Microsoft is preparing to kill many known KASLR bypasses in the next release.
Unless the calling process has debug privilege enabled, kernel addresses will be stripped from the output data for all leaking NtQuery APIs
A bit late but here is the writeup for the Fourchain challenge series from HITCON 2022, where we chain exploits for Chrome, Linux and Virtualbox. Enjoy! https://t.co/vGP5W8OMPB
@HaboobSa@jack_halon Wow that was a disappointment. You should at least reference other blogs that have done a better job explaining the vulnerability…
Today I am releasing part 2 of my 3-part browser exploitation series on Chrome!
In part 2, we take a deep dive into the V8 compiler pipeline by understanding what happens under the hood in Ignition, Sparkplug, and TurboFan!
Enjoy!
https://t.co/XAnbzdnjeQ
Today I am finally releasing a new 3-part browser exploitation series on Chrome! This was written to help beginners break into the browser exploitation field.
Part 1 covers V8 internals such as objects, properties, and memory optimizations. Enjoy! https://t.co/bbFjOOzlOu
The @defcon presentation “Process injection: breaking all macOS security layers with a single vulnerability” by @xnyhps is now available on YouTube. Enjoy!
https://t.co/8gwXUyLMRP