Sign in

Binni Shah

@binitamshah.bsky.social
943 followers 0 following 359 posts

Linux Evangelist, Malwares , Security Enthusiast, Investor, Contrarian , Neurology , Philanthropist , Reformist ,Sigma female

PostsRepliesMedia
Binni Shah @binitamshah.bsky.social · 21/05/2025
Linux Reverse Shell in x86 Assembly : rootfu.in/linux-revers...
rootfu.in
Linux Reverse Shell in x86 Assembly - ROOTFU.IN
Introduction: Why Build a Reverse Shell in Assembly? Ever wondered how low-level code can create a powerful remote shell? In this post, we’ll dive into crafting a Linux reverse shell using x86 assembl...
062
Binni Shah @binitamshah.bsky.social · 20/05/2025
300 Milliseconds to Admin: Mastering DLL Hijacking and Hooking to Win the Race (CVE-2025-24076 and CVE-2025-24994) : blog.compass-security.com/2025/04/3-mi...
052
Binni Shah @binitamshah.bsky.social · 20/05/2025
Bypassing kASLR via Cache Timing : r0keb.github.io/posts/Bypass... kASLR Internals and Evolution : r0keb.github.io/posts/kASLR-... credits @r0keb
033
Binni Shah @binitamshah.bsky.social · 20/05/2025
Cache poisoning via race-condition in Next.js : zhero-web-sec.github.io/research-and... credits @zhero___
022
Binni Shah @binitamshah.bsky.social · 20/05/2025
O2 VoLTE : Locating any customer with a phone call : mastdatabase.co.uk/blog/2025/05...
021
Binni Shah @binitamshah.bsky.social · 18/05/2025
Bypassing Web Filters (Part 4) : Host Header Spoofing & Domain Fronting Detection Bypasses : blog.compass-security.com/2025/03/bypa... 3 : Domain Fronting : blog.compass-security.com/2025/03/bypa... 2 : Host Header Spoofing : blog.compass-security.com/2025/03/bypa...
blog.compass-security.com
Bypassing Web Filters Part 4: Host Header Spoofing & Domain Fronting Detection Bypasses – Compass Security Blog
But – as you know – no system is perfect. This last post of the series discusses techniques that can sometimes be used to bypass domain fronting detection and prevention methods.
022
Binni Shah @binitamshah.bsky.social · 18/05/2025
Game Hacking : Part 1 - Land Of The PEB - Modules and DLLs : codeneverdies.github.io/posts/lotp-1/ Part 2 : Running from the debugger : codeneverdies.github.io/posts/lotp-2/ Part 3: BakkesMod : codeneverdies.github.io/posts/gh-1/ 4 : Valve Anti-Cheat (VAC) : codeneverdies.github.io/posts/gh-2/
codeneverdies.github.io
1. Land Of The PEB - Modules and DLLs
Welcome to my first series called “Land Of The PEB” where I will be discussing various topics related to the Process Environment Block (PEB). What is this thing? The Process Environment Block (we will...
030
Binni Shah @binitamshah.bsky.social · 18/05/2025
0-click RCE on Tesla Model 3 through TPMS Sensors : www.synacktiv.com/sites/defaul... credits @masthoon @vdehors
11010
Binni Shah @binitamshah.bsky.social · 17/05/2025
PE32 Ransomware : A New Telegram-Based Threat on the Rise : any.run/cybersecurit... credits @MauroEldritch
any.run
PE32 Ransomware: A New Telegram-Based Threat on the Rise  - ANY.RUN's Cybersecurity Blog
Read technical analysis of PE32, a new ransomware strain that demands ransom for both decryption and not leaking stolen data.
020
Binni Shah @binitamshah.bsky.social · 17/05/2025
Evolution of Tycoon 2FA Defense Evasion Mechanisms : Analysis and Timeline : any.run/cybersecurit...
020
Binni Shah @binitamshah.bsky.social · 17/05/2025
HTML to PDF Renderer : A tale of local file access and shellcode execution : neodyme.io/en/blog/html...
010
Binni Shah @binitamshah.bsky.social · 17/05/2025
Fileless Execution : PowerShell Based Shellcode Loader Executes Remcos RAT : blog.qualys.com/vulnerabilit...
002
Binni Shah @binitamshah.bsky.social · 17/05/2025
Breaking up-to-date Windows 11 BitLocker encryption -- on-device but software-only : neodyme.io/en/blog/bitl...
030
Binni Shah @binitamshah.bsky.social · 17/05/2025
Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks : ethz.ch/en/news-and-... Ref : *Speculative calculations open a backdoor to information theft (*2022) : ethz.ch/en/news-and-... RETBLEED : www.usenix.org/system/files...
ethz.ch
ETH Zurich researchers discover new security vulnerability in Intel processors
Computer scientists at ETH Zurich discover new class of vulnerabilities in Intel processors, allowing them to break down barriers between different users of a processor using carefully crafted instruc...
051
Binni Shah @binitamshah.bsky.social · 17/05/2025
Mastering Rate Limit Bypass Techniques : infosecwriteups.com/mastering-ra...
infosecwriteups.com
Mastering Rate Limit Bypass Techniques
Learn How Hackers Bypass Rate Limits — and How You Can Too
010
Binni Shah @binitamshah.bsky.social · 17/05/2025
Hacking Casino - How Math Beats the Casino Odds : www.youtube.com/watch?v=87Fg... Shuffle Up and Deal: Analyzing the Security of Automated Card Shufflers : i.blackhat.com/BH-US-23/Pre... How To Rob a Casino : 0x00sec.org/t/how-to-rob...
youtube.com
Hacking Casino | How Math Beats the Casino Odds
YouTube video by Sumsub
020
Binni Shah @binitamshah.bsky.social · 17/05/2025
Writing a Self-Mutating Malware : 0x00sec.org/t/writing-a-... Metamorphic Code Examples : stackoverflow.com/questions/10...
0x00sec.org
Writing a Self-Mutating Malware
This topic was automatically closed after 121 days. New replies are no longer allowed.
033
Binni Shah @binitamshah.bsky.social · 17/05/2025
How To Rob a Casino : 0x00sec.org/t/how-to-rob...
0x00sec.org
How To Rob a Casino
Casinos, some view these places as something that corrupts the soul, leading individuals astray with the allure of easy money and instant gratification. Others see casinos as an escape from reality, s...
010
Binni Shah @binitamshah.bsky.social · 17/05/2025
macOS Malware Development (Part 2) : 0x00sec.org/t/macos-malw... Part 1 : 0x00sec.org/t/macos-malw... Ref : Inside a Hello World executable on OS X : adrummond.net/posts/macho The Mystery of Mach-O Object Structure : alexdremov.me/mystery-of-m... www2.cs.arizona.edu/~collberg/Te...
0x00sec.org
macOS Malware Development II
Today’s post is about writing fully custom malware targeting macOS. We’ll walk through its architecture, mutation techniques, and anti-analysis methods, with a focus on Mach-O internals and Darwin AP...
020
Binni Shah @binitamshah.bsky.social · 17/05/2025
Fuzzing Windows ARM64 closed-source binary : www.romainthomas.fr/post/25-04-w...
031
Binni Shah @binitamshah.bsky.social · 17/05/2025
Litterbox : Sandbox approach for malware developers and red teamers to test payloads against detection mechanisms before deployment : github.com/BlackSnufkin...
000
Binni Shah @binitamshah.bsky.social · 02/05/2025
Pupkin : a deceptively simple .NET-based stealer designed to harvest browser passwords, Discord tokens, and Telegram sessions — all controlled silently through a Telegram C2 : muff-in.github.io/blog/pupkin-...
muff-in.github.io
Pupkin: A Simple .NET Info-Stealer Exfiltrating Data via Telegram
Pupkin Stealer is a deceptively simple .NET-based stealer designed to harvest browser passwords, Discord tokens, and Telegram sessions — all controlled silently through a Telegram C2.
021
Binni Shah @binitamshah.bsky.social · 02/05/2025
Linux running in Excel : github.com/NSG650/Linux...
010
Binni Shah @binitamshah.bsky.social · 02/05/2025
felix86 : Run x86-64 programs on RISC-V Linux : github.com/OFFTKP/felix86
github.com
GitHub - OFFTKP/felix86: Run x86-64 programs on RISC-V Linux
Run x86-64 programs on RISC-V Linux. Contribute to OFFTKP/felix86 development by creating an account on GitHub.
010
Binni Shah @binitamshah.bsky.social · 01/05/2025
LigerLabs - Educational Modules for (Anti-)Reverse Engineering : ligerlabs.org
ligerlabs.org
Home
000
Binni Shah @binitamshah.bsky.social · 01/05/2025
Attacking My Landlord's Boiler : blog.videah.net/attacking-my...
010
Binni Shah @binitamshah.bsky.social · 01/05/2025
How I Found Malware in a BeamNG Mod : lemonyte.com/blog/beamng-...
lemonyte.com
How I Found Malware in a BeamNG Mod
An analysis using Process Monitor and WinDbg, dealing with JavaScript, WASM, and Windows shellcode.
010
Binni Shah @binitamshah.bsky.social · 01/05/2025
How I made $64k from deleted files — a bug bounty story : medium.com/@sharon.briz...
medium.com
How I made $64k from deleted files — a bug bounty story
TL;DR — I built an automation that cloned and scanned tens of thousands of public GitHub repos for leaked secrets. For each repository I…
021
Binni Shah @binitamshah.bsky.social · 01/05/2025
How a Single Line Of Code Could Brick Your iPhone : rambo.codes/posts/2025-0...
rambo.codes
How a Single Line Of Code Could Brick Your iPhone | Rambo Codes
Gui Rambo writes about his coding and reverse engineering adventures.
000
Binni Shah @binitamshah.bsky.social · 01/05/2025
AirBorne : Wormable Zero-Click RCE in Apple AirPlay Puts Billions of Devices at Risk : www.oligo.security/blog/airborne
012
Binni Shah @binitamshah.bsky.social · 01/05/2025
VectorKernel : PoCs for Kernelmode rootkit techniques research or education (Currently focusing on Windows OS. All modules support x64 family 64bit OS only) : github.com/daem0nc0re/V... credits @daem0nc0re
github.com
GitHub - daem0nc0re/VectorKernel: PoCs for Kernelmode rootkit techniques research.
PoCs for Kernelmode rootkit techniques research. Contribute to daem0nc0re/VectorKernel development by creating an account on GitHub.
021
Binni Shah @binitamshah.bsky.social · 01/05/2025
Digital Forensics Lab : Free hands-on digital forensics labs for students and faculty : github.com/frankwxu/dig...
github.com
GitHub - frankwxu/digital-forensics-lab: Free hands-on digital forensics labs for students and faculty
Free hands-on digital forensics labs for students and faculty - frankwxu/digital-forensics-lab
022
Binni Shah @binitamshah.bsky.social · 01/05/2025
tpotce : T-Pot - The All In One Multi Honeypot Platform : github.com/telekom-secu...
000
Binni Shah @binitamshah.bsky.social · 01/05/2025
JS-Tap : JavaScript payload and supporting software to be used as XSS payload or post exploitation implant to monitor users as they use the targeted application : github.com/hoodoer/JS-Tap Details : Weaponizing JavaScript for Red Teams : trustedsec.com/blog/js-tap-...
011
Binni Shah @binitamshah.bsky.social · 01/05/2025
Ghosting-AMSI : AMSI Bypass via RPC Hijack (NdrClientCall3) : github.com/andreisss/Gh...
000
Binni Shah @binitamshah.bsky.social · 01/05/2025
Yet Another NodeJS Backdoor (YaNB) : A Modern Challenge : www.trustwave.com/en-us/resour...
010
Binni Shah @binitamshah.bsky.social · 01/05/2025
Right-Click Execution - A Tale of Windows LNK NTLM Leak : zeifan.my/Right-Click-... Warm up : Windows LNK - Analysis & Proof-of-Concept : zeifan.my/Windows-LNK/
zeifan.my
Right-Click Execution - A Tale of Windows LNK NTLM Leak
OverviewI recently identified and responsibly disclosed a potential security issue affecting Windows LNK files (shortcuts). This issue impacts multiple versions of the Windows operating system, includ...
011
Binni Shah @binitamshah.bsky.social · 01/05/2025
cuddlephish : Weaponized multi-user browser-in-the-middle (BitM) for penetration testers : github.com/fkasler/cudd... Details : link.springer.com/article/10.1... credits @FKasler
000
Binni Shah @binitamshah.bsky.social · 01/05/2025
Fuzzing Windows ARM64 closed-source binary with QBDI and libFuzzer : www.romainthomas.fr/post/25-04-w...
romainthomas.fr
Fuzzing Windows ARM64 closed-source binary | Romain Thomas
This blog post introduces coverage-guided fuzzing with QBDI and libFuzzer targeting Windows ARM64.
020
Binni Shah @binitamshah.bsky.social · 01/05/2025
Pwning the Ladybird browser : jessie.cafe/posts/pwning...
020
Binni Shah @binitamshah.bsky.social · 01/05/2025
Pwning the Ladybird browser : jessie.cafe/posts/pwning...
010
Binni Shah @binitamshah.bsky.social · 01/05/2025
Linux Kernel Exploitation (CVE-2025-21756) : Attack of the Vsock : hoefler.dev/articles/vso... Source code for the exploit : github.com/hoefler02/CV...
021
Binni Shah @binitamshah.bsky.social · 01/05/2025
Drag and Pwnd : Leverage ASCII characters to exploit VS Code : portswigger.net/research/dra... credits @d4d89704243 ActiveScan++ : github.com/albinowax/Ac... Ref : WorstFit : Unveiling Hidden Transformers in Windows ANSI! : blog.orange.tw/posts/2025-0... credits @orange_8361
001
Binni Shah @binitamshah.bsky.social · 24/04/2025
How I Got Hacked : A Warning about Malicious PoCs : chocapikk.com/posts/2025/s... Full Dump : chocapikk.com/ioc/s1nk.zip credits @Chocapikk_
chocapikk.com
How I Got Hacked: A Warning about Malicious PoCs | Chocapikk's Cybersecurity Blog 🛡️💻
An in-depth forensic analysis of how a seemingly legitimate Proof-of-Concept (PoC) for CVE-2020-35489 turned out to be a cleverly disguised malware. This blog post details the attack vector, payload d...
162
Binni Shah @binitamshah.bsky.social · 24/04/2025
Zig Strike: The ultimate toolkit for payload creation and evasion : kpmg.com/nl/en/home/i... ZigStrike : a powerful Payload Delivery Pipeline (developed in Zig) offering a variety of injection techniques and anti-sandbox features : github.com/0xsp-SRD/Zig...
032
Binni Shah @binitamshah.bsky.social · 24/04/2025
NativeTokenImpersonate - a tool to impersonate users by stealing their tokens using only NTAPI functions : ricardojoserf.github.io/nativetokeni... Impersonate Tokens using only NTAPI functions : github.com/ricardojoser... credits @RicardoJoseRF
ricardojoserf.github.io
NativeTokenImpersonate - Token Impersonation using only NTAPIs
Tool to impersonate users by stealing their tokens using only NTAPI functions. It supports two types of impersonation, one similar to CreateProcessWithToken and the other to ImpersonateLoggedOnUser.
000
Binni Shah @binitamshah.bsky.social · 24/04/2025
Doppelganger : Cloning and Dumping LSASS to Evade Detection using RTCore64.sys, NtCreateProcessEx and MiniDumpWriteDump : vari-sh.github.io/posts/doppel...
vari-sh.github.io
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Technique for cloning and dumping LSASS to evade detection using RTCore64.sys, NtCreateProcessEx and MiniDumpWriteDump.
021
Binni Shah @binitamshah.bsky.social · 24/04/2025
Bypassing AMSI with Dynamic API Resolution in PowerShell : rootfu.in/bypassing-am...
020
Binni Shah @binitamshah.bsky.social · 24/04/2025
Deploy Hidden Virtual Machine For VMProtections Evasion And Dynamic Analysis : r0ttenbeef.github.io/Deploy-Hidde... credits @c_midnight1337
021
Binni Shah @binitamshah.bsky.social · 24/04/2025
Detecting C2-Jittered Beacons with Frequency Analysis : www.diegowritesa.blog/2025/04/dete...
000