The core utilities that run every Linux system have been rewritten in Rust. We audited them.
Before shipping uutils coreutils with Ubuntu 26.04, @Canonical commissioned Zellic for an external security audit.
Two rounds, fixes contributed directly upstream.
Full report below.
V12 is now live for open beta. It can:
- Find valuable bugs
- Generate working, runnable PoC
- Generate patch and test the PoC against it
In our testing during audits at Zellic, Zenith, and Code4rena we've been consistently impressed.
Best of all: it's free. (Don't abuse it!)
Bad auditors miss obvious bugs. We built an AI tool that finds them.
Introducing V12: the only autonomous Solidity auditor that actually finds Highs and Criticals.
We'll be releasing it for free.
V12 finds Crits in Zellic audits, High/Mediums in Cantina, and a bug in Pendle.
Still hacking with your feet on the ground? Not anymore, we cooked ๐
Join Ctrl+Space CTF Quals (20โ21 Sep) to be one of the 5 finalist teams to play in-orbit challenges running on @D_Orbit ION Satellite Carrier ๐ฐ๏ธ at @esa 3S conference ๐ณ๐ฑ (4โ6 Nov)!
https://t.co/cvS1NKTvZF
๐จ Sponsoring us?!
The mhackeroni kitchen will open its usual pop-up restaurant in Vegas at @defcon this August ๐
There's still time to help us make it - write us if you'd like to discuss!
Let's get your logo out there on this summer's hottest piece of apparel ๐๐ฉ
We're proud to share that Zellic Security Researcher @fcremo helped discover an issue in the Cairo VM during a recent audit of @Starknet OS.
This bug has been fixed as an immediate patch to Starknet's current version 0.13.3.
๐ข Calling all Sponsors!
Get mhackeroni to the DEF CON 32 CTF finals ๐ฉ๐
Would you like to be a part of moving the kitchen to Las Vegas this summer & secure a spot for your logo in our highly-demanded t-shirt?
Contact us!
Your favourite Italian Acheriโข๏ธ need your help!
@hackerfantastic@pid_eins I am trying to understand the vulnerability you are outlining. Could you please give me an idea of how you would hijack the pty to inject inputs into it without ptrace and without being root/having CAP_SYS_ADMIN which AFAIK is needed to use TIOCSTI on the pts?
@_revng I meant you don't get to decide where the push goes, it's one time up, the next down.
I guess it could be worse, it could push half word up, half word down.