Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. May 11, 2026: The Red Sun still prevails.

May 11, 2026: The Red Sun still prevails.

Scheduled Pinned Locked Moved Uncategorized
43 Posts 5 Posters 226 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • wdormann@infosec.exchangeW wdormann@infosec.exchange

    @jhr77 @christopherkunz @GossiTheDog
    Always revert your VM to a clean state before (and after) testing an exploit. 😂

    christopherkunz@chaos.socialC This user is from outside of this forum
    christopherkunz@chaos.socialC This user is from outside of this forum
    christopherkunz@chaos.social
    wrote last edited by
    #33

    @wdormann @jhr77 @GossiTheDog Meanwhile, slightly elsewhere: https://github.com/Nightmare-Eclipse/GreenPlasma
    Looking forward to seeing the writeup to this.
    https://github.com/Nightmare-Eclipse/YellowKey

    jhr77@mastodon.socialJ wdormann@infosec.exchangeW 3 Replies Last reply
    0
    • christopherkunz@chaos.socialC christopherkunz@chaos.social

      @wdormann @jhr77 @GossiTheDog Meanwhile, slightly elsewhere: https://github.com/Nightmare-Eclipse/GreenPlasma
      Looking forward to seeing the writeup to this.
      https://github.com/Nightmare-Eclipse/YellowKey

      jhr77@mastodon.socialJ This user is from outside of this forum
      jhr77@mastodon.socialJ This user is from outside of this forum
      jhr77@mastodon.social
      wrote last edited by
      #34

      @christopherkunz @wdormann @GossiTheDog Has this person also other hobbies than exploiting Windows?

      christopherkunz@chaos.socialC 1 Reply Last reply
      0
      • jhr77@mastodon.socialJ jhr77@mastodon.social

        @christopherkunz @wdormann @GossiTheDog Has this person also other hobbies than exploiting Windows?

        christopherkunz@chaos.socialC This user is from outside of this forum
        christopherkunz@chaos.socialC This user is from outside of this forum
        christopherkunz@chaos.social
        wrote last edited by
        #35

        @jhr77 @wdormann @GossiTheDog Well, they're certainly pissed at MS: "Microsoft has chosen to make this worst instead of resolving the situation like adults, they pulled every childish game possible. My patience is running out you're making everyone else paying for it."

        1 Reply Last reply
        0
        • christopherkunz@chaos.socialC christopherkunz@chaos.social

          @wdormann @jhr77 @GossiTheDog Meanwhile, slightly elsewhere: https://github.com/Nightmare-Eclipse/GreenPlasma
          Looking forward to seeing the writeup to this.
          https://github.com/Nightmare-Eclipse/YellowKey

          wdormann@infosec.exchangeW This user is from outside of this forum
          wdormann@infosec.exchangeW This user is from outside of this forum
          wdormann@infosec.exchange
          wrote last edited by
          #36

          @christopherkunz @jhr77 @GossiTheDog
          GreenPlasma prompts for admin creds, so to call it a privilege escalation is a stretch.

          As for YellowKey, the writeup is a bit too hand-wavy for me to follow, so I'll leave the repro to somebody else to try.

          Link Preview Image
          1 Reply Last reply
          0
          • wdormann@infosec.exchangeW wdormann@infosec.exchange

            @jhr77 @christopherkunz
            I suspect that Microsoft pushed out Defender updates that mitigate the exploit.

            With current definitions, I've not seen RedSun succeed. No matter how long I wait.

            With old definitions, success is pretty quick.

            buherator@infosec.placeB This user is from outside of this forum
            buherator@infosec.placeB This user is from outside of this forum
            buherator@infosec.place
            wrote last edited by
            #37
            @wdormann @jhr77 @christopherkunz I don't see a Defender entry in today's update that also points to this being a signature based mitigation
            wdormann@infosec.exchangeW 1 Reply Last reply
            0
            • buherator@infosec.placeB buherator@infosec.place
              @wdormann @jhr77 @christopherkunz I don't see a Defender entry in today's update that also points to this being a signature based mitigation
              wdormann@infosec.exchangeW This user is from outside of this forum
              wdormann@infosec.exchangeW This user is from outside of this forum
              wdormann@infosec.exchange
              wrote last edited by
              #38

              @buherator @christopherkunz @jhr77
              I can't imagine why they'd wait for Patch Tuesday if they already have the path to fix it automatically at any time they want. 🤷‍♂️

              buherator@infosec.placeB 1 Reply Last reply
              0
              • wdormann@infosec.exchangeW wdormann@infosec.exchange

                @buherator @christopherkunz @jhr77
                I can't imagine why they'd wait for Patch Tuesday if they already have the path to fix it automatically at any time they want. 🤷‍♂️

                buherator@infosec.placeB This user is from outside of this forum
                buherator@infosec.placeB This user is from outside of this forum
                buherator@infosec.place
                wrote last edited by
                #39
                @wdormann @christopherkunz @jhr77 Vuln mgmt is hard, e.g. how you track patch coverage vs. signature update status? Not that pushing a sig was a bad idea, I'd just expect a KB for this too.
                wdormann@infosec.exchangeW 1 Reply Last reply
                0
                • buherator@infosec.placeB buherator@infosec.place
                  @wdormann @christopherkunz @jhr77 Vuln mgmt is hard, e.g. how you track patch coverage vs. signature update status? Not that pushing a sig was a bad idea, I'd just expect a KB for this too.
                  wdormann@infosec.exchangeW This user is from outside of this forum
                  wdormann@infosec.exchangeW This user is from outside of this forum
                  wdormann@infosec.exchange
                  wrote last edited by
                  #40

                  @buherator @christopherkunz @jhr77
                  Right. There is no official statement that the vulnerability was actually fixed.

                  I personally believe that it was fixed, as I can no longer reproduce the exploit with updated definitions.

                  I suspect that others in this thread do not agree with me.

                  Would be nice to have a definitive answer.

                  wdormann@infosec.exchangeW 1 Reply Last reply
                  0
                  • wdormann@infosec.exchangeW wdormann@infosec.exchange

                    @buherator @christopherkunz @jhr77
                    Right. There is no official statement that the vulnerability was actually fixed.

                    I personally believe that it was fixed, as I can no longer reproduce the exploit with updated definitions.

                    I suspect that others in this thread do not agree with me.

                    Would be nice to have a definitive answer.

                    wdormann@infosec.exchangeW This user is from outside of this forum
                    wdormann@infosec.exchangeW This user is from outside of this forum
                    wdormann@infosec.exchange
                    wrote last edited by
                    #41

                    @buherator @christopherkunz @jhr77
                    Related: In Microsoft's world, CVEs are identifiers for software updates released on Patch Tuesday (or OOB through the same channel), not vulnerabilities. They used to have proprietary identifiers for their software updates, like MS08-067, but when they switched to using CVEs, they didn't switch what the identifiers are for.

                    As such, I could imagine why they didn't think a CVE was necessary for the vulnerability that allowed the RedSun exploit to work.

                    1 Reply Last reply
                    0
                    • christopherkunz@chaos.socialC christopherkunz@chaos.social

                      @wdormann @jhr77 @GossiTheDog Meanwhile, slightly elsewhere: https://github.com/Nightmare-Eclipse/GreenPlasma
                      Looking forward to seeing the writeup to this.
                      https://github.com/Nightmare-Eclipse/YellowKey

                      jhr77@mastodon.socialJ This user is from outside of this forum
                      jhr77@mastodon.socialJ This user is from outside of this forum
                      jhr77@mastodon.social
                      wrote last edited by
                      #42

                      @christopherkunz @wdormann @GossiTheDog What the h... is that yellowkey? I am a little bit afraid to try it. It sounds that it should be better prepared not on a windows system and tested on a completely separate pc.

                      wdormann@infosec.exchangeW 1 Reply Last reply
                      0
                      • jhr77@mastodon.socialJ jhr77@mastodon.social

                        @christopherkunz @wdormann @GossiTheDog What the h... is that yellowkey? I am a little bit afraid to try it. It sounds that it should be better prepared not on a windows system and tested on a completely separate pc.

                        wdormann@infosec.exchangeW This user is from outside of this forum
                        wdormann@infosec.exchangeW This user is from outside of this forum
                        wdormann@infosec.exchange
                        wrote last edited by
                        #43

                        @jhr77 @christopherkunz @GossiTheDog
                        I've not been able to reproduce YellowKey in a VMware Workstation VM.

                        So either VMware is interfering with the hold CRTL and do NOT lift your finger off it apparently required part of the exploit, or it simply doesn't work.

                        Even if it did work, I suspect that it'd perhaps only work on systems that don't both with PIN-on-boot protection. Which is sort of known to be not terribly secure.

                        1 Reply Last reply
                        1
                        0
                        • R relay@relay.infosec.exchange shared this topic
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups