Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @andreyknvl
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @andreyknvl
-
Andrey Konovalov Retweeted
How complicated is cellular baseband firmware? At least this complicated: over 150K debugging messages across 932 directories and 2,775 files! Rebuilding the source code skeleton from Samsung S10's Shannon S5000 baseband debugging messages.https://github.com/grant-h/shannon_s5000 …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
Implemented a PoC for disabling kernel lockdown on Ubuntu via a keyboard emulated through USB/IP, CC
@mjg59https://github.com/xairy/unlockdown …Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
My patch to disable PCI device DMA in early boot to avoid gaps in IOMMU coverage just got merged to mainline, so here's a writeup of it: https://mjg59.dreamwidth.org/54433.html
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Linux kernel 5.5 includes kcov extension that allows to collect code coverage from background kernel threads: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=eec028c9386ed1a692aa01a85b55952202b41619 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
What I'm thinking reading this sad story of crit remote vuln introduced into all
#linux LTS kernels and still unfixed (now in your kernel)- this "forgot to release lock" is mostly solved problem today with static analysis. Kernel absolutely needs it as part of the dev process 1/nhttps://twitter.com/grsecurity/status/1220351582405042176 …Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Ported my old interactive USB keyboard script to the new FaceDancer, sent a PR: https://github.com/usb-tools/Facedancer/pull/30 … CC
@ktemkinThanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
Welcome
#Gerrit changes for#linux kernel: https://linux-review.googlesource.com/c/virt/kvm/kvm/+/1464 … and the mailing list version for contrast: https://lore.kernel.org/lkml/20200123180436.99487-1-bgardon@google.com/T/#TerryJones … Gerrit has side-by-side diffs, full expandable context, non-lossy comments attached to lines. Here are docs: https://linux.googlesource.com/Documentation/#gerrit-code-reviews-for-the-linux-kernel …Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
Wow, crazy issue bypasses PAN: Part of the uaccess routines (__arch_clear_user() and __arch_copy_{in,from,to}_user()) fail to re-enable PAN if they encounter an unhandled fault while accessing userspace. Check out the patch: https://lore.kernel.org/patchwork/patch/1157641/ …
@Liran_AlonShow this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
I have so many questions right now. You know
#Linux, right, the thing that runs the universe today? This FOU_ATTR_LOCAL_V6 wanted to say .len instead of .type: https://elixir.bootlin.com/linux/v5.4/source/net/ipv4/fou.c#L665 … This means this thing never-ever worked in any way. Any attempt to pass these args would...Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
========================= The Life and Incredible Adventures of One QEMU Bug (Which I Finally Fixed) ========================= A thread [1/n]
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
Week has passed... If you said 20+ you were right. 30 on dashboard (open+pending) https://syzkaller.appspot.com/upstream#open My local instance has 70(!): https://gist.githubusercontent.com/dvyukov/80548bcc0f577670e2d1b1c4a1e7fe49/raw/290c9063c915a01f9bd25d85b313619590529919/gistfile1.txt … All reachable by unpriv users That's not all. To find more we need to fix these first, otherwise it just keep crashinghttps://twitter.com/dvyukov/status/1217502660007546881 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
Got an OOPS? Figured out the type in the variable causing the oops? Got the offset? Deep in a sub struct? Got you covered with a new EXAMPLE: https://git.kernel.org/pub/scm/devel/pahole/pahole.git/commit/?id=277c2b3d1b4a12c9d4c5297a99e1f0c352685d78 …
#pahole#linux#bpf#btfThanks. Twitter will use this to make your timeline better. UndoUndo -
Nice talk about CFI in the Linux kernel by
@kees_cook Slides: https://outflux.net/slides/2020/lca/cfi.pdf … Video:https://www.youtube.com/watch?v=0Bj6W7qrOOI …Thanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
I'll make my tech report and poc public soon. It was a fun bug affecting most major distributions. one exploit to rule them all w/ all kernel expl mitigation bypasses - no rop chains / hardcoded crap https://duasynt.com/blog/ubuntu-centos-redhat-privesc …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
Brace yourselves, more netfilter bugs are coming! https://github.com/google/syzkaller/blob/master/sys/linux/socket_netlink_netfilter_nftables.txt … Bets on number of bugs in the first week
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
Nightmare is an intro to binary exploitation / reverse engineering course based around ctf challenges (binaries + writeups by hacking topics) https://github.com/guyinatuxedo/nightmare …
#reverse#exploitationThanks. Twitter will use this to make your timeline better. UndoUndo -
Linux Kernel Runtime Guard (LKRG) bypass collection by Ilya Matveychikov, CC
@Adam_pi3https://github.com/milabs/lkrg-bypass …Thanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
ROP/JOP pivoting to user space is now back in style https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24cecc37746393432d994c0dbc251fb9ac7c5d72 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Andrey Konovalov Retweeted
New blog post. ARM hardware bug. In the specification. https://siguza.github.io/PAN/
Thanks. Twitter will use this to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.