Opens profile photo
Follow
Click to Follow scwuaptx
Angelboy
@scwuaptx
HITCON CTF/217/
blog.angelboy.twJoined September 2012

Angelboy’s Tweets

My new blog post! Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”. Reverse engineering CVE-2022-34718 + write a remote Denial of Service exploit. Covers IPsec and IPv6 fragmentation in the Windows kernel, bin-diffing, and making weird packets
14
1,079
Show this thread
Our second #Pwn2Own champion and Master of Pwn! 🏆🏆🏆 This couldn't be done without the hard work of my superb teammates (, and our new blood )! Also, big thanks to for this great event 🎉
Quote Tweet
And that's a wrap! Congrats to DEVCORE and @orange_8361 for winning Master of Pwn for Toronto 2022. Thanks to all who participated and special thanks to #Google and #Synology for co-sponsoring the event.
Image
26
443
🔥 1/ In the last 6 months working on Linux kernel bug hunting/exploitation there has been a number of key resources which have been super useful (coming from a macOS/Windows background) to understand the state of things in 2022 🚀. Here's a short🧵 to recognise this + thoughts:
Image
8
615
Show this thread
I'm very glad to announce that we'll hold ACSC(Asian Cyber Security Challenge), a new international CTF for the young! This is a kind of qualification round, where the high achievers will be selected as the Asian representatives and compete in World Final!
1
44
Show this thread
Although I did not find useful vulnerabilities in other targets and other attacker surface, it was a good experience for me. The most important thing is that I learned a lot during the research. Hope I can find more vulnerabilities in the future.
Quote Tweet
I am surprised that we won the #Pwn2Own 2021 because we only registered for one entry. But we are actually the only team (out of 3 teams) got the full-win on Exchange Server! Thanks to the lucky draw results and my awesome @d3vc0r3 research team member @mehqq_ and @scwuaptx! twitter.com/thezdi/status/…
60
Archangel Michael's Storage : A segment heap challenge. In my intended solution, you need to corrupt _HEAP_PAGE_RANGE_DESCRIPTOR to create overlap chunk. More detail will release soon.
2
8
Show this thread
😖
Quote Tweet
Confirmed! The DEVCORE team of @orange_8361, @scwuaptx and @mehqq_ used an elegant heap overflow to get code execution on the #Synology NAS during their 2nd attempt. They earn themselves $20,000 and 2 Master of Pwn points.
Dawg This What We Do This Is What Were Meant To Do GIF
GIF
14