iOS jailbreak demo in iPhone 12 Pro running latest iOS 14.2 by Liang Chen(@chenliang0817) at Singular Security Lab(@SingularSecLab)
Ask Liang Chen or SingularSecLab about the jailbreak and his talk directly.
@s0uRc3_c0de@Chompie A lot of details are involved in technology, I plan to share my very stable use method later.
But because of national policy, I have no way to directly publish the attack code.
So I may only post a blog. 😅
@chompie achieved #SMBGhost CVE-2020-0796 RCE exploit,Stunningly good job! 👍
I can fully understand your pain as I spent a lot of time to test its stability and finally succeeded in exploiting SMBGhost RCE continuously. 😜
@chompie1337@Chompie I haven't debug your use, but I feel that the technology we use should be similar.
It may just be a slight difference in some addresses and subsequent usage methods.
@chompie Tested your exploit code,but It shows "physical read primitive failed" in my testing environment which might relate to VMware Physical Address at 0x1000. 🤔
Today we at Microsoft are excited to announce the pre-release version of the Windows Runtime Language projection for @rustlang pushing support for Rust on Windows forward! https://t.co/Ukj0CQ3aP5
New P0 blog post up. How a one line change in the Windows kernel broke the Windows Chromium sandbox (and thus Edge and Firefox at the same time). https://t.co/yY11guLOm8
• Read everyday.
• Spend time with nature.
• Ask questions.
• Never stop learning.
• Don't pay attention to what others think of you.
• Do what interests you the most.
• Study hard.
• Teach others what you know.
• Make mistakes and learn.
• It's Okay to not know things!
Are you interested in font security? I've just updated my BrokenType repository (https://t.co/t5QBfx4drE) with several new tools: font2pdf (embedding custom fonts in PDFs), a DirectWrite API testing harness and a Windows FontSub.dll loader. Enjoy :)
Applying Timeless Analysis to the recent CVE-2019-1347: When a mouse over a file is enough to crash your system. Read our analysis and get your hands on the trace on our new demo platform. https://t.co/kUmTcSHNs6
Happy to successfully exploited Edge Browser + Sandbox Bypss at #TianfuCup ,and our Sandbox Bypass vulnerability can exploit Chrome Sandbox as well.
Details of the relevant vulnerabilities will be published at the appropriate time.
Credit goes to our team members. 👻
Congrats! All the three Edge exploits are confirmed to be success! Teams ddd @ExpSky and 360vulcan @mj0011sec both achieved RCE + sandbox escape, so each earned $55,000. Team .(dot) get $10,000 with RCE.