malwarecube's profile picture.

malwarecube

@malwarecube

Pinned

I put together a possible detection / mitigation browser agent in response to @mrd0x 's Browser in the Browser (BITB) phishing technique. Native browser functionality could be a great solution, but here's an open-source idea for now. github.com/odacavo/enhanc…


If you’re in #Canada, you’ve likely seen this recent #deepfake YouTube ad. What I found led me straight to the scammer. In this video, I show how I traced the operation back to its source, warned the victims, and eventually shut the infrastructure down. youtube.com/watch?v=6208Bm…

malwarecube's tweet card. How I Took Down A $150,000 Scam

youtube.com

YouTube

How I Took Down A $150,000 Scam


malwarecube reposted

For years #OWASP #Ottawa met at Shopify's Cody's Cafe.But as that is no longer available we needed to find a new place. We are pleased to announce a new location at the University of Ottawa.This will keep our meetup's central. We will continue to live stream. Details to follow.


malwarecube reposted

Stealth trick for Red Teaming - why worry about being caught by an MDR (i.e., Artic Wolf, FireEye, etc.) when you can kill their visibility? 🧐 ipconfig /displaydns - Find API Endpoint echo 127.0.0.1 blahblah.fireye.com >> c:\windows\system32\drivers\etc\hosts


Thank you for sharing!

Try this extension to automatically detect and provide verbose warnings for embedded iframe elements in order to protect yourself against Browser-In-The-Browser (BITB) attacks by @odacavo github.com/odacavo/enhanc…



malwarecube reposted

I wish the IT Crowd did more series.


malwarecube reposted

BREAKING: @TheJusticeDept announced a policy revision to the United States Computer Fraud and Abuse Act (CFAA) which includes exemptions of criminal charges for "good-faith" security researchers. This is a huge victory for our cause! #HackingIsNotACrime justice.gov/opa/pr/departm…


malwarecube reposted

you've heard of Y2K. now get ready for...the user agent apocalypse😂

gf_256's tweet image. you've heard of Y2K. now get ready for...the user agent apocalypse😂

malwarecube reposted

Super interesting: looks like scammers found a subdomain takeover on "forms.ferrari.com" and are using it to host an NFT scam.

samwcyo's tweet image. Super interesting: looks like scammers found a subdomain takeover on "forms.ferrari.com" and are using it to host an NFT scam.
samwcyo's tweet image. Super interesting: looks like scammers found a subdomain takeover on "forms.ferrari.com" and are using it to host an NFT scam.

malwarecube reposted

After 5 years of work, security.txt is officially an RFC. I am pleased to announce RFC 9116: rfc-editor.org/rfc/rfc9116. I would like to use this opportunity to thank those who made this possible. Thank you. ❤️

EdOverflow's tweet image. After 5 years of work, security.txt is officially an RFC. I am pleased to announce RFC 9116: rfc-editor.org/rfc/rfc9116.

I would like to use this opportunity to thank those who made this possible. Thank you. ❤️

malwarecube reposted

APSU ALERT: We are under a Ransomeware attack. If your computer is connected to the APSU network, please disconnect IMMEDIATELY


Thanks for 50 followers! I will most definitely let you down.


malwarecube reposted

An infected host on your network is running searches on Bing.


malwarecube reposted

Thanks a lot for the good work and the sharing!! 🙏


malwarecube reposted

This is _awesome_! I just installed it in Firefox on my machine and tested it with a few pages. Works exactly as needed, and I'm super impressed with how quickly you made this available. Nice work!


malwarecube reposted

Works well! (with apologies to Jeff Geerling)

ronnie35967255's tweet image. Works well!
(with apologies to Jeff Geerling)

malwarecube reposted

I've also referenced your browser extension in my repo since several people were asking about how to detect this phishing technique.

mrd0x's tweet image. I've also referenced your browser extension in my repo since several people were asking about how to detect this phishing technique.

malwarecube reposted

Thanks, really good stuff. One thing to note is the iframe is optional. An alternative can be a div (customized to be a login form) that contains the form tag and is aligned with the URL bar & title bar. But since the templates I've put out use iframes this will block them.


Loading...

Something went wrong.


Something went wrong.