cybersecurity
education
€ EUR
  • $ USD
  • € EUR

[CQURElabs] Alternate Data Streams

Author: Adrian Denkiewicz, Cybersecurity Expert at CQURE NTFS (New Technology File System) is a default file system for Windows operating system. Long time ago it replaced FAT family and brought several new features. One of its lesser known functions is called Alternate Data Streams (ADS for short). It has been initially implemented in Windows NT […]

#CQLabs – Implementing Proof-of-Concept C2 with Microsoft OCR

During the security assessments, one of the things that we always check is the possibility to extract information outside of the client network. This includes the ability to copy data to external drivers, send them via e-mail to external e-mail addresses, use various TCP/UDP ports, non-typical protocols or even side channels. In mature environments, special […]

#CQLabs 4 – from Unquoted Service Path to Privilege Escalation

cqlabs-4

In this article, I will write about a service misconfiguration that I’ve found within the Rockstar Games Launcher (https://socialclub.rockstargames.com/rockstar-games-launcher). The issue is already fixed by the vendor and I was granted a bounty for its discovery and coordinated disclosure. The interesting trivia about it is that the component was not initially included in the scope […]

#CQLabs – CVE-2019-15511: Broken Access Control in GOG Galaxy

This article covers a vulnerability discovered in GOG Galaxy, which may result in Local Privilege Escalation due to a lack of authorization of commands sent via a local TCP connection. The attacker may exploit this vulnerability to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. Background I’ve recently started looking at […]

#CQLabs – How UAC bypass methods really work by Adrian Denkiewicz

Adrian_Denkiewicz_CQlabs

In this article, we will analyze a couple of knowns, still working, UAC bypasses – how they work, what are the requirements, and potential mitigation techniques. Before we dive into this, we need to briefly explain what UAC is.   What is UAC The acronym UAC stands for User Account Control, a part of the […]

Black Hat USA 2020 Highlights: When TLS Hacks You

  Black Hat USA 2020   I had a pleasure to be a part of Black Hat USA 2020. Due to the current pandemic, this year’s conference was held as a virtual event. It lacked lots of typical social interactions – all presentations were prerecorded, but sometimes one couldn’t hear or see the speaker due […]

Black Hat USA 2020 Highlights: Portable Document Flaws 101

  #2 Portable Document Flaws 101 Last time, I’ve shared my thoughts on the novel TLS-based attack. This time, I want to cover research done by Jens Müller @jensvoid on insecure (and less known) PDF features. He presented the “Portable Document Flaws 101” session during the second day of the BHUSA 2020 conference. The presentation […]

Black Hat USA 2020 Highlights: Demystifying Modern Windows Rootkits

  #3 Demystifying Modern Windows Rootkits The third article in the series will focus on rootkit talk given by Bill Demirkapi (@BillDemirkapi). In his talk, Bill explained how rootkits are created and loaded, how the attacker can establish a stealth communication channel with the rootkit, and how to cover up rootkit traces. Rootkits Let’s start […]

How can we help you?

Suggested searches

    Search history

      Popular searches:

      Not sure what course to look for?

      Mobile Newsletter Form