SakDriver: Reversing a Windows Kernel Driver Rootkit
Original text: “SakDriver: Reversing a Kernel Driver Rootkit” — 0xSec, 0xsec.gitbook.io. Disassembly screenshots, the command-ID table, indicators of compromise and the YARA figure below are reproduced with attribution captions.
Executive Summary
What began as a routine look at a “Cobalt Strike Beacon” sample turned out to be something far more dangerous: a full Windows kernel-mode…
https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/
Original text: “SakDriver: Reversing a Kernel Driver Rootkit” — 0xSec, 0xsec.gitbook.io. Disassembly screenshots, the command-ID table, indicators of compromise and the YARA figure below are reproduced with attribution captions.
Executive Summary
What began as a routine look at a “Cobalt Strike Beacon” sample turned out to be something far more dangerous: a full Windows kernel-mode…
https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/
👍7🔥3
Longinus: Two Security Boundaries in One Bug — Piercing Chrome’s Renderer and the V8 Sandbox with CVE-2026-6307
Original text: “Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307” — Nebula Security, NebuSec (June 29, 2026). Code, tables and figures below are reproduced verbatim with attribution captions.
Executive Summary
CVE-2026-6307 is a single V8 vulnerability that crosses two security boundaries at once. The root cause…
https://core-jmp.org/2026/07/cve-2026-6307-v8-framestate-type-confusion/
Original text: “Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307” — Nebula Security, NebuSec (June 29, 2026). Code, tables and figures below are reproduced verbatim with attribution captions.
Executive Summary
CVE-2026-6307 is a single V8 vulnerability that crosses two security boundaries at once. The root cause…
https://core-jmp.org/2026/07/cve-2026-6307-v8-framestate-type-confusion/
🔥5
IDA pro 9.4
*
Linux + Windows + Mac + ARM
download
*
*
Linux + Windows + Mac + ARM
download
*
tree "/home/data/0x01/IDA/IDA pro 9.4/"
/home/reeves/data/soft/IDA/IDA pro 9.4/
├── ida-pro_94_armlinux.run
├── ida-pro_94_armmac.app.zip
├── ida-pro_94_armwin.exe
├── ida-pro_94_x64linux.run
├── ida-pro_94_x64mac.app.zip
├── ida-pro_94_x64win.exe
├── kg_patch
│ ├── idapro.hexlic
│ ├── keygen.js
│ ├── README
│ ├── x64linux
│ │ ├── libida32.so
│ │ └── libida.so
│ └── x64win
│ ├── ida32.dll
│ └── ida.dll
└── misc
├── hexlicsrv94_x64linux.run
├── hexvault94_x64linux.run
├── idapin94.zip
└── lumina94_x64linux.run
5 directories, 17 files
🔥36👍20😱12
This media is not supported in your browser
VIEW IN TELEGRAM
skitter-creek-bath-salts
*
exploit: “xor dword [0xf80c2094], 1<<22”
Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. As far as I can tell can’t be fixed.
get
*
exploit: “xor dword [0xf80c2094], 1<<22”
Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. As far as I can tell can’t be fixed.
get
👍11🔥2😱1
Забавнейшая штука ! SSHDESK
пиксели и input идут внутри SSH PTY
Я так подумал, концептуально его можно превратить в
screen capture
mouse injection
keyboard injection
remote GUI
encrypted transport
управляющий канал !!!
*** осталось сдлеать отдельный desktop в параллель (desk 0 to desk X), user hide, ну и какую никакую persistence модель бы воткнуть
god bless SSH
пиксели и input идут внутри SSH PTY
Я так подумал, концептуально его можно превратить в
HVNC под *nix, большая часть архитектуры то готова: screen capture
mouse injection
keyboard injection
remote GUI
encrypted transport
управляющий канал !!!
*** осталось сдлеать отдельный desktop в параллель (desk 0 to desk X), user hide, ну и какую никакую persistence модель бы воткнуть
god bless SSH
👍14🔥12😱2