yarh- there is a quote from the movie Donni Darko I find a fit here. Tell them to go fuck a suck. It takes time- I have to develop new tooling before it will rain again at my new focus. Thing is- you have to do something nobody have ever one before- by definiton!
-
This Tweet is unavailable.
-
-
Replying to @jonasLyk @SandboxBear
so by doing stuff that requires development of new tooling I increase my chances quite of lot- still need persistence, dedication, luck, skills and talent though. Exploit development is an art - an art where there is no middle ground, you find an exploitable vuln or you dont
1 reply 1 retweet 1 like -
This Tweet is unavailable.
-
Replying to @SandboxBear
1.5 months- preparing tooling and research- thats how it is. I mean- sure, I found a way to BSOD a Windows Sandbox remote with only needing access to create a file but its probaly sandbox specific. But if you wana go some ways not travelled much maybe:
1 reply 0 retweets 0 likes -
Replying to @jonasLyk @SandboxBear
DDE- nobody wanna go there, but its an IPC that can cross privelegie barriers and I suspect hides lots of vulnerabilities, it can even impersonate clients. Intel DAP applets, because what the world needed was a way do run java directly in ring -1 .
1 reply 0 retweets 0 likes -
Replying to @jonasLyk @SandboxBear
DAP applets should never have been created- but they are here, but I refuse to get used to them. When you think you reached the end destination on your travelling on road of stupidity you discover that there exist stuff like reimplementation of pkcs10 running as a DAP applet
1 reply 0 retweets 0 likes -
Replying to @jonasLyk @SandboxBear
This must be the final destination right? Nonono - you see, that applet.... why wouldnt it have a system service following it on its stupidity journey? Well- i mean, how else would you bridge a way directly to ring -1 from the users browser?
1 reply 0 retweets 0 likes -
Replying to @jonasLyk @SandboxBear
So yarh, browser extensions, one for firefox, one for ie and one for chrome- they talk to the service, that talk to to the applet. I havent checked, but ill bet ya there no auth nor auth for what sites that can talk to the applet. Also, there is a blueray decoder running as an
1 reply 0 retweets 0 likes -
Replying to @jonasLyk @SandboxBear
DAP applet, its crypto scheme do at least appear solid- but I doubt anybody ever did basic fuzzing nor just poking a bit around. First step would be a DAP java bytecode disassembler though. Just some suggestions if you wanna travel the roads not travelled much :)
1 reply 0 retweets 1 like
wait- did I say DAP I mean DALhttps://software.intel.com/content/www/us/en/develop/documentation/dal-developer-guide/top/architecture/architecture-applets.html …
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.