ax  mX

@axi0mX

Bootrom exploit philanthropist. Apple silicon hacker. iOS jailbreaker. Join us as we dance madly on the lip of the volcano.

checkra.in
Joined October 2015

Tweets

You blocked @axi0mX

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @axi0mX

  1. Pinned Tweet
    27 Sep 2019

    EPIC JAILBREAK: Introducing checkm8 (read "checkmate"), a permanent unpatchable bootrom exploit for hundreds of millions of iOS devices. Most generations of iPhones and iPads are vulnerable: from iPhone 4S (A5 chip) to iPhone 8 and iPhone X (A11 chip).

    Show this thread
    Undo
  2. Retweeted
    Apr 15

    I'm happy to finally share my writeup on weird things you can do with multicast protocols. Packets Remystified: Broadcast Brujería

    Undo
  3. Retweeted
    Apr 14

    Small but mighty! This is a video of a killer T cell of the immune system destroying a monstrous ovarian cancer cell. I recently captured this data on a spinning disc confocal microscope.

    Show this thread
    Undo
  4. Retweeted
    Apr 14
    Undo
  5. Retweeted
    Apr 15

    may i present to you, ✨her✨

    Show this thread
    Undo
  6. Retweeted
    Apr 14

    thinking about how we've fallen so far from gods light. in 1994, a pc magazine writer tasked with covering doom bit their lip, thought a little, and said "i should put a complete map editing tutorial in there. maybe next to the cheat codes"

    Show this thread
    Undo
  7. Retweeted
    Apr 14

    I just learned that *THIS* is the sudo logo and I'm going back to logging in as root for everything.

    Show this thread
    Undo
  8. Retweeted
    Apr 15

    could not for the life of me figure out how to buy a bus ticket in Milan. it was literally easier to get a shell 😆

    Undo
  9. Retweeted
    Apr 13

    What flips your bit? I've written a new "This Week in Glean" blog post where I look for evidence of cosmic radiation in Mozilla telemetry data:

    Undo
  10. Retweeted
    26 May 2020

    buckle down for the least satisfying memory safety debugging story ever

    Show this thread
    Undo
  11. Retweeted

    share your debugging stories 🐛

    Show this thread
    Undo
  12. Retweeted
    Apr 11

    low level hacking: accidentally becoming a world expert on a very specific thing only like 8 other people know about (including the developers)

    Undo
  13. Retweeted
    Apr 14

    How much does it cost to improve ventilation? TLDR Start at 2.1 air changes/hour (ACH), 10 CFM/person Increase to >8 ACH, 40 CFM/person It costs $17/person/year. I'm not kidding. $17/person/year can be the difference between awful and amazing ventilation. 1/10

    Show this thread
    Undo
  14. Retweeted
    Apr 14

    Enterprise security. The comment happens to be about Comcast/Xfinity, but I feel like it's pretty common to see this kind of thing at large companies in general, which is one reason I find it hilarious when companies advertise "enterprise-grade security"

    His experience is similar to one I had a long while back when trying to report to Comcast that I found one of their sysadmin's home directory on GitHub. It had ssh keys, passwords, configs, scripts, etc etc. When I reported it on their support forum, some random dude responded basically saying I found nothing, insulting me, etc. It's wild to me how quickly people will go to insult in these situations.

I ended up making a big stink elsewhere and they got the repo down. Funny enough, their heads of security told me they'd use my disclosure to push the execs into building a big bounty program. Long story short, their CISO told me on the phone that what I found wasn't a "bug", and that if they did a bug bounty program, they'd go bankrupt.
    Show this thread
    Undo
  15. Retweeted
    Apr 13

    my typical day at Google: 9am - reverse a linked list 11am - count unique ways to climb a staircase with dp 12pm - lunch 3pm - help animal escape NxM matrix efficiently 4pm - invert a binary tree 5pm - commute home using Dijkstra's

    Show this thread
    Undo
  16. Retweeted
    Apr 14

    Continuing my look back at interesting vulnerabilities from last year here are some edited notes from my analysis of CVE-2021-1782, a rather subtle race condition vulnerability in the XNU vouchers subsystem found exploited in-the-wild last January:

    Undo
  17. Retweeted
    Apr 13
    Replying to

    Mom can I hack iOS? No we have iOS at home IOS at home:

    Undo
  18. Retweeted
    Apr 13
    Undo
  19. Retweeted
    Apr 12

    Pilot (to my 5-year-old daughter a few days ago): Do you know you could be a flight attendant when you grow up? 5: I could also own the plane.

    Show this thread
    Undo
  20. Retweeted
    Apr 13

    TIL that a lot of heatsinks are made with a process called 'skiving', which basically means 'scraping' fins out of the base material. I always thought they were milled or extruded! Original video:

    Show this thread
    Undo
  21. Retweeted
    Apr 12

    If you've tried using fancy semantic search tools for C, but gave up and stuck with grep... trust me, the tool you've been looking for is weggli. No setup or config needed, and it's not formal or heavyweight.

    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·