@Cluely's Vibdecoded premium tiers are unlocked by a simple script.
I withheld the technical PoC deliberately after being burned by amateur VDPs in the past and shared only an impact video to start a secure dialogue first. Silence.
If no response soon, I post the redacted demo
Submitted a Windows kernel info disclosure to MSRC
A zero capability LPAC process can read the user mapped win32k desktop heap and recover kernel pointer material from the heap metadata
The useful part is turning that into exact win32k object address recovery
@Cluely's Vibdecoded premium tiers are unlocked by a simple script.
I withheld the technical PoC deliberately after being burned by amateur VDPs in the past and shared only an impact video to start a secure dialogue first. Silence.
If no response soon, I post the redacted demo
@SecurityMB I am still working on my bachelors but I am open to dropping it for such a job. You can check my profile for practical real world experience!
@cluely You maybe should look into your BB submissions after vibecoding the whole infrastructure... I am asking once again for an answer so that we can do responsible disclosure.
Trying to coordinate a security report with @cluely for over a week via their disclosure channels. Would appreciate a response. I only submitted a showcase video, not PoC details, due to past poor VDP experiences of companies scamming researchers...
Second writeup is up on GitHub: VVM (HTB RE). Tiny custom VM, XOR decoded handlers, bytecode turned into a clean constraint system, then solved in script.
https://t.co/FpP45su8d3
today I decided that I will post writeups on github. first one is Callfuscated, an Insane RE challenge on HackTheBox. callfuscation + custom VM hiding 4 obfuscated functions. GDB did what static analysis could not. https://t.co/ER2sMG0Cj0