Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @ifsecure
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @ifsecure
-
Ivan Fratric proslijedio/la je Tweet
Just published a follow-up to my Adobe Reader symbols story on the Project Zero blog. Turns out there's even more debug metadata to be found in some old (and new) builds, including private CoolType symbols. Enjoy! https://googleprojectzero.blogspot.com/2020/01/part-ii-returning-to-adobe-reader.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Our research on Safari's Intelligent Tracking Prevention (ITP) is now available on https://research.google/pubs/pub48871/ cc
@arturjanc@kkotowicz@empijeipic.twitter.com/JvbLIhGDXd
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
SLOP - A Userspace PAC Workaround https://bugs.chromium.org/p/project-zero/issues/detail?id=1933 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Quick reminder that we're still updating the "0day detected in-the-wild" spreadsheet here: https://googleprojectzero.blogspot.com/p/0day.html . The first entry for 2020 is now in the books -- CVE-2019-17026 is a type confusion issue in the JIT engine for Firefox, detected in active attacks by Qihoo 360 ATA.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
I'm very excited to share my blogpost series (including PoC code) about a remote, interactionless iPhone exploit over iMessage: https://googleprojectzero.blogspot.com/2020/01/remote-iphone-exploitation-part-1.html …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
At Google Project Zero, the team spends a *lot* of time discussing and evaluating vulnerability disclosure policies and their consequences. It's a complex and controversial topic! Here's P0's policy changes for 2020 (with our rationale for the changes): https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Kudos to the GPZ team for their willingness to explore new vulnerability disclosure policies in addition to doing great research :) At the risk of wading into a disclosure debate (plz no), I think these policy changes will help improve customer safetyhttps://twitter.com/itswillis/status/1214595438113886209 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
I've recently been fuzzing the PHP interpreter, and took a UaF bug all the way from crashing-sample to weaponized code execution. Here is the first of several blog posts I plan to write about the process. https://blog.jmpesp.org/2020/01/fuzzing-php-with-domato.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Slides + recording of my
#36c3 talk: https://saelo.github.io/presentations/36c3_messenger_hacking.pdf … https://media.ccc.de/v/36c3-10497-messenger_hacking_remotely_compromising_an_iphone_through_imessage … had to omit many details, but blogpost coming soon!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Writeup on how I made $40,000 breaking the new Chromium Edge using essentially two XSS flaws.https://leucosite.com/Edge-Chromium-EoP-RCE/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
A nice write-up on WinAFL setup for fuzzing popular image viewers resulting in quite a few bugs.https://www.apriorit.com/dev-blog/644-reverse-vulnerabilities-software-no-code-dynamic-fuzzing …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Project Zero blog: "SockPuppet: A Walkthrough of a Kernel Exploit for iOS 12.4" by Ned Williamson (
@NedWilliamson) -- https://googleprojectzero.blogspot.com/2019/12/sockpuppet-walkthrough-of-kernel.html …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
New video! I'm talking with the bug bounty hunter
@wtm_offensi about a vulnerability he found in Google Cloud Shell. And the funny part is, Google even sponsored the video :D https://www.youtube.com/watch?v=E-P9USG6kLs …pic.twitter.com/wPmaFddgRM
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
IE: Use-after-free in JScript arguments during toJSON callback https://bugs.chromium.org/p/project-zero/issues/detail?id=1947 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Blog post on CVE-2019-2215, the Android binder bug that was exploited in-the-wild and affected most Android devices manufactured prior to Fall 2018. https://googleprojectzero.blogspot.com/2019/11/bad-binder-android-in-wild-exploit.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
I presented about Site Isolation in Google's event called
#bugSWAT
/ "The world of Site Isolation and compromised renderer"
Slide: https://speakerdeck.com/shhnjk/the-world-of-site-isolation-and-compromised-renderer …
Video:https://youtu.be/ppW_soCb6wM Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Here’s probably my favorite XSS of this year :) This is why we love legacy browser features like DOM Clobbering ;)https://twitter.com/securitum_com/status/1196340839418650625 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Awesome-AFL : A curated list of different AFL forks and AFL inspired
#fuzzers with detailed equivalent academic papers with AFL-fuzzing tutorials https://github.com/Microsvuln/Awesome-AFL …#awesome#AFL#fuzzers#Fuzzer#Awesome_AFL#AFL_forks#AFL_fuzzing_TutorialsPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ivan Fratric proslijedio/la je Tweet
Chrome: Site Isolation bypass and local file disclosure via Payment Handler API https://bugs.chromium.org/p/project-zero/issues/detail?id=1928 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Oh look, dangling terrorism and pedophilia to justify what is ultimately used for human right violation. It's not like we ever heard that one before.
https://twitter.com/campuscodi/status/1189299688140349442 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.