"A journey of fuzzing Nvidia graphic driver leading to LPE exploitation"
The slides of @Th1errry's presentation at #Hexacon2022 are now available in our github repository
https://t.co/HMX0Cl0zf5
The week is not over if you are at @hexacon_fr
Join Thierry Doré at 12:30 tomorrow and learn about his journey into the wilderness of fuzzing NVIDIA GPU drivers and then exploiting them
https://t.co/p1SpZz6di7
#WTFuzz#GPU#Fuzzing
Ravi d'avoir pu affronter, hier, les équipes de @quarkslab en simultanée mondiale ! A l'occasion de l'inauguration de leurs nouveaux locaux en plein coeur de Paris, j'ai joué simultanément contre les équipes en présentiel à Paris, et celles en distantiel ailleurs dans le monde🧵
Towards 1-day Vulnerability Detection using Semantic Patch Signatures. Alexis @DarkaMaul is defending his PhD today!
QbPhD++
Building and sharing knowledge with all, being part of the research community, participating in improving software security! So proud of Team @quarkslab!
A new ring3 sponsor has joined the adventure! Thank you @quarkslab 🙏
They also participate in our diversity program in collaboration with @Blackhoodie_RE
Quarkslab offers security solutions, consulting services and R&D 🚀
Check their website at https://t.co/ZOsWHpKtVc
Attacking Titan M with Only One Byte
Code execution and exfiltration of encryption keys from Google Pixel phone's Secure Element now being presented by @DamianoMelotti and @max_r_b at @BlackHatEvents#BHUSA
Full details are now public in their blog post:
https://t.co/KwRFhXeHMr
Teaser video: Dissecting Google's Titan M chip
Quarkslab's engineer @DamianoMelotti presents his talk with @max_r_b at @BlackHatEvents#BHUSA
Join them Thursday 11th 3:20pm at Islander FG for a tour of embedded system's reversing, fuzzing and exploitation
https://t.co/tEXObtJFoR
Today I presented a joint work with @4Dgifts@erynian and @bcreusillet from @quarkslab at the French Academy of Technologies @AcadTechnolog to answer “why is it so hard to build secure software?” Obviously a tricky question that will deserve a longer development than a tweet :)
Congratulations to our incredible researchers Max & Damiano for their nomination for their exploit on the TITAN-M. Invite them to parties if you are coming to BHUSA and enjoy their work! https://t.co/zueaZhNIXz https://t.co/kmzlTaVy2G
[SSTIC2021] Challenge. https://t.co/fxPPnDdgsB for the video of the presentation and https://t.co/wg1UbgnXhd for the github repository of the source code.
[SSTIC2021] QBDL: QuarkslaB Dynamic Loader. https://t.co/C3dBPjxm4m for slides and video. The github repository of the project is https://t.co/XrYSBB1pU2
[SSTIC2021] Exploitation du graphe de dépendance d'AOSP à des fins de sécurité.
https://t.co/WTjanjMxCw for slides, video, and full article
https://t.co/V8RWTAJHJe
SSTIC 2021 is over. Thanks to all the speakers and the organizers for this event. We cross our fingers to see you IRL next year! To make the event last a little longer, here are the links to the material Quarkslab produced and participated in this year.
Thanks to my first 2 twits in 6 years my account was flagged as rule-infringing. I had to appeal my account suspension 6 times from Nov. 2020 to May 2021 before it to be unlocked: "try again in 2 weeks we're overwhelmed". Final word: "automated detection system error". Indeed...