We analyzed how different LLMs and prompt strategies impact bug triage performance in our #BinaryNinja plugin #Mole. TL;DR: Real-world code is far harder than synthetic benchmarks, false positives dominate, stability varies by model, and prompt tuning is strongly model-dependent.
First two unauthenticated RCE CVEs published - Discovered with the help of our #Binja plugin #Mole!
🔗 Advisory: https://t.co/tgb42PVnyx
🔗 Mole: https://t.co/J3NwT2iWkK
More vulnerabilities have been reported - stay tuned for upcoming advisories.
Static pointer tracking is tricky.
Just shipped some improvements to my #BinaryNinja plugin #Mole: it now tracks array and struct members more precisely.
An example on how Mole does this: https://t.co/4FQOPA1l1F
Binja's multiple ILs make precise analysis so much more powerful!
A while back, I wanted to learn about @qb_triton and symbolic execution in general, and to research its challenges when it comes to real-world binaries. What began with a few simple scripts evolved into PoC tool called Morion, which I've just released.
#symbex#libtriton#morion
I've written a detailed showcase to highlight some of the tool's features (and current limitations). The showcase illustrates how the tool can, for example, help assess if a bug is exploitable and if so, assist in crafting a functional exploit:
https://t.co/zPviKloeiW
@HatforceSec@cydcampus@IEEE The paper should soon be listed on the conference website: https://t.co/cuvmX68J3Z. Give me a DM if you want me to share it directly.
You missed the interesting @swisscyberstorm talk "Hidden Inbox Rules in Microsoft Exchange" by @dp__pd? All infos about his research and the attack can be found here: https://t.co/M7zfbRiUZu #SCS18
Compass Security Blog: Hidden inbox rules in Microsoft Exchange… or how to secretly steal your messages. Topic presented at this year’s @swisscyberstorm. #DFIR
https://t.co/iG3oHgOs39