Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
Blokirali ste korisnika/cu @D0C_H0LL1D4Y
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @D0C_H0LL1D4Y
-
DPR3 proslijedio/la je Tweet
I recently left my position and I'm looking for consulting work. (Not looking for a full-time position.) Particularly interested in low-level security and development work, e.g. code audits, reverse engineering, exploit mitigations, LLVM development, etc.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
In those CET times: It's possible to return in unwinding to any address in the SSP, causing a "type confusion" between stack frames ;) I really like the different variants of this concept https://twitter.com/AmarSaar/status/1211565530286632960 …:) Type confusions are on fire! (stack frames, objc for PAC bypass)https://twitter.com/yarden_shafir/status/1217728223355817986 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
New blogpost: Sanitized Emulation with QEMU-AddressSanitizer https://andreafioraldi.github.io/articles/2019/12/20/sanitized-emulation-with-qasan.html … I just open-sourced my QEMU patches to fuzz binaries with ASan, QASan. You can also use it with ARM targets on Linux, a thing that you can't do with LLVM ASan!
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
DPR3 proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Yet another great vuln by
@qualys CVE-2019-19726. wideOpenBSD local rootHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Did I really just forget my LUKS password?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
An amazing video about "Arbitrary Code Execution in Zelda Ocarina of Time". Also great editing to show the complex memory interactions!https://www.youtube.com/watch?v=RoEmGCNsbno …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
Maersk didn't have a single backup up their 100 global domain controllers. Designed to backup to each other, they could lose 1 or 25 DCs & be fine. They just couldn't lose all of them. Miraculously,
@a_greenberg said at#CYBERWARCON, a serendipitous blackout in Ghana saved 1 DC.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
I've just written a performant in-memory fuzzing module with
@fridadotre for AFL++ https://github.com/andreafioraldi/frida-js-afl-instr …. Watch AFL++ on GH and stay tuned for a frida_mode in the next days!pic.twitter.com/4FHZbsi0Fy
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
What I found interesting 1/3: Deep Analysis of Exploitable Linux Kernel Vulnerabilities 2017-2019 https://www.youtube.com/watch?v=MYEAGmP_id4 … With some overview and deep dive into several real exploits. Including
#bpf, SMAP, exploiting races. 1/3https://twitter.com/LinuxSecSummit/status/1192601742854119424 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
A random bit of trivia I remembered recently. Got a DOS box with a password protected BIOS and no tools handy? Corrupt CMOS checksum with this simple command and get inside after reboot: echo “dummy” > CLOCK$
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
Static analysis to determine object sizes allocated by various syscalls to perform kernel SLAB/SLUB layout manipulation, enabling exploitation. 30 new N-day exploits coming, abstract includes link to a sample set of exploits. https://twitter.com/blackhatevents/status/1189333619229233153 …
Tweet je nedostupan.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Anyone know if IDA Pro sends all binaries to a remote server to help with “improvements” for future releases?
@ilfakHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
Kernel privilege escalation bug in Android affecting fully patched Pixel 2 & others. Reported under 7 day deadline due to evidence of in-the-wild exploit.
@tehjh and I quickly wrote a POC to get arbitrary kernel r/w using this bug, released in tracker. https://bugs.chromium.org/p/project-zero/issues/detail?id=1942 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
DPR3 proslijedio/la je Tweet
geohot is back - just for checkm8:https://www.youtube.com/watch?v=0f21HU2Lr2o …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je Tweet
Apparently Apple kernel 0day (I don’t have a test machine for Apple). thread_set_state() is called on current thread (illegal according to docs) in 32bit process with all registers set to 0xffffffff other than gs=23. Exploit bypasses SMEPhttps://twitter.com/piedpiper1616/status/1174132817690628097 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
DPR3 proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
DPR3 proslijedio/la je Tweet
Add NT API’s grammars to Domato, then use
@TinySecEx engine to run generated Code via chakra. CC@ifsecurepic.twitter.com/MqZ9kHNCq4
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.


