@XenoKovah@quarkslab oh i almost missed it because i looked only at the bugs but that timeline is so hilarious. Tianocore: "uh we lost our head of psirt. can you wait until we have a new one that we intend to throw in a burning house immediatly?".
@brinlystorm as a german it hurts to see things like this so often. it feels like the country has a critical vuln everybody knows about but no one patches it and slowly actors keep extracting all the goods until nothing is left.
@seanhn past years is quiet a stretch. most stuff already obsolete now but some stuff i enjoyed reading:
- all from https://t.co/qENFkCLPTa
- all from https://t.co/r2ZdVFOVc7
https://t.co/IHaZZ5kifE
First big result from our new CPU research project, a use-after-free in AMD Zen2 processors! 🔥 AMD have just released updated microcode for affected systems, please update! https://t.co/NVPWFpVopz
Almost a year after my defense, my PhD thesis "Automated Security Testing of Unexplored Targets Through Feedback-Guided Fuzzing" is now archived on the university server 🎉
We fuzzed Nvidia drivers, tcp servers, basebands, WebAssembly, ..
Enjoy reading :)
https://t.co/aBHy2X74iP
On the surface, analytical problem solving is my forte. Cicada 3301, Boxen, CTFs, 0day research, reversing highly complex targets etc
The key to everything I've done has always been an intense focus on building up a deep intuitive understanding and useful mental models though
#BHUSA Briefing "How To Tame Your Unicorn - Exploring and Exploiting Zero-Click Remote Interfaces of Modern Huawei Smartphones" exploits vulnerabilities to escape from the baseband and take over not only Android and the Linux kernel, but even TrustZone: https://t.co/n0SQFcJS5d
In case you missed it like me,looks like erynian from Quarklabs released his snapshot fuzzer 'rewind' (written in Rust!) Included a step-by-step guide on how to reproduce CVE-2020-17087 (A Windows Kernel Cryptography Driver).So many fuzzers,thank you guys! https://t.co/iyTD98SAa4
In the 6 years since the car Jeep hack, there hasn't been a similar attack (no interaction -> arbitrary CAN messages). There has been some no interaction remote attacks (eg @esizkur against Tesla) and some arbitrary CAN message (eg @keen_lab against Telsa) but no full attacks.