Abusing MySQL LOCAL INFILE to read client files
Recently, I was playing the VolgaCTF 2018 CTF with my teammates from TheGoonies and we came across an interesting Web challenge that we didn't manage to solve during the competition. The following day,...
View ArticleLuaBot: Malware targeting cable modems
During mid-2015 I disclosed some vulnerabilities affecting multiple ARRIS cable modems. I wrote a blogpost about ARRIS' nested backdoor and detailed some of my cable modem research during the 2015...
View Article0CTF 2016 Write Up: Monkey (Web 4)
The Chinese 0CTF took place on March 12-13 and it was yet another fun CTF. I played with my teammates from TheGoonies and we were ranked #48.I found the Web task "Monkey" particularly interesting: I...
View ArticleARRIS Cable Modem has a Backdoor in the Backdoor
A couple of months ago, some friends invited me to give a talk at NullByte Security Conference. I started to study about some embedded device junk hacking hot topics and decided to talk about cable...
View ArticleHack.lu 2015 CTF Write Up: Dr. Bob (Forensic 150)
Hack.lu 2015 CTF was organised by fluxfingers during October 20-22. It's one of the coolest CTFs around, the only drawback is that it runs during week days (hey guys patch this for the next years). My...
View ArticleMac OS X 10.11 Partial Lock Screen Bypass
Lock screen bypasses are becoming mainstream. The most notable recent bypasses are the one from Ubuntu 14.04 (hold enter, lock screen crashes, computer unlocked) and the one from Android 5.x (input...
View ArticleCSAW CTF 2015 Write Up: Weebdate (web500)
The anual CSAW CTF Qualification Round took place on September 18-20 and it was yet another really cool CTF. I played with my friends from TheGoonies and we ranked #128 overall (The Goonies 'R' Good...
View ArticleExtracting RAW pictures from memory dumps
IntroductionEarlier today, while reading my Twitter timeline, I saw some Infosec folks discussing about scripts/tools to identify RAW pictures in memory dumps. I decided, then, to write this blog post...
View ArticleFirmware Forensics: Diffs, Timelines, ELFs and Backdoors
This post covers some common techniques that I use to analyze and reverse firmware images. These techniques are particularly useful to dissect malicious firmwares, spot backdoors and detect unwanted...
View Article9447 2014 CTF Write Up: coor coor
The Australian 9447 Security Society CTF took place on November 29-30 and it was yet another fun and really professionally organized CTF. I played with my friends from TheGoonies once again (The...
View ArticleHack.lu 2014 CTF Write Up: At Gunpoint
Hack.lu's 2014 CTF took place on October 21-23. The event was organized by fluxfingers, and this year's challenges were really enjoyable, huge props to them. I played with my friends from TheGoonies -...
View ArticleScan the Internet & Screenshot All the Things
During Defcon 22, @ErrataRob, @paulm and @Viss (mass)scanned the Internet and presented some Tips, Tricks and Results. Lots of people confronted @Viss after he posted some VNC screenshots on his...
View ArticleHacking Asus RT-AC66U and Preparing for SOHOpelesslyBroken CTF
So it's finally July, time to pack for DEFCON, follow @defconparties on Twitter and decide which villages to visit and which talks to attend.There's a new hacking competition this year called...
View ArticleFoxit PDF Reader Stored XSS
A friend of mine was performing an external pentest recently and he started to complain that his traditional Java exploits were not being effective. He was able to map a few applications and defenses...
View ArticleWildcard DNS, Content Poisoning, XSS and Certificate Pinning
Hi everyone, this time I'm going o talk about an interesting vulnerability that I reported to Google and Facebook a couple of months ago. I had some spare time last October and I started testing for...
View ArticleAnalyzing Malware for Embedded Devices: TheMoon Worm
All the media outlets are reporting that Embedded Malware is becoming mainstream. This is something totally new and we never heard of this before, right? The high number of Linux SOHO routers with...
View ArticleBinwally: Directory tree diff tool using Fuzzy Hashing
For this post, I'll discuss about the concept of directory tree and binary diffing and how it could be used to find potential vulnerabilities and security issues that were (silently) patched on...
View ArticleUnpacking Firmware Images from Cable Modems
Hacking Cable modems used to be very popular during the early 2000’s. People like DerEngel and Isabella from TCNiSO carried lots of research on the topic and talks from bitemytaco (R.I.P) and BlakeSelf...
View ArticleAnalyzing and Running binaries from Firmware Images - Part 1
During the first part of SIMET Box Firmware analysis, we downloaded the firmware Image, extracted its contents, compared/analyzed its base and found a couple of interesting files (SSH keys, binary...
View ArticleSIMET Box Firmware Analysis: Embedded Device Hacking & Forensics
For my first blog post I decided to have a quick look on the firmware from SIMET Box. SIMET is organized by the Brazilian NIC.br in order to test and monitor the Internet speed across the country. For...
View Article