Network Security News Summary for Monday May 24th, 2021
Phishing without Server; Anti-Debugging; WinRM exposes http.sys; Firefox Exploit
Serverless Phishing Campaign
https://isc.sans.edu/forums/diary/Serverless+Phishing+Campaign/27446/
Locking Kernel32.dll As Anti-Debugging Technique
https://isc.sans.edu/forums/diary/Locking+Kernel32dll+As+AntiDebugging+Technique/27444/
WinRM Vulnerable to http.sys Vulnerability
I finally found time to answer my own question. WinRM *IS* vulnerable. This really expands the number of vulnerable systems, although no one would intentionally put that service on the internet.
— Jim DeVries (@JimDinMN) May 19, 2021
Mozilla Firefox “Content-Type Confusion” Unsafe Code Execution
Mozilla Firefox “Content-Type confusion” – Unsafe code execution
keywords: mozilla; firefox; winrm; anti-debugging; serverless; phishing
by Internet Storm Center Stormcast
linux smtp server