<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Blogs on ThreatCat.ch Blog</title>
    <link>https://www.threatcat.ch/blog/</link>
    <description>Recent content in Blogs on ThreatCat.ch Blog</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 07 Dec 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://www.threatcat.ch/blog/feed.xml" rel="self" type="application/atom+xml" />
    <item>
      <title>Encryption as Obfuscation</title>
      <link>https://www.threatcat.ch/blog/encryption-as-obfuscation/</link>
      <pubDate>Thu, 07 Dec 2023 00:00:00 +0000</pubDate>
      
      <guid>https://www.threatcat.ch/blog/encryption-as-obfuscation/</guid>
      <description>Some time ago, we analyzed a sample with an encrypted payload using an interesting technique. Unfortunately we can&amp;rsquo;t share the sample, and it isn&amp;rsquo;t available on Virustotal neither.</description>
    </item>
    
    <item>
      <title>When hunters become prey - CSTI (?) in Nuclei</title>
      <link>https://www.threatcat.ch/blog/when-hunters-become-prey/</link>
      <pubDate>Thu, 29 Jun 2023 00:00:00 +0000</pubDate>
      
      <guid>https://www.threatcat.ch/blog/when-hunters-become-prey/</guid>
      <description>TL;DR We discovered what we believe is a Client Side Template Injection (CSTI) vulnerability in Nuclei that allows an attacker to crash the scanner (Denial of Service - DoS) and, under certain circumstances, even leak secret keys.</description>
    </item>
    
    <item>
      <title>FENtastic chessadecimal encryPGN: Solution</title>
      <link>https://www.threatcat.ch/blog/fentastic-chessadecimal-encrypgn-solution/</link>
      <pubDate>Thu, 27 Apr 2023 00:00:00 +0000</pubDate>
      
      <guid>https://www.threatcat.ch/blog/fentastic-chessadecimal-encrypgn-solution/</guid>
      <description>This blog post shows different ways to solve the Capture the Flag (CTF) challenge posted on April 21, 2023.</description>
    </item>
    
    <item>
      <title>FENtastic chessadecimal encryPGN</title>
      <link>https://www.threatcat.ch/blog/fentastic-chessadecimal-encrypgn/</link>
      <pubDate>Fri, 21 Apr 2023 00:00:00 +0000</pubDate>
      
      <guid>https://www.threatcat.ch/blog/fentastic-chessadecimal-encrypgn/</guid>
      <description>We created a CTF to celebrate the World Chess Championship 2023 between Ian Nepomniachtchi and Ding Liren:</description>
    </item>
    
    <item>
      <title>Undo .NET Constant Obfuscation in IDA Pro</title>
      <link>https://www.threatcat.ch/blog/undo-dotnet-constant-obfuscation-in-ida-pro/</link>
      <pubDate>Thu, 09 Mar 2023 00:00:00 +0000</pubDate>
      
      <guid>https://www.threatcat.ch/blog/undo-dotnet-constant-obfuscation-in-ida-pro/</guid>
      <description>While .NET malware samples are usually easy to decompile using dnspy and similar tools, possibly after an initial unpacking step using dnspy&amp;rsquo;s debugger or a dedicated unpacker like ConfuserEx, there often remain additional &amp;ldquo;small&amp;rdquo; obfuscations of strings or constants.</description>
    </item>
    
  </channel>
</rss>
