Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @flat_z
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @flat_z
-
this trick may work on other crypto hw as well if it doesn't restrict key lengths
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
a crypto flaw was in ability to issue hmac operation with key length < 16, for example, by setting it to 1 you can bruteforce key bytes one by one by comparing hmac result with hmac result with known partial key, see code in gist
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Thanks. Twitter will use this info to make your timeline better. UndoUndo
-
so, PS4 Crypto Coprocessor (CCP) interface in secure kernel had a bug that allowed us to dump (or better saying, bruteforce) key slots from SAMU, that's how AES/HMAC keys from PFS, portability keys, VTRM keys, etc could be retrieved on unpatched firmware:https://gist.github.com/flatz/22215327864d7512e52268f9c9c51cd8 …
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Alexey Kulaev Retweeted
Small write-up about AES key extraction in TSEC // Nintendo Switch You can read it here: https://gist.githubusercontent.com/plutooo/733318dbb57166d203c10d12f6c24e06/raw/15c5b2612ab62998243ce5e7877496466cabb77f/tsec.txt …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Alexey Kulaev Retweeted
Je Ne Sais Quoi - Falcons over the Horizon https://hexkyz.blogspot.com/2021/11/je-ne-sais-quoi-falcons-over-horizon.html … A blogpost/writeup on TSEC co-authored by
@hexkyz and myself. Enjoy!Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Alexey Kulaev RetweetedThanks. Twitter will use this info to make your timeline better. UndoUndo
-
Just dropped my project I've worked on for several years: https://github.com/flatz/pkg_pfs_tool … it's PS4 PKG/PFS unpacker, that can build GP4, generate all keys, etc
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Alexey Kulaev Retweeted
Chrome and Windows zero-day exploit chain used in the wild by PuzzleMaker APThttps://securelist.com/puzzlemaker-chrome-zero-day-exploit-chain/102771/ …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Two LPEs in McAfee Total Protection, well done :)https://twitter.com/Denis_Skvortcov/status/1394614314359828490 …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
hey Sony, why dealing with PS store UX is harder than writing an exploit for PS? a half of year have passed since introduction of new UI and the stupid bug is still here: i can't buy a game without clearing cookies/appcache each time...
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
usage: downgrade_elf.py --sdk-version 05.050.001 --verbose old.elf new.elf downgrade_sfo.py --sdk-version 05.050.001 --system-version 05.050.000 --verbose old.sfo new.sfo
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
two scripts i've made some time ago to downgrade ps4 elf/sfo to lower fw: https://pastebin.com/Jy2NNvhq https://pastebin.com/iGbHw5YX
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Alexey Kulaev RetweetedThanks. Twitter will use this info to make your timeline better. UndoUndo
-
Alexey Kulaev Retweeted
Here you are, https://hackerone.com/reports/826026 , PS4 kernel exploit for FW 7.02 and below. Vulnerability discovered on 2019-06-09. This must be chained together with a WebKit exploit, for example https://github.com/Fire30/bad_hoist … for FW 6.50.
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Analysis of two 0-days which we have found some time ago:https://securelist.com/the-zero-day-exploits-of-operation-wizardopium/97086/ …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Alexey Kulaev Retweeted
TIL: Windows Revocation Lists (STL, such as boot.stl and driver.stl) work with a "truncated hash" format that is always 16 bytes... to... save... memory
Here's an example. 1/2
cc @mattifestationpic.twitter.com/5T4B5YlJTy
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Alexey Kulaev Retweeted
It seems that nobody is able to implement ECC properlyhttps://twitter.com/NSAGov/status/1217152211056238593 …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Alexey Kulaev Retweeted
Also while I am on twitter :P https://github.com/Fire30/bad_hoist … PS4 Webkit exploit for 6.XX consoles. Gains addrof/fakeobj and arbitrary read and write primitives. Fixed in 7.00. Uses bug from: https://bugs.chromium.org/p/project-zero/issues/detail?id=1665 …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
sadly ccc is over, it was very cool to meet many friends in one place at
#36c3, I hope to see all of you next year, you're the best and one of the smartest people i know. happy new year!Thanks. Twitter will use this info to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.


