Here's a repository of all the code and tools I developed to explore this attack surface.https://github.com/taviso/ctftool
-
-
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
I saw some websites claim that, but I think it's a mistake, it doesn't really seem right. My theory is it's just CTextFramework, but that's just a guess!
- Još 6 drugih odgovora
Novi razgovor -
-
-
This is cool, nice find. Do MS plan to patch this one, e.g. the local user to SYSTEM issue?
-
Thanks! Yes, although it remains to be seen how thoroughly, it was quite a journey
https://bugs.chromium.org/p/project-zero/issues/detail?id=1859 … - Još 5 drugih odgovora
Novi razgovor -
-
-
I like the quote: Sometimes, hacking is just someone spending more time on something than anyone else might reasonably expect
-
Hah, I stole it from
@jgamblin
- Još 2 druga odgovora
Novi razgovor -
-
-
Did they miss the deadline again or did a partial/complete patch ?
-
They literally left it until the last second, so I haven't been able to review the patches yet. It's my understanding that the patch won't be complete, but will fix the most important vectors. I haven't seen the patch yet, so I'm not certain.

- Još 2 druga odgovora
Novi razgovor -
-
-
Impressive research and a very well written post (as always)! A minor correction: s/where it's stack/where its stack/
-
Thanks! Fixed.
Kraj razgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
research today, a major design flaw in Windows that's existed for almost *two decades*. I wrote a blog post on the story of the discovery all the way through to exploitation.