@yunsu_dev I once got my bug patched before the contest due to someone report it to the vendor and even once got duplicated because some team write down every bug they found even the one that not used or they not exploited it yet 😂 that's the game and you all have to face it.
@yunsu_dev There is nothing wrong with report your bug to the vendor or any bug bounty program so you can at least get some reward for your finding. I don't know why people keep saying that "revenge" report like it a bad behaviour.
Confirmed! @ExLuck99 and @gr4ss341 of ANHTUD chained two vulnerabilities (CWE‑125 and CWE‑122) to achieve code execution on the Sony XAV‑9500ES, earning $10,000 USD and 2 Master of Pwn points in Round 3. #Pwn2Own#P2OAuto
Verified! Nao and @ExLuck99 from ANHTUD used a heap-based buffer overflow to exploit the Lexmark CX532adwe, but we penalized for a rules violation. The still earn $10,000 and 2 Master of Pwn points. #Pwn2Own
Confirmed! ChatGPT helped Team ANHTUD as they used 3 bugs - 1 collision, 1 unique SSRF and 1 cleartext storage of sensitive information - to exploit Home Automation Green. They finished with just 45 seconds remaining. Their work earns them $16,750 and 3.75 Master of Pwn points. #Pwn2Own
Blog for ToolShell
Disclaimer: The content of this blog is provided for educational and informational purposes only.
https://t.co/gT0aoKXkig
#SharePoint#ToolShell
Sadly, I can't get to Berlin in time for P2O. So, just stay at home with an <(´= ⩊ =`)> elf in my Triton console. Good luck to all contestants out there.
🧵
Mega thread on RF, SDR, ham radio, and signal hacking:
I've been writing educational posts and threads on these topics.
To help finding them easier, I will put all the links here.
And I will link the new threads to the bottom of this meta thread every time I write one.
0/n
Confirmed! We were definitely thrilled to see @ExLuck99 and @greengrass19000 of ANHTUD use a command injection bug to exploit the Alpine IVI and leave us a special message. Their round 2 win earns them $10,000 and 2 Master of Pwn points. #P2OAuto