RSSAmplifier

Blog

Adepts of 0xCC

A brotherhood of owls praying to the debugger God. @AdeptsOf0xCC

adepts.of0x.ccRSS feed ↗10 posts

Latest posts

From your doorbell to your home network

Dear Fellowlship, I am delighted to inform you that the owls have found the time to get back to hacking in their spare time. After this two-year hiatus, we are pleased to preach a new homily from this humble digital pulpit of ours. Please, take a seat and listen to the story.

Mixing watering hole attacks with history leak via CSS

Dear Fellowlship, today’s homily is about one of the fields that we most rejoiced in when we were youngsters 15 years ago: client-side attacks and harmless information leaks. Please, take a seat and listen to the story.

VBA: overwriting R/W/X memory in a reliable way

Dear Fellowlship, today’s homily is an addendum to our previous homily “VBA: having fun with macros, overwritten pointers & R/W/X memory”. After writing the previous post our owls met in a parliament to deliberate how to add stability to the technique shown. After a few exchanges of ideas lubricated by the consecrated wine, the solution was found. This solution was presented to the public during…

A christmas tale: pwning GTB Central Console (CVE-2024-22107 & CVE-2024-22108)

Dear Fellowlship, today’s homily is about the paradox of how adding security solutions to your infrastructure increases the vulnerable surface.

VBA: having fun with macros, overwritten pointers & R/W/X memory

Dear Fellowlship, today’s homily is about an epiphany one of our owls had a couple of weekends ago: an alternative way for running shellcodes in macros. Please, take a seat and listen the story. Prayers at the foot of the Altar a.k.a. disclaimer I am writing this article because I had fun last weekend researching this and wanted to share my findings. Maybe this could be useful to someone, but to…

Developers are juicy targets: DCOM & Visual Studio

Dear Fellowlship, today’s homily is about the umpteenth DCOM-based lateral movement method you’ll see, this time targeting that blessing that populates any company: developers. Dreaded users whose machines are often found on quite a few exclusion lists to avoid the myriad of false positives they generate with their work.

VBA: resolving exports in runtime without NtQueryInformationProcess or GetProcAddress

Dear Fellowlship, today’s homily is about bending the ungodly language of VBA to reduce traces when writing sacrilegious prayers. Please, take a seat and listen to the story.

Beating an old PHP source code protector

Dear Fellowlship, today’s homily is about our last fight against an ancient artifact called Nu-Coder, The PHP Protector. Please, take a seat and listen to the story.

Spice up your persistence: loading PHP extensions from memory

Dear Fellowlship, today’s homily is about how to improve persistences based on PHP extensions. In this gospel we will explain a way to keep a PHP extension loaded on the server without it being backed up by a file on disk. Please, take a seat and listen the story.

Thoughts on the use of noVNC for phishing campaigns

Dear Fellowlship, today’s homily is a rebuke to all those sinners who have decided to abandon the correct path of reverse proxies to bypass 2FA. Penitenziagite!