The writeup is here. We achieved RCE in Minecraft Bedrock, turning a 4-byte heap overflow into complete client compromise.
@ryaagard details a universal, Bedrock-specific technique for bypassing ASLR and achieving arbitrary read / write primitives.
๐จ Zebra 4.5.0 is out. This release fixes multiple security vulnerabilities across consensus and networking.
All node operators should upgrade immediately.
https://t.co/3Iane54YsM
@jimii_47@_mixy1 for the current crate, we would use the `program_id` passed in by the entrypoint.
for dependencies (ie "cpi" feature), you would still need to have `declare_id`
DEFCON 26 Quals: LLMs are allowed! (but like cmon guys, donโt just do the prompt, like at least pretend to be busy, like canโt we just go back to 2022 when LLMs still kind of sucked, I mean donโt just go and say solve this, like if itโs just helping thatโs ok but like if it just