Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Security Research Labs

@srlabs@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

We are SRLabs, a hacking research collective and consulting think tank. Follow us to stay on top of the latest hacking research.

0 Followers
0 Following
11 Posts
Joined December 08, 2022
Open post
Security Research Labs @srlabs@infosec.exchange
· 6mo ago

We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)

Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.

For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.

https://srlabs.de/blog/hacking-ai-agent

#AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure

srlabs.de
37
0
46
1
Open post
Security Research Labs @srlabs@infosec.exchange
· 15mo ago

Unveiled at #TROOPERS25 - Hexagon fuzzing unlocked

Hexagon is the architecture in Qualcomm basebands - they power most of the world's leading smartphones.

Until now, this baseband was out of reach.

We released the first open-source toolchain for system-mode Hexagon fuzzing, presented by Luca Glockow (@luglo@infosec.exchange), Rachna Shriwas, and Bruno Produit (@bruno@social.pileus.ch) at @WEareTROOPERS@infosec.exchange

Full post: https://www.srlabs.de/blog-post/hexagon-fuzz-full-system-emulated-fuzzing-of-qualcomm-basebands

How we opened up mobile firmware in 3 steps:
1. Boot real iPhone basebands with a custom QEMU fork
2. Rust-powered fuzzer controls execution via JSON configs
3. Ghidra integration maps coverage across threads

This brings full visibility to Qualcomm’s 4G/5G/GPS stacks.

Reproducible. Extendable. Open source.

Hexagon’s no longer off-limits - mobile security just got a lot more transparent.


🔗 Try it yourself: https://github.com/srlabs/hexagon_fuzz
📚 Docs: https://github.com/srlabs/hexagon_fuzz/blob/main/docs/reverse_engineering.md
🖥️ Slides from Troopers25: https://github.com/srlabs/hexagon_fuzz/blob/main/docs/talk/hexagon_fuzz_troopers2025.pdf
🛠️ Issues, ideas, or contributions? PRs welcome.

infosec.exchange
34
4
35
0
Open post
Security Research Labs @srlabs@infosec.exchange
· 29mo ago

New Research – #BogusBazaar, a sprawling criminal fake webshop network:

• 75,000+ domains
• 450,000+ credit cards
• 1 million fraud cases
• USD 50+ million in fake orders

We publish our insights together with an international team of journalists from Die Zeit (Germany), The Guardian (United Kingdom), and Le Monde (France).

https://www.srlabs.de/blog-post/bogusbazaar

infosec.exchange
53
0
85
0
Open post
Security Research Labs @srlabs@infosec.exchange
· 18mo ago

Currently available Go fuzzing tools were missing critical features - some don’t play well with the latest Go toolchain. So we set out to change that.

@bruno@social.pileus.ch, Nils Ollrogge, and colleagues explored more powerful ways to fuzz Go binaries. By tapping into Go’s native instrumentation — which is compatible with libFuzzer — we enabled effective fuzzing of Go code using LibAFL.

We’ve documented our approach and shared insights in our latest blog post: https://www.srlabs.de/blog-post/golibafl---fuzzing-go-binaries-using-libafl

Repo: https://github.com/srlabs/golibafl

srlabs.de
17
4
19
0
Open post
Security Research Labs @srlabs@infosec.exchange
· 29mo ago

After months of intensive research, we are ready to drop new insights on yet another criminal group.

You might want to pick up a copy of Die Zeit (German), The Guardian (English) or Le Monde (French) tomorrow ;)

Stay tuned for updates!

37
0
28
0
Open post
Security Research Labs @srlabs@infosec.exchange
· 25mo ago

It has long been known that timing analyses are a *theoretical* attack on Tor. By distributing the circuits across different jurisdictions, the goal was to make these attacks impractical to implement:

Only a "global adversary" should be able to break the anonymity by correlating the traffic from entry and exit nodes. Correlation becomes even easier if delays or content can be actively introduced into the traffic pattern.

Just as we could (theoretically) become a "global adversary" by renting enough servers, law enforcement agencies can (practically) achieve this through close cooperation, especially since Tor nodes are not evenly distributed across jurisdictions but tend to cluster in certain regions.

Western law enforcement agencies seem to have reached the "global adversary" level through collaboration (in isolated cases and certainly with significant effort). What is problematic for Tor is that other "law enforcement agencies," whose focus is on dissidents, whistleblowers, and journalists, could do the same.

So, it is finally time for cover traffic and random delays: nodes in the Tor network would introduce a random traffic background noise as well as random delays to make targeted correlations more difficult. This would make Tor even slower. This is probably why it has been avoided until now.

In conclusion, we would like to emphasize that there is no reason for regular users of the Tor browser to worry about their anonymity. These are highly targeted attacks on individual accounts of the messenger "Ricochet" over extended periods of time. Because the messenger, unlike a browser, is also reachable, it naturally has an increased attack surface for timing analyses.

https://www.tagesschau.de/investigativ/panorama/tor-netzwerk-100.html

tagesschau.de
14
0
15
0
Open post
Security Research Labs @srlabs@infosec.exchange
· 27mo ago

Our Red Team regularly challenges Fortune 500 defenses. Often times, a decent ADCS honeypot could have stopped us.

So we built one.

Blog post: https://www.srlabs.de/blog-post/certiception-the-adcs-honeypot-we-always-wanted

Source code: https://github.com/srlabs/Certiception/

Presentation at @WEareTROOPERS@infosec.exchange, including a strategic guide to deception: https://github.com/srlabs/Certiception/blob/main/documentation/The_Red_Teamers_Guide_To_Deception.pdf

srlabs.de
4
0
4
0
Open post
Security Research Labs @srlabs@infosec.exchange
· 33mo ago

Unlocked - Ransomware edition 🔓🔧

Our colleague Tobias rocked the stage at #37C3 releasing your free decryptor for Black Basta – Germany's "second most used ransomware."

Watch the full talk including cryptographic kung fu: https://media.ccc.de/v/37c3-11903-unlocked_recovering_files_taken_hostage_by_ransomware

You can find the decryptor on Github: https://github.com/srlabs/black-basta-buster

For a closer look at our Black Basta research, stay tuned for a detailed blog post!

Bust Black Basta with the Black Basta Buster, basta!

infosec.exchange
5
0
2
0
Open post
Security Research Labs @srlabs@infosec.exchange
· 32mo ago

SRLabs joins Allurity!

We joined Allurity, a group of seven cyber pioneers across Europe. Starting SRLabs Chapter 2 today!

Over the past decade, our team of SRLabs hacking wizards helped clients all over the world push the envelope on hacking resilience.

In Allurity, we found a partner with a shared vision of how IT security should be done. Very happy to join forces with some of Europe’s greatest in our mission to bring effective security to innovation leaders.

Together, we continue fusing hacking with consulting, while exploring technology through research – just a bit more of everything.

A special thank you to our SRLabs teammates and alumni who made SRLabs Chapter 1 an ever-exciting journey!

Looking forward to the next chapter – together with our Allurity sisters!
@CSIS @Securix @Aiuken @IDNorth @Arcticgroup @cloudcomputing

https://allurity.com/cybersecurity-group-allurity-strengthens-its-position-through-the-acquisition-of-globally-recognized-srlabs/

allurity.com
2
0
1
0
Open post
Security Research Labs @srlabs@infosec.exchange
· 37mo ago

We have 6 solves so far on our SRLabs hacking challenges!🔓
As expected, the #telco challenge is the hardest to crack.

Do you want to hack a telco network or try the crypto and pwn categories?
https://hackingchallenge.srlabs.de

Running until 21.09
Discord: https://discord.gg/vusPXQzhVa

#ctf

infosec.exchange
1
0
1
0
Open post
Security Research Labs @srlabs@infosec.exchange
· 35mo ago

Meet @iyskierka@infosec.exchange Security Consultant at SRLabs! Watch her video where she shares her work experiences and OSCP study tips. 🔒💻
https://youtu.be/AzoZ1gnIo9Y?si=2zYbXtPHpkB3wUAo

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:58:32 UTC