🦜 Adepts of 0xCC
@adepts.of0x.cc@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
A brotherhood of owls praying to the debugger God.<p><a href="https://twitter.com/AdeptsOf0xCC" target="_blank" rel="noopener">@AdeptsOf0xCC</a></p>
Your feed and you don't want it here? Just
e-mail the birb.
From your doorbell to your home network
https://adepts.of0x.cc/Eufy-DoorBell-hacking/
Published: July 28, 2026 00:00
Dear Fellowlship, I am delighted to inform you that the owls have found the time to get back to hacking in their spare time. After this two-year hiatus, we are pleased to preach a new homily from this humble digital pulpit of ours. Please, take a seat and…
Mixing watering hole attacks with history leak via CSS
https://adepts.of0x.cc/CSS-History-LEAKS/
Published: August 13, 2024 00:00
Dear Fellowlship, today’s homily is about one of the fields that we most rejoiced in when we were youngsters 15 years ago: client-side attacks and harmless information leaks. Please, take a seat and listen to the story.
VBA: overwriting R/W/X memory in a reliable way
https://adepts.of0x.cc/VBA-RWX-ADDENDUM/
Published: July 7, 2024 00:00
Dear Fellowlship, today’s homily is an addendum to our previous homily “VBA: having fun with macros, overwritten pointers & R/W/X memory”. After writing the previous post our owls met in a parliament to deliberate how to add stability to the technique…
A christmas tale: pwning GTB Central Console (CVE-2024-22107 & CVE-2024-22108)
https://adepts.of0x.cc/gtbcc-pwned/
Published: January 23, 2024 00:00
Dear Fellowlship, today’s homily is about the paradox of how adding security solutions to your infrastructure increases the vulnerable surface.
VBA: having fun with macros, overwritten pointers & R/W/X memory
https://adepts.of0x.cc/VBA-hijack-pointers-rwa/
Published: January 12, 2024 00:00
Dear Fellowlship, today’s homily is about an epiphany one of our owls had a couple of weekends ago: an alternative way for running shellcodes in macros. Please, take a seat and listen the story. Prayers at the foot of the Altar a.k.a. disclaimer I am…
Developers are juicy targets: DCOM & Visual Studio
https://adepts.of0x.cc/Visual-Studio-DCOM/
Published: December 23, 2023 00:00
Dear Fellowlship, today’s homily is about the umpteenth DCOM-based lateral movement method you’ll see, this time targeting that blessing that populates any company: developers. Dreaded users whose machines are often found on quite a few exclusion lists to…
VBA: resolving exports in runtime without NtQueryInformationProcess or GetProcAddress
https://adepts.of0x.cc/VBA-exports-runtime/
Published: March 17, 2023 00:00
Dear Fellowlship, today’s homily is about bending the ungodly language of VBA to reduce traces when writing sacrilegious prayers. Please, take a seat and listen to the story.
Beating an old PHP source code protector
https://adepts.of0x.cc/decrypt-nu-coder/
Published: March 7, 2023 00:00
Dear Fellowlship, today’s homily is about our last fight against an ancient artifact called Nu-Coder, The PHP Protector. Please, take a seat and listen to the story.
Spice up your persistence: loading PHP extensions from memory
https://adepts.of0x.cc/dlopen-from-memory-PHP/
Published: December 26, 2022 00:00
Dear Fellowlship, today’s homily is about how to improve persistences based on PHP extensions. In this gospel we will explain a way to keep a PHP extension loaded on the server without it being backed up by a file on disk. Please, take a seat and listen…
Thoughts on the use of noVNC for phishing campaigns
https://adepts.of0x.cc/NoVNC-phishing/
Published: September 9, 2022 00:00
Dear Fellowlship, today’s homily is a rebuke to all those sinners who have decided to abandon the correct path of reverse proxies to bypass 2FA. Penitenziagite!