Felix aka [xi-tauw]

@PsiDragon

Windows Privilege Escalator

in da web
Vrijeme pridruživanja: prosinac 2010.

Tweetovi

Blokirali ste korisnika/cu @PsiDragon

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @PsiDragon

  1. 11. pro 2019.

    cc , I bet you like CVE-2019-19247

    Prikaži ovu nit
    Poništi
  2. 11. pro 2019.

    Writeup for EOP for Windows Origin client. (CVE-2019-19247 и CVE-2019-19248) Rus - Eng -

    Prikaži ovu nit
    Poništi
  3. 1. lis 2019.

    Writeup for third Steam vulnerability. but not this time, already patched. Rus - Eng -

    Poništi
  4. 13. ruj 2019.

    Third reported vulnerability has been fixed in main client. Hurray.

    Poništi
  5. 27. kol 2019.

    Unbanned on h1. So try do new report there.

    Poništi
  6. proslijedio/la je Tweet
    26. kol 2019.

    August - Steam Client Update released. Finally a fix for the local privilege escalation vulnerability - ;-)

    Poništi
  7. 26. kol 2019.

    If someone from Valve () read this, please DM me. Yep, another vulnerability at Steam.

    Poništi
  8. 22. kol 2019.

    3/3. Now it is Valve's turn to do something. Since status the same, it means Valve has do nothing for changing it. It is still Valve's work. Am I right, Matt ?

    Prikaži ovu nit
    Poništi
  9. 22. kol 2019.

    2/3. Today I was told that Valve not take any action to dispute CVE. So, the status was set based on my article. First reason for "DISPUTED" is H1-Valve rejection of the report. I provided my position to CVE team when request the CVE.

    Prikaži ovu nit
    Poništi
  10. 22. kol 2019.

    1/3. It seems we need some clarification about CVE-2019-14743 and status "DISPUTED". FAQ says the status means "When one party disagrees with another party's assertion that a particular issue in software is a vulnerability".

    Prikaži ovu nit
    Poništi
  11. proslijedio/la je Tweet
    21. kol 2019.
    Odgovor korisniku/ci

    Hey, you are win!) Valve was changed his political for LPE bugs.) Now LPE bugs in scope.

    Poništi
  12. 21. kol 2019.

    Valve is patching something. I'll wait for main client update.

    Poništi
  13. proslijedio/la je Tweet
    21. kol 2019.

    Many have seen me criticise lately, which has lead some Epic apologists call me a Steam fanboy. Well, I think it's about time the Valve apologist be angry at me, because what follows won't be pretty. In the words of , you done fucked it up, .

    Prikaži ovu nit
    Poništi
  14. 21. kol 2019.

    I request CVE for the last one Steam's eop. Got two in reply: CVE-2019-15316 is mine and CVE-2019-15315 for Xiaoyin Liu's

    Poništi
  15. 20. kol 2019.
    Poništi
  16. 20. kol 2019.
    Prikaži ovu nit
    Poništi
  17. 20. kol 2019.

    Valve banned me on their H1 program. So... I release new EoP vulnerability at Steam. Another . Rus - Eng -

    Prikaži ovu nit
    Poništi
  18. proslijedio/la je Tweet
    15. kol 2019.

    I found a way to bypass the fix. The bypass requires dropping a file in a nonadmin-writable location, so I think it's out-of-scope for Valve. Write-up: cc

    Poništi
  19. 13. kol 2019.

    Main client got update On first sight - all regsetsecurity has been removed. Will look in few days. cc

    Poništi
  20. proslijedio/la je Tweet
    11. kol 2019.

    The fix for the Steam LPE: The service now checks for registry symlinks by iterating through subkeys under the Steam key & calls RegQueryValueEx with a check for the "SymbolicLinkValue" key value.

    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·