Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Bastian Buck

@bstnbuck@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

IT-Security Consultant - Malware Analyst - Network Security

5 Followers
74 Following
10 Posts
Joined December 29, 2022
Twitter:
https://twitter.com/bstnbuck
GitHub:
https://github.com/bstnbuck
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 1mo ago
A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; #CVE-2026-63030), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing… If you haven't already, update your Wordpress (preferably yesterday…) and also enable automatic updates for themes and plug-ins! I found several PHP backdoors/webshells (see @abuse_ch@ioc.exchange Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops@infosec.exchange and https://github.com/ruppde/yara_rules tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates. Hashes: 1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966 05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf 1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8 8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c 165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5 b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6 a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8 7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09
GitHub

GitHub - ruppde/yara_rules: Yara rules

Yara rules. Contribute to ruppde/yara_rules development by creating an account on GitHub.

1
0
0
0
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 41mo ago

Ever heard of side channel attacks?🤔
Especially with IoT crypto (car...), it could be potentially dangerous. In a course of my master program, I was able to successfully attack the AES alternative ChaCha20👏. More about this in our paper => https://github.com/bstnbuck/ChaCha20-CPA

And no, ChaCha20 as well as AES do not become insecure with that!😅 Countermeasures are available and can also be implemented. And with your own web server, this is not needed at all...

GitHub

GitHub - bstnbuck/ChaCha20-CPA: Correlation Power Analysis (CPA) Attack against ChaCha20

Correlation Power Analysis (CPA) Attack against ChaCha20 - bstnbuck/ChaCha20-CPA

2
0
3
0
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 21mo ago

VShred -- A simple tool to securely delete files and directories, implemented in #Vlang.
v1.4.0 with some performance improvements and better flag handling is released!
https://github.com/bstnbuck/VShred

infosec.exchange
0
0
1
0
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 29mo ago

The crypto hash function RIPEMD-160 ( can be found at Bitcoin among others), the block cipher Twofish (AES finalist, available in Veracrypt, key-sizes: 128, 192, 256 bit) and the lesser known IGE block cipher mode are now implemented in V-crypto!
https://github.com/bstnbuck/V-crypto

github.com
0
0
0
0
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 30mo ago

(X)#Salsa20 a stream cipher invented by Daniel J. Bernstein has now found its way to #v_crypto.

As a finalist in the #eSTREAM competition, it is still considered secure today and is very similar to the meanwhile better-known ChaCha stream cipher. Salsa20 is equipped with the number of rounds 8, 12, 20 and variable counters.. Implemented in pure #V!

https://github.com/bstnbuck/V-crypto/tree/main/salsa20

infosec.exchange
0
0
0
0
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 31mo ago

New crypto algorithms for the programming language #V!
The obsolete and insecure protocols (MD4, TEA, XTEA) are way easier to implement, but should not be used productively...
#vlang #v_crypto

https://github.com/bstnbuck/V-crypto

infosec.exchange
0
0
0
0
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 32mo ago

Without #passwords, almost nothing works online. Fact. I have created #PHAuiS, which provides an overview of software and the password hashing algorithms they use.

Contributions welcome!🙏
https://github.com/bstnbuck/PHAuiS

infosec.exchange
0
0
0
0
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 32mo ago

V's crypto library is growing again​. New additions are ChaCha20, Poly1305 and ChaCha20-Poly1305. Thanks to the contributors!
An overview of implemented and (by me) planned crypto algorithms, protocols, etc. I have created V-crypto.
https://github.com/bstnbuck/V-crypto

github.com
0
0
0
0
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 35mo ago

One of my customers received 4 #Pikabot downloaders in one day. E-mail with relevant content and an typical encrypted ZIP with JS file (downloader) attached. Really nice... not👏
https://bazaar.abuse.ch/sample/695b47d6854dd74bb9518cc1d967fba78af5f1970196e8c8ccdc4b9ab38280c6/
https://bazaar.abuse.ch/sample/92f83e84c416aa06317a952d94fb306263176d6670da3d69d94adff3ce3c4ad8/
https://bazaar.abuse.ch/sample/c6cc75415fa83b796c2e18c96024e37c4d1d9a348010510158d6f934a6c4714e/

bazaar.abuse.ch

MalwareBazaar | Checking your browser

0
0
0
0
Open post
Bastian Buck @bstnbuck@infosec.exchange
· 45mo ago

Simulate a kill chain with HereItsSoEasy and thus practice the case of emergency. All this in one Gist... Including ransomware, bind shell and dropper script.
https://gist.github.com/bstnbuck/bb34b62bb7599d29de32a92722889e11

gist.github.com
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 11:25:46 UTC