Cropping and Redacting Images Safely, (Thu, Mar 23rd)

The recent “acropalypse” vulnerabilities in Android and Windows 11 showed yet again the dangers of relying on image processing tools to redact images [1][2]. While many image formats are still fundamentally “pixel” based, many have gone beyond simple “array of pixel” formats. Added compression, metadata, and other optimization features can make it difficult to remove information from images. This is not a new issue and has been a problem many times [3].

Continue reading Cropping and Redacting Images Safely, (Thu, Mar 23rd)→

Posted in Uncategorized

From Phishing Kit To Telegram… or Not!, (Mon, Mar 20th)

Phishing kits are not new, they are plenty in the wild, and my honeypot collects many samples daily. Usually, a phishing kit will collect credentials and send them to a compromised server (WordPress is generally an excellent target to host this kind of malicious code). Later, I found many kits that (ab)use online services to receive data submitted via HTTP forms[1].

Continue reading From Phishing Kit To Telegram… or Not!, (Mon, Mar 20th)→

Posted in Uncategorized

Old Backdoor, New Obfuscation, (Sat, Mar 18th)

When you’re hunting, sometimes you feel lucky because you spotted something that looks brand new, but sometimes it’s not new or… the code has been changed to bypass existing detections. Here is a perfect example. A few months ago, Juniper discovered[1] a backdoor targeting VMWare ESXi servers, more precisely, the OpenSLP service (%%cve:2019-5544%% and %%cve:2020-3992%%).

Continue reading Old Backdoor, New Obfuscation, (Sat, Mar 18th)→

Posted in Uncategorized