Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @ThomasKing2014
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @ThomasKing2014
-
Thomas King proslijedio/la je Tweet
From a discussion with
@MeBeiM , I noticed that this check in https://elixir.bootlin.com/linux/v4.20.17/source/arch/x86/mm/fault.c#L1383 … was removed in the 5.x kernel. Does any kernel hacker know why? Accessing the stack belop SP remains a bug IMO.pic.twitter.com/nbKf8LEHNf
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
TeamViewer (all versions) keys lead to password extraction, not hashed. TeamViewer stored user passwords encrypted with AES-128-CBC with key: 0602000000a400005253413100040000 and iv of 0100010067244F436E6762F25EA8D704 - in the Windows registry.https://whynotsecurity.com/blog/teamviewer/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
Just published a follow-up to my Adobe Reader symbols story on the Project Zero blog. Turns out there's even more debug metadata to be found in some old (and new) builds, including private CoolType symbols. Enjoy! https://googleprojectzero.blogspot.com/2020/01/part-ii-returning-to-adobe-reader.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
macOS/iOS: ImageIO: heap corruption when processing malformed TIFF image https://bugs.chromium.org/p/project-zero/issues/detail?id=1952 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
RT - Many Releases! HTool Beta 1 for macOS & iOS: https://h3adsh0tzz.com/projects/htool/ Mach-O Helper Toolset for iOS (arm64): https://h3adsh0tzz.com/projects/macho-toolset/ … Libhelper for macOS, iOS & Linux: https://h3adsh0tzz.com/projects/libhelper/releases/ … And a quick blog post summarising it all: https://h3adsh0tzz.com/2020/01/htool-beta-1-release/ …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
I'll make my tech report and poc public soon. It was a fun bug affecting most major distributions. one exploit to rule them all w/ all kernel expl mitigation bypasses - no rop chains / hardcoded crap https://duasynt.com/blog/ubuntu-centos-redhat-privesc …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
WeChat: Memory corruption in CAudioJBM::InputAudioFrameToJBM https://bugs.chromium.org/p/project-zero/issues/detail?id=1948 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
SLOP - A Userspace PAC Workaround https://bugs.chromium.org/p/project-zero/issues/detail?id=1933 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Again, more features can be abused. If someone wanna know how to R/W kernel memory directly without any syscalls. Check out my previous slide: https://www.blackhat.com/docs/asia-18/asia-18-WANG-KSMA-Breaking-Android-kernel-isolation-and-Rooting-with-ARM-MMU-features.pdf …. And the Linux kernel patch: https://www.openwall.com/lists/kernel-hardening/2018/05/30/5 …https://twitter.com/s1guza/status/1214359148474830859 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
My talk on iMessage exploitation (https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10497.html …) starts in two hours. You can watch it in room Ada or on https://streaming.media.ccc.de/36c3
#36c3Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
New blogpost: Sanitized Emulation with QEMU-AddressSanitizer https://andreafioraldi.github.io/articles/2019/12/20/sanitized-emulation-with-qasan.html … I just open-sourced my QEMU patches to fuzz binaries with ASan, QASan. You can also use it with ARM targets on Linux, a thing that you can't do with LLVM ASan!
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
Happy to announce that our paper “Automatic Techniques to Systematically Discover New Heap Exploitation Primitives” got accepted ,
@USENIXSecurity!#usesec20!Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
[BLOG] A Deep Dive Into Samsung's TrustZone (Part 2) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-2.html … by
@NeatMonster_,@patateQbool and@pandasec_Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
Simplest and strangest sandbox escape I've found in Chrome was just derestricted https://crbug.com/1000002
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
macOS: Kernel use-after-free due to race condition in wait_for_namespace_event() https://bugs.chromium.org/p/project-zero/issues/detail?id=1937 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
In the 1st of our Top 5 bugs for 2019,
@hosselot takes a look at a sandbox escape in#Firefox originally submitted to the program by@_niklasb. Read the details at http://bit.ly/2M0XatD#ZDITop5Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
I repropose my notes about x86, Linux and virtualization in a single text file (~2500 lines only) for my fellow students in Sapienza. https://gist.githubusercontent.com/andreafioraldi/c6ab4765a3821bc6f07537ad4cdafa9e/raw/4351fe1e6235daf85647ad34d2b50df20a21da63/asov_checkshit_singlefile.txt …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Thomas King proslijedio/la je Tweet
Linux: privilege escalation via io_uring offload of sendmsg() onto kernel thread with kernel creds https://bugs.chromium.org/p/project-zero/issues/detail?id=1975 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thomas King proslijedio/la je Tweet
CVE-2019-13734, CVE-2019-13750, CVE-2019-13751, CVE-2019-13752, CVE-2019-13753 WebSQL, 3 of them were used on TFC(https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html …).
Sorry due to responsible disclosure I didn't reply to some DMs a few days eariler about asking me what I used on TFC.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.