unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
I Thought I Found a Prime Pattern That Breaks RSA
I didn’t. But working out why taught me more about RSA than any tutorial ever did, because i...
2026-7-17 11:24:57 | 阅读: 15 |
收藏
|
????Blog of Osanda - osandamalith.com
mathrm
equiv
varphi
pmod
wheel
I Thought I Found a Prime Pattern That Breaks RSA
I didn’t. But working out why taught me more about RSA than any tutorial ever did, because i...
2026-7-17 11:24:57 | 阅读: 3 |
收藏
|
????Blog of Osanda - osandamalith.com
mathrm
equiv
varphi
pmod
buckets
Inside a TradingView Phishing Kill Chain: Dissecting a Self-Hosted ScreenConnect Phishing Campaign
It started with a well-timed email: “Welcome! Your Free 1-Month Trial Has Started,” brand...
2026-7-7 22:58:38 | 阅读: 31 |
收藏
|
????Blog of Osanda - osandamalith.com
sig
windows
microsoft
2026
Inside a TradingView Phishing Kill Chain: Dissecting a Self-Hosted ScreenConnect Phishing Campaign
It started with a well-timed email: “Welcome! Your Free 1-Month Trial Has Started,” brand...
2026-7-7 22:58:38 | 阅读: 0 |
收藏
|
????Blog of Osanda - osandamalith.com
sig
windows
microsoft
client
RtlRegisterWait Shellcode Execution PoC
嗯,用户让我总结一篇文章的内容,控制在100字以内,而且不需要特定的开头。首先,我需要理解这篇文章的内容。看起来这是一个关于RtlRegisterWait Shellcode执行的概念验证代码。 作者是Osanda Malith Jayathissa,文章中有一个C程序,使用了ntdll.dll中的RtlRegisterWait和RtlDeregisterWait函数。程序创建了一个事件句柄,然后注册了一个回调函数,这个回调函数就是shellcode。当事件被触发时,shellcode就会执行。 所以,总结的时候需要包括几个关键点:RtlRegisterWait的使用、Shellcode作为回调、事件触发执行。同时要保持简洁,不超过100字。 可能的结构是:介绍作者和代码目的,说明使用了哪些函数,以及执行过程。确保语言简洁明了。 </think> 文章展示了一个利用`RtlRegisterWait`函数执行Shellcode的概念验证代码。作者通过创建事件句柄并注册回调函数(即Shellcode),实现了在事件触发时执行Shellcode的功能。...
2025-10-18 20:3:17 | 阅读: 28 |
收藏
|
????Blog of Osanda - osandamalith.com
shellcode
hevent
hwait
RtlRegisterWait Shellcode Execution PoC
123456789101112131415161718192021222324252627282930313233343536373839404142434...
2025-10-18 20:3:17 | 阅读: 0 |
收藏
|
????Blog of Osanda - osandamalith.com
shellcode
hevent
hwait
Executing Shellcode with ReadDirectoryChanges’s Hidden Callback
文章介绍了一种利用Windows API `ReadDirectoryChanges` 的异步回调机制来注入和执行恶意代码的方法。通过将shellcode嵌入可执行文件并注册为回调函数,在特定文件操作触发时,内核会调用该shellcode在主线程中执行,实现隐蔽攻击。...
2025-9-25 21:4:18 | 阅读: 21 |
收藏
|
????Blog of Osanda - osandamalith.com
shellcode
overlapped
hdir
Executing Shellcode with ReadDirectoryChanges’s Hidden Callback
While digging into the ReadDirectoryChanges API, I noticed it supports an asynchronous callb...
2025-9-25 21:4:18 | 阅读: 0 |
收藏
|
????Blog of Osanda - osandamalith.com
shellcode
overlapped
hdir
Encrypting Shellcode using SystemFunction032/033
After a while, I’m publishing a blog post which made me interested. With the recent tweets a...
2022-11-11 06:50:7 | 阅读: 360 |
收藏
|
osandamalith.com
shellcode
0x8b
puchar
Encrypting Shellcode using SystemFunction032/033
After a while, I’m publishing a blog post which made me interested. With the recent tweets a...
2022-11-10 22:50:7 | 阅读: 0 |
收藏
|
????Blog of Osanda - osandamalith.com
shellcode
0x8b
puchar
Executing Shellcode via Callbacks
In simple terms, it’s a function that is called through a function pointer. When we pass a...
2021-04-01 09:27:16 | 阅读: 102 |
收藏
|
osandamalith.com
shellcode
oldprotect
windows
0377400434
Executing Shellcode via Callbacks
In simple terms, it’s a function that is called through a function pointer. When we pass a...
2021-4-1 00:27:16 | 阅读: 1 |
收藏
|
????Blog of Osanda - osandamalith.com
shellcode
oldprotect
windows
Hacking the World with HTML
123456789101112131415161718192021222324252627282930313233343536373839404142434...
2020-07-20 06:01:11 | 阅读: 51 |
收藏
|
osandamalith.com
newfilename
payload
rdonly
buff
Exploring the MS-DOS Stub
A long time ago when I got my first computer, I accidentally opened a 32-bit demo with a nic...
2020-07-20 01:23:46 | 阅读: 91 |
收藏
|
osandamalith.com
lfanew
cx
bh
paragraphs
mz
Hacking the World with HTML
In my previous article Exploring the MS-DOS Stub I stated that after experimenting, the Wind...
2020-7-19 21:1:11 | 阅读: 1 |
收藏
|
????Blog of Osanda - osandamalith.com
windows
php
lfanew
rundll32
bypass
Exploring the MS-DOS Stub
A long time ago when I got my first computer, I accidentally opened a 32-bit demo with a nic...
2020-7-19 16:23:46 | 阅读: 0 |
收藏
|
????Blog of Osanda - osandamalith.com
lfanew
bh
cx
10h
ah
My Journey into eCXD – eLearnSecurity Certified eXploit Developer
I first want to thank eLearnSecurity for creating such a course on this topic of exploit d...
2020-06-25 21:10:56 | 阅读: 93 |
收藏
|
osandamalith.com
windows
shellcode
explains
bypass
internals
My Journey into eCXD – eLearnSecurity Certified eXploit Developer
I first want to thank eLearnSecurity for creating such a course on this topic of exploit d...
2020-6-25 12:10:56 | 阅读: 0 |
收藏
|
????Blog of Osanda - osandamalith.com
windows
shellcode
explains
bypass
internals
WMI 101 for Pentesters
PowerShell has gained popularity with SysAdmins and for good reason. It’s on every Windows m...
2020-02-27 00:07:26 | 阅读: 47 |
收藏
|
osandamalith.com
reverse
osanda
security
researching
WMI 101 for Pentesters
PowerShell has gained popularity with SysAdmins and for good reason. It’s on every Windows m...
2020-2-26 15:7:26 | 阅读: 1 |
收藏
|
????Blog of Osanda - osandamalith.com
powershell
windows
wql
caption
cimv2
Previous
1
2
3
4
5
6
7
8
Next