We're super stoked to publish this post. A huge shoutout to our former intern, @rainbowpigeon_ who poured his heart & soul into this 7-8 months ago. It took us a bit to polish it up but we're incredibly proud of him. Dive in & let us know what you think!
https://t.co/7YsHPq1EdL
Tried out CVE 2020-22204 with @PTDuy and @CurseRed at @starlabs_sg and had tons of fun trying to get a reverse shell while trying to get the meta-data of a malicious DjVu file with ExifTool.
Made a writeup for b64lib from S4CTF. Was a very good challenge written by @ptrYudai, very very subtle bug, and fortunately not a heap note :D
Most of the credit goes to the god @RBTree_ for spotting the bug that let us leak libc
https://t.co/1LuMjJw3TW
Monday Blues? We have a new blog post, "You Talking to me?" by @CurseRed
https://t.co/GmoYvO1fkn
with some inputs from @Creastery and some editing work from Frances.
We hope it might be interesting for some of you.
My write-up covering #Zer0Con2021 talk!
Four Bytes of Power: exploiting CVE-2021-26708 in the Linux kernel
https://t.co/GLukmZ7b1y
#Zer0Con2021 slides: https://t.co/rIOnakyr7A
PoC exploit demo video: https://t.co/2ceeuiffq6
Enjoy!
`testing.F` is coming soon. F is short for fuzz(ing).
Helps us to find hard-to-spot bugs in code automatically. This technique had found 200+ bugs in Go stdlib before.
Learn more?
https://t.co/TjgvrrFvbN by @katie_hockman#golang
While you’re updating #IDAPro to v7.6, take a minute to update #IPyIDA to v1.6, which now supports recent versions of the IPython kernel. Thanks to @zerotypic and all contributors who made this possible! https://t.co/P0meRT1ytT #IDA#IDAPython#ESETresearch cc @idatips 1/2
I'm pausing #themorningpaper for the time being. It's been a hugely rewarding project, and I'd like to say a massive thank you to everyone who supported and encouraged me in it over the years. Find out more here: https://t.co/310mUEzOH2
We welcome @Qualcomm to the #NDSS2021 as one of our Silver Sponsors. Want to support a leading, global #security conference? Find out more about our sponsorship opportunities: https://t.co/wWDJrawJ8l
i hacked,
babyrop, sice-sice-baby, flippidy, and sourceless-rust-wasm-pwn, from #dicegang2021 ctf held over weekend,
the tasks were hard and nice. @dicegangctf
https://t.co/ga7eAsmtjU
"6 of 24 0-days exploits detected in-the-wild [in 2020] are closely related to publicly disclosed vulnerabilities. Some of these 0-day exploits only had to change a line or two of code to have a new working 0-day exploit." https://t.co/MoVC8r7eGW
Hi everyone who have been following my account. I would like to let you know of a situation I am in right now. Words cannot say how I am confused, frightened and stressed out. I assume you all have heard of the campaign targeting security researchers.