Andrea Fioraldi

@andreafioraldi

Msc CE @ CTF with & . malweisse on IRC. Binary stuffs, programming languages and fuzzing.

Italy
Vrijeme pridruživanja: lipanj 2017.

Medijski sadržaj

  1. prije 9 sati
    Odgovor korisnicima i sljedećem broju korisnika:
  2. From a discussion with , I noticed that this check in was removed in the 5.x kernel. Does any kernel hacker know why? Accessing the stack belop SP remains a bug IMO.

  3. 25. sij
    Odgovor korisnicima

    Lulz booted, was my fault, I didn't unpoison the kmalloc buffer at init and Serenity does several reboots (with triple faults) so when allocating memory at the second boot the memory allocated at the first boot was incorrectly flagged as UAF.

  4. 25. sij
    Odgovor korisniku/ci

    Now I don't know If QASan is bugged or if there is a UAF at startup in SerenityOS

  5. 25. sij

    This morning I decided to experiment a bit with QASan in full system mode. It works with a small firmware and now I'm trying to boot a patched SerenityOS. You can find my attempts here:

    Prikaži ovu nit
  6. 14. sij

    Suppose that with CVE-2020-0601 a state-actor can insert malicious code in win updates. Now suppose that NSA is backdooring the patch using the vuln itself and it disclosed the vuln to force all to install the backdoored patch. Can we call it vuln-inception?

    Prikaži ovu nit
  7. 2. sij

    Porn pic of 23.10

  8. 1. sij

    New stickers for the new laptop: Dragon Book and Sci-Hub. Two sources of knowledge for my studies that I like so much.

  9. 30. pro 2019.

    was a blast! Here with the crew we are toasting in honor of these amazing 4 days. Cheers to all old and new friends here, see u next year/defcon/somewhere!

  10. 22. pro 2019.

    Real electronic music, love it

  11. 19. pro 2019.

    I'm fuzzing an old libxml2 for known vulns. IDK if they will trigghered cause they were found with libFuzzer+ASan but at least frida-fuzzer can do binary-only fuzzing of the libxml's API and it is a good thing to know.

    Prikaži ovu nit
  12. 26. stu 2019.

    Inject & fuzz with + QBDI on Android x86_64. I've to test this against real apps with parsing API, any suggestions?

  13. 21. stu 2019.
  14. 16. stu 2019.

    I've just written a performant in-memory fuzzing module with for AFL++ . Watch AFL++ on GH and stay tuned for a frida_mode in the next days!

    Prikaži ovu nit
  15. 16. stu 2019.

    New laptop, I've immediately installed the only software that I need.

  16. 26. lis 2019.

    1m 22s of fuzzing on my laptop to trigger the abort in this snippet:

    Prikaži ovu nit
  17. 13. lis 2019.

    echo "export LD_PRELOAD=/home/andrea/AFLplusplus/libdislocator.so" >> /etc/profile

  18. 16. ruj 2019.

    pnginfo.exe (+libpng.dll) under Wine is a piece of cake with AFL++ QEMU. Of course CompareCoverage is enabled, maybe it's time to fuzz some Windows binaries in the spare time.

    Prikaži ovu nit
  19. 12. ruj 2019.
    Odgovor korisniku/ci
  20. 12. ruj 2019.

    Seems that fuzzing lodepng in QEMU mode with 8100 exec/s is now possible with AFL++ ... Persistent mode is coming <3 (ps. plain QEMU is circa 1400 exec/s, not persistent LLVM is circa 3900 exec/s)

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·