Captain Blackbeard Radio #15

July 10, 2022270 words2 mins read

HAPPY INDEPENDENCE DAY TO YE ALL! Yaaaaaaaarrrrrrr!

CaptainBlackbeard Radio invites ye, to an audio psychedelic four dimensional three hour tour. For the most dramatic, exciting and captivating political story ever told! With some of the greatest performances in CaptainBlackbeard Radio history.

In this broadcast, we explore America on it’s finest day, American elections and just how far can they bend?

Read more ...

Danger Mouse and Sparklehorse: Dark Night Of The Soul

July 7, 202281 words1 min read     

The security racket

June 16, 2022223 words2 mins read

*This article was initially a note but I decided to move it here.

Hertzbleed definitely looks like the latest entry in the security racket, it always goes the same way:

  • Find some unremarkable side channel. Bonus points if it’s something that’s always been known but nobody cared about (Spectre, BadUSB).
  • Try your luck with the USENIX reviewers. After enough attempts, you’ll probably get lucky enough when you get a dumb enough panel to accept your quite unremarkable paper.
  • As soon as you get the acceptance notice, buy a custom domain and hire a graphic designer (or five, preferably Jony Ive being one of them) for a “cool” logo.
Read more ...

Hardcore Movie Week

June 3, 20221238 words6 mins read

I had some more-than-usual free time lately so I’ve been watching a lot of movies. Below are just the ones that got on the list of my favorite movies, the names of the others will be forgotten.

Dersu Uzala
Dersu Uzala
Directed by Akira Kurosawa in 1975, Dersu Uzala is a portrait of the friendship between a Russian surveyor and an aging Nanai hunter.

By the way, if you were impressed (just like I was) by Maxim Munzuk, the actor that plays Dersu Uzala, you should really read this 4-part article by his daughter, Svetlana Munzuk, (part 1, part 2, part 3, part 4).

Life can’t be stopped, that means that time can’t be stopped either. The saying - a time for everything - is not in vain. It really is like that: everybody is born in his own time and lives in his own times. Maxim Munzuk

Read more ...

Captain Blackbeard Radio #14

April 22, 2022244 words2 mins read

MERRY 4/20 TO YE ALL! Yaaaaaaaarrrrrrr!

The Unclean Serene Unseen Offscreen Obscene Is In Episode Fourteen!

THE FINEST SOUNDS AROUND FROM THE UNDERGROUND

IT BE THE END OF THE WORLD!

CaptainBlackbeard Radio invites ye, to an audio psychedelic four dimensional three hour tour. The entire world shutters and braces itself, facing the most horrifying species extinction level crisis imaginable. Missiles are currently in the air, in Episode 14!

In this broadcast, we explore Modern War in the 21st Century.

Read more ...

Pentesting setup: Burp, Android and Macbook M1

April 10, 2022395 words2 mins read

Setting up a pentesting environment on a Macbook M1 for an Android device is really easy and you can intercept in Burp Suite all the requests sent from the device. Let’s do that.

  1. You will need Android Studio, make sure you download the ARM version. Yes, we all hate Google.

  2. Open Android Studio and create a device using an API level that is supported by modern applications (for example Pixel 2, API 32, arm64-v8a architecture), or leave the default device (Pixel_3a_API_32_arm64-v8a).

  3. Launch the emulator using your device name (that you specified in the step above, remember to replace YOUR_USER with your actual macOS username; in my case, the username is the name of my pet horse, Twinkles; just kidding, that’s the name of my pet fish, my pet horse is named Fondue):

$ cd /Users/YOUR_USER/Library/Android/sdk/emulator
$ ./emulator -avd Pixel_3a_API_32_arm64-v8a -writable-system
Read more ...

Cellebrite UFED 4PC (capabilities and a bonus)

April 9, 20221421 words7 mins read

This article might look like an ad but trust me, it’s not. I suggest you stick around until the end of the article, there will be a small-ish surprise.

In case you’re not familiar with Cellebrite, they are an Israeli digital intelligence company that provides tools for federal, state, and local law enforcement as well as enterprise companies and service providers to collect, review, analyze and manage digital data.

Cellebrite UFED 4PC is a universal hardware and software package for forensic research that makes it possible to extract, decode and analyze digital data obtained from mobile devices on an existing PC or laptop. The complex is delivered with a set of UFED applications, peripherals and accessories necessary for successful research. UFED 4PC can work both independently and with third-party software.

Read more ...

Enrique Bunbury: Expectativas

April 8, 2022212 words1 min read     

Spring Core RCE 0-day vulnerability

March 30, 2022157 words1 min read

Earlier today we got a hint that a new Spring Core RCE might be available, well, now it’s confirmed. Additional info (PDF file, in Chinese by original author).

Vulnerability impact

  • JDK version 9 and above.
  • uses Spring Framework or derivative framework.

Bug fixes

At present, the Spring maintainers have not released a patch and it is recommended to use a lower JDK version as a temporary solution.

PoC (download)

Read more ...

Globant (and customers) leak by Lapsus$ Group

March 30, 2022357 words2 mins read

Lapsus$ is back and on fire, today we got a new leak today with Globant.com admin credentials and a 70GB torrent from Globant customers. Keep in mind that no torrent files are hosted on this website.

Globant is an IT and Software Development company operating in Argentina, Colombia, Uruguay, the United Kingdom, Brazil, the United States, Canada, Peru, India, Mexico, Chile, Costa Rica, Ecuador, Spain, France, Germany, Romania and Belarus. It was formed in 2003 by Martín Migoya, Guibert Englebienne, Martín Umaran and Néstor Nocetti. It was founded in Buenos Aires, but currently is headquartered in Luxembourg and principally serves clients in the United States and United Kingdom.

Original messages from Lapsus$ Group are below.

Read more ...