Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @_niklasb
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @_niklasb
-
Pinned Tweet
I wrote a thing about my macOS sandbox escape & LPE from Pwn2Own https://phoenhex.re/2019-05-26/attribution-is-hard-at-least-for-dock …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
@NedWilliamson how does it feel to drop 0d on Apple? You have good lawyers?Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
I just tested the jailbreak and it worked first try by the way
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
This is really bad for end users, combined with a webkit 1day (to be found in git repo), a full chain could have been built just with readily available bugs for almost a month now
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
apparently Apple undid a patch for @NedWilliamson's bug in 12.4?https://twitter.com/Pwn20wnd/status/1163102269518204930 …Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Niklas B Retweeted
In multiple recent disclosure discussions on Twitter, I had said I will write a longer blog post about my views. I finally found the time to jot them down. I expect almost every reader to disagree with something vehemently. Enjoy "Disclosure Rashomon": http://addxorrol.blogspot.com/2019/08/rashomon-of-disclosure.html …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Niklas B Retweeted
My stance on this: the increased Apple bounty *will* make more researchers report bugs rather than selling them. It will also drive the price for these bugs higher on the offensive market, but isn’t that the goal?
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Niklas B Retweeted
Today,
@5aelo and I unrestricted five bugs in iMessage! Here are some highlights:Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Niklas B Retweeted
Darf ich kurz um eure Aufmerksamkeit bitten. Zumindest dann, wenn ihr a) Lebensmittelverschwendung nicht ab könnt, oder b) in einer Lebenssituation mit nur wenig Geld zum Leben seid.
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
The new quickJS release already fixed some of the issue we found, pretty neat, maybe this will be the first reasonably safe JS engine? :) In the meantime here's a new UAF for your pwning pleasure: (() => { var pwn = {}; pwn.valueOf = () => pwn = 0; pwn++; })();
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Niklas B Retweeted
Results for the quickJS 0day challenge are out! Enjoy fresh ascii art, 0day and exploit techniques with curl http://rce.party/cracksbykim-quickJS.nfo … | less
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
did I hear 10x tennis player?
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Niklas B Retweeted
12. A 10x engineer is usually levitating, and farting out 1's and 0's as they whiteboard a proof that P=NP. They stopped sleeping before they were born. They are usually typing on two keyboards simultaneously.
Thanks. Twitter will use this to make your timeline better. UndoUndo -
If somebody has a way to do proper copy & paste in tmux that would already be a big step forward :>
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
WSL 2 is neat. Once Windows Terminal gets proper panes and clipboard support I might actually be able to use Windows to get work done
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Niklas B Retweeted
My iOS 12.2 exploit is now available! Thanks again to Brandon for his help in getting through the Mach trenches from BSD. https://bugs.chromium.org/p/project-zero/issues/detail?id=1806#c12 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Niklas B Retweeted
I wrote a thing about a Chakra RCE for which the JIT trigger is tweetable :) function opt(o) { o.pwn = o.a; } https://phoenhex.re/2019-07-10/ten-months-old-bug …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Niklas B Retweeted
Exploitation was a bit tricky because I had to upload the malicious language pack to http://addons.mozilla.org To bypass the manual review I turned RCE into UXSS to log into my own account on AMO and be able to access an unlisted LP (which only undergoes some automated tests)
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Exploitation was a bit tricky because I had to upload the malicious language pack to http://addons.mozilla.org To bypass the manual review I turned RCE into UXSS to log into my own account on AMO and be able to access an unlisted LP (which only undergoes some automated tests)
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
I reported some more sandbox issues, will probably write a blog post about this whole attack surface once everything is fixed
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.