Save the Environment (Variable)

For my link archive as this is environment variable override trick to override DLL loading is not just limited to executables shipping with Windows, but also with other products (likely: virus scanners that run privileged); another alternative is running a local process serving the WebDAV protocol.

TL;DR – By manipulating environment variables on process level, it is possible to let trusted applications load arbitrary DLLs and execute malicious code. This post lists nearly 100 executables vulnerable to this type of DLL Hijacking on Windows 11 (21H2); it is demonstrated how this can achieved with just three lines of VBScript.

[Wayback/Archive] Save the Environment (Variable)

Via:

–jeroen

#DEFCON30

Microsoft Windows - Wikipedia

The more I read about #defcon #badge drama, I get the idea that the Defcon organization didn't know what they we're getting into creating such a badge. Because the 2022 badge for #Defcon30 was a lot more simple and different team. So I have doubts about the capabilities of #defcon32 badge team.

And that the outsource partner Entropic Engineering should have said 'Nope, this will not work.' Or at least stopped working when the money was used. But I can't find anything about previous work of EE.

#DEFCON30 talk by Michael Bargury & Lana Salameh | #DArT30

Title: Powerpwn: An offensive/defensive security toolset for Microsoft 365 Power Platform.

Link to talk > πŸ“Ίhttps://www.youtube.com/watch?v=e8PEIOa6W9M

Link to tool > βš™οΈhttps://github.com/mbrg/power-pwn

More details > πŸ“°https://github.com/DefconParrot/DefconArsenalTools/blob/main/exploitation/DC30/powerpwn.md

DEF CON 30 - Michael Bargury - No-Code Malware - Windows 11 at Your Service

YouTube

Back by popular demand! Be there or be square! πŸ“¦ πŸ‘Ύ

Pick up your badge in our DEF CON Village, doors open 8/11/23 at 10:00 AM!

blacksincyberconf.com/bic-village

#BlacksInCyber #BIC_Village #BIC_CTF #BlacksInCybersecurity #DEFCON31 #DEFCON #DEFCON30 #BadgeLife

Back by popular demand! Be there or be square! πŸ“¦ πŸ‘Ύ

Pick up your badge in our DEF CON Village, doors open 8/11/23 at 10:00 AM!

blacksincyberconf.com/bic-village

#BlacksInCyber #BIC_Village #BIC_CTF #BlacksInCybersecurity #DEFCON31 #DEFCON #DEFCON30 #BadgeLife

Sneak peak πŸ‘€ BIC CTF 2023 @ DEFCON 31 is here & CTF ROOM will be hosting!

The challenge will begin on Fri Aug 11th, 12PM PDT/10PM EAT & end on Sat 12th, 5PM PDT/3AM EAT.

blacksincyberconf.com/ctf

#BlacksInCyber #BIC_Village #BIC_CTF#BlacksInCybersecurity #DEFCON31 #DEFCON #DEFCON30 #BadgeLife

Sneak peak πŸ‘€ BIC CTF 2023 @ DEFCON 31 is here & CTF ROOM will be hosting!

The challenge will begin on Fri Aug 11th, 12PM PDT/10PM EAT & end on Sat 12th, 5PM PDT/3AM EAT.

blacksincyberconf.com/ctf

#BlacksInCyber #BIC_Village #BIC_CTF#BlacksInCybersecurity #DEFCON31 #DEFCON #DEFCON30 #BadgeLife

Sneak peak πŸ‘€ BIC CTF 2023 @ DEFCON 31 is here & CTF ROOM will be hosting!

The challenge will begin on Fri Aug 11th, 12PM PDT/10PM EAT & end on Sat 12th, 5PM PDT/3AM EAT.

blacksincyberconf.com/ctf

#BlacksInCyber #BIC_Village #BIC_CTF#BlacksInCybersecurity #DEFCON31 #DEFCON #DEFCON30 #BadgeLife

Sneak peak πŸ‘€ BIC CTF 2023 @ DEFCON 31 is here & CTF ROOM will be hosting!

The challenge will begin on Fri Aug 11th, 12PM PDT/10PM EAT & end on Sat 12th, 5PM PDT/3AM EAT.

blacksincyberconf.com/ctf

#BlacksInCyber #BIC_Village #BIC_CTF#BlacksInCybersecurity #DEFCON31 #DEFCON #DEFCON30 #BadgeLife

The BIC Lituation Networking Session will begin at 6:00 PM PST in the BIC VillageπŸ“Caesars Forum! Meet the team with light food, drinks & music!

https://lnkd.in/gEqAqKC

#BlacksInCyber #BIC_Village #BIC_CTF #BlacksInCybersecurity #DEFCON31 #DEFCON #DEFCON30

LinkedIn

This link will take you to a page that’s not on LinkedIn