Confirmed! Their enthusiasm was rewarded as they used an integer overflow to escape #Oracle VirtualBox and execute code on the underlying OS. They earn $40,000 and 4 Master of Pwn points. #Pwn2Own#P2OBerlin
And that bring Day One of #Pwn2Own Berlin to a close. We awarded $260,000 today, but more great research is yet to come. STAR Labs has an early lead on Master of Pwn, but it's anyone's game at this point. Stay tuned for more results as we go.
We have another collision. Hyunwoo Kim (@V4bel) and Wongi Lee (@_qwerty_po) of Theori were able to escalate to root on Red Hat Linux with an info leak and a UAF, but one of the bugs used was an N-day. They still win $15,000 and 1.5 Master of Pwn points. #Pwn2Own
During #Pwn2Own Automotive, the team from @Synacktiv used 2 bugs to take over the #Autel Maxicharger. Our latest blog takes a brief look at how they did it, and how Autel patched it.
https://t.co/PkkX4xtQ89
Debugging Hyper-V:
1. Halt in hvix64.
2. Set VM Resume breakpoint.
3. Turn on Intel Processor Trace.
4. Break in the Secure Kernel.
Record all Intel PT executed instructions by reading Host mode memory from within Guest mode.
Hopefully cool video for hypervisor enthusiasts.
🚨 solid writeup on CVE-2024-21338! Learn how a clever AppLocker driver exploit bypasses SMEP & kCFG. Two paths to SYSTEM access revealed. Worthy read! Great work by @crowdfense
https://t.co/6d8Ilyc5V0
Very interesting series on dynamically hooking Golang programs
Part 1: https://t.co/RYjBvVHQi9
Part 2: https://t.co/gzuyIThaNW
Credits Mihail Kirov and Damien Aumaître (@quarkslab)
#infosec