought We Knew, (Mon, Jul 24th)

So often you&#;x26;#;39;ll see folks (me included) use “jq” to take an unformatted JSON mess and turn it into a readable output. For instance, last thursday we used the Shodan API to dump about 650k of host info like this:
curl -s -k “https://api.shodan.io/shodan/host/%1?key=%shodan-api-key%” | jq

Continue reading JQ: Another Tool We Thought We Knew, (Mon, Jul 24th)→

Posted in Uncategorized