Here are the slides for my keynote, 'Mobile Exploitation, the past, present, and the future' at #Zer0Con2023. Zer0con was a blast as always, thank you @POC_Crew!! 🚀💫
https://t.co/cqEftba9Cy
"In mid-2022, @Google Project Zero was provided with access to pre-production hardware implementing the ARM MTE specification. This blog post series is based on that review, and includes general conclusions about the effectiveness of MTE as implemented"
https://t.co/V0rkSV9udr
Sharing another V8 Sandbox design document more widely: https://t.co/h29nL4uBEM
This one discusses how to protect code pointers - probably the most performance sensitive part touched by the sandbox - with (almost) no performance overhead.
Here are my slides from my @0x41con presentation on Apple’s Lockdown Mode:
https://t.co/GQP0uIXbBC Enjoy 🎉
⚠️ Ironically the slides won't load when you have Lockdown Mode enabled 💀
See README for more info here - https://t.co/CIucgwnIss
https://t.co/RNvUDWV8Jl SSH agent forwarding just became even more dangerous. 😂-- leave it to the creative minds at Qualys to turn a series of dlopen()+dlclose() calls (of unrelated/benign shared libraries) into arbitrary code exec, hats off!
The @0x41con lives on because of the hardcore diehard fans it gained over the years who offered to organize and keep it alive. It takes time, effort & money to give you the experience for free.
Mad props @Simone_Ferrini, @f_roncari, @jndok for hosting the 4th ed. It was amazing!
It was an honour to organize with @xerub + @Simone_Ferrini + @jndok this 🇪🇸 edition of @0x41con, arguably the world's best conference for research quality. Shoutout to @xerub that made it possible, to all the speakers and to all the attendees who made it special 🫶🏼 #0x41con
I presented my Lockdown Mode research at @0x41con today and it was a dream come true ❤️ I started my iOS research journey ~5yrs ago & always dreamt of just attendin let alone presentin with such legends. This has been a tremendous honor! Thank u @xerub & @Simone_Ferrini et al.
The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022
written by @testanull
https://t.co/cN9EPOMLua
Thanks to @thezdi for reviewing and inputs to the blog post. Greatly appreciate that.