@LiveOverflow On Android assessments I regularly see a minSDK version of 23 so assume there is some reasoning behind that and would be a good bet in terms of the number of users that would be impacted by any findings.
Do you want to know more about #r2frida? Found this awesome blog talking about some practical stuff using one of our challenges! https://t.co/ZEeFScDawf
Besides, do not lose the opportunity to learn more on our training with @enovella_ & @Hexploitable!
https://t.co/qK0EGQFkmx
I made a quick Automation to protect my iPhone if someone steals it while unlocked: if they turn on Airplane Mode (Find My), it asks for a passcode. If wrong… it automatically locks the phone 🔒, turns ON all connectivity 📡 + Low Power Mode 🔋, and shares its current location📍
The insane number of politicians claiming to have fought for innocent postmasters before Toby Jones played 1 in a drama is best illustrated by Priti Patel saying Fujitsu should be held to account when her timeline shows “by account” means getting paid to speak at their conference
The third edition of my Security Engineering texbook will be freely available for download later this year, 42 months after publication. We did that with the first and second editions too, and in each case it increased sales of the paper book! https://t.co/PSnvpt1ivv
We're revealing details of an obscure debugging feature in the Apple A12-A16 SoC’s that bypasses all of the hard-to-hack hardware-based memory protections on new iPhones. Its not used by the firmware and we don't know how the attackers found out about it. https://t.co/hsQo6JIPMJ
Thanks to marcan (https://t.co/sDwlE7Wq6T) and @zhuowei (https://t.co/EzBvk4cNBY) now we know the original purpose for this unknown hardware feature. Its MMIO debug registers for GPU L2 cache. I am really excited that we are very close to solving this mystery!
Hector Martin (marcan) has some good ideas that the iMessage exploit used dbgwrap and cache debugging registers.
He also talks about how the "sbox" design is very clearly an ECC or CRC and not intended to obfuscate anything.
https://t.co/gloFTi0ycm
The recording of our (me, @bzvr_, @kucher1n) #37c3 talk “Operation Triangulation: What You Get When Attack iPhones of Researchers” was published! https://t.co/j97J9TiXsC
Frida supports a number of different writers for different CPU architectures, such as X86Writer for x86 and Arm64Writer for AArch64. In part 6 of Advanced Frida Usage blog series, we will cover the Arm64Writer for iOS➡️ https://t.co/HRRMqONfFa #Frida#ARM64#CyberSecurity
🔥Free Ghidra Content for Beginners 🔥
A series of 7 free tutorials demonstrating the most common Ghidra workflows.
These are the most common and approachable workflows that you can use day-to-day to begin analysing malware with Ghidra.
[1/8] 🧵
#malware#ghidra
Remember when we figured out how to symbolicate crash reports for SwiftUI? Now you can too 😎
We're excited to release ETSymbolication & the Emerge Tools Symbolicator, an open source way to generate & use symbols to symbolicate any crash 💥
https://t.co/MaXWH59YV7
In fairness to this driver, someone had dangerously placed a kitchen roll in the road which they had had to take emergency actions to avoid, expertly manoeuvring the vehicle, including rolling it, so as not to damage even a single sheet of the kitchen roll.
We can all be refugees
Nobody is safe,
All it takes is a mad leader
Or no rain to bring forth food,
We can all be refugees
We can all be told to go,
We can be hated by someone
For being someone.
- Benjamin Zephaniah, 'We Refugees'
Over the weekend I was reading a post by @inversecos on exploiting an Arm64 binary:
https://t.co/gIOYER5QKU
I thought it would be interesting to also do the exploit on x64 Windows and show how we can use Frida to autopwn the binary, check it out on 🔪🧥
https://t.co/crcjug1CJl