We open-sourced a fault injection tool, KRF, that uses kernel-space syscall interception. You can use it today to find faulty assumptions (and resultant bugs) in your programs. Check it out! This post covers intercepting system calls from within the Linux kernel, via a plain old kernel module. We’ll...
Annual report reveals continued concerns over online theft and disruption
Publicly accessible data included info on FBI investigations
Trying to make a living as a programmer participating in bug bounties is the same as convincing yourself that you’re good enough at Texas Hold ‘Em to quit your job. There’s data to back this up in Fixing a Hole: The Labor Market for Bugs, a chapter in New Solutions for Cybersecurity, by Ryan Ellis,...
“Collection #1” dump features over 21m dehashed passwords
Auto-execution VBA code is able to perform several malicious actions, says FortGuard Labs.
KoiPhish is a simple yet beautiful relay proxy idea.
The idea for this little project goes back many years. Since I started learning Golang I figured it would be good exercise to finally go ahead an implement it. So, last December during the 35C3 (which is always inspiring congress) I wrote it up.
I...
Vulnerabilities could allow hackers full access to user accounts and in-game currency.
Two independent security researchers disclose vulnerabilities in web hosting platforms and an airline reservation system.
Just a list of useful notes when dealing with Macs. I’m pretty new to Macs and there might be other, better solutions to the challenges I had to sovle but these worked for me and I’m learning. :)
Pivoting between accounts and keychain issues After pivoting on a target host and elevating to root it s...
Attack targets French ad agency
Ukrainian men said to have stolen non-public documents
This year for CSAW CTF, Trail of Bits contributed two cryptography problems. In the first problem, you could combine two bugs to break DSA much like the Playstation 3 firmware hackers. The other challenge–-weirder and mathier–-was split into two parts: one for the qualifiers, one in finals. This cha...
UK security experts urge organizations to plan upgrade
IoT security showed incremental improvement in 2018, says Gemalto.
With 2019 a day away, let’s reflect on the past to see how we can improve. Yes, let’s take a long look back 30 years and reflect on the original fuzzing paper, An Empirical Study of the Reliability of UNIX Utilities, and its 1995 follow-up, Fuzz Revisited, by Barton P. Miller. In this blog post, […]
Del Rio, Texas, is working with the Feds after the city suffered a ransomware attack.
Recruitment of top talent is potentially compromised as government enters into its 25th day of a shutdown.
The Trail of Bits SummerCon Fellowship program is now accepting applications from emerging security researchers with excellent project ideas. Fellows will explore their research topics with our guidance and then present their findings at SummerCon 2019. We will be reserving at least 50% of our fundi...
Suspicious activity was first reported to ticketing firm in April