Fortunately this http.sys bug was an internal find by our team. This one thanks to @_mxms, @fzzyhd1 and everyone who contributes to our tooling and automation.
@tekknolagi A child can attach to its parent if the parent calls ptrace(PTRACE_TRACEME, ...) or you modify yama_scope; whether or not gdb will be able to use the tty properly, I don’t know :p
These, combined with recent @WIRED reporting on Chinese espionage campaign Operation Skeleton Key targeting the Taiwan Semiconductor Industry (https://t.co/5d4XUlJUxP), suggests possibility of an explosion of new homegrown semiconductor companies in the mainland.
It's not obvious from the advisory, but the same code runs in RDP client. The issues have been patched in both.
This would have allowed a malicious server to compromise a client without any alerting behavior, or a MitM attack with a warning confirmation.
August Patch Tuesday includes fixes for our internal finds in RDP, including RCE and remote info disclosure, and affecting Win 10 latest. The team successfully built a full exploit chain using some of these, so it's likely someone else will as well.
Patch and enable NLA.
We've built tools for fuzzing based on emulation of a process snapshot captured via minidump. We're considering open sourcing the tool, and I'm curious about interest level from the rest of the world. (1/3)
@RolfRolles@aaronportnoy Last year RPISEC was at the RPI club fair, and a person of color came to our table and saw the book, and asked the same thing. I’m incredibly happy they asked instead of assuming
#RealWorldCTF2018 RPISEC has successfully pwned the Safari browser and spawned a calculator on the victim host at their first attampt during the demostration!
After Trump was elected, I felt unsafe. I thought that electing a man as president who has assaulted women would normalize that behavior, make assault seem inconsequential to a perpetrator. Right now, I feel worse. It’s normalized, all right.