I recently developed and posted about a technique called "First sequence sync", expanding @albinowax's single packet attack.
This technique allowed me to send 10,000 requests in 166ms, which breaks the packet size limitation of the single packet attack.
https://t.co/puM7hZWIlE
New blog post: Cosmos IBC Reentrancy Infinite Mint. A critical reentrancy bug in ibc-go could have enabled the infinite mint of IBC tokens on Cosmos chains.
https://t.co/ybeLpiUqTU
🔐Today, we are announcing the most significant cryptographic security upgrade in iMessage history with the introduction of PQ3, a groundbreaking post-quantum cryptographic protocol that advances the state of the art of end-to-end secure messaging.
https://t.co/UGGz0YNTTb
The video and slides of my talk "A 3-Year Tale of Hacking a Pwn2Own Target..." are out. Hope this presentation somehow could be another reference to your next research!
➡️ Video: https://t.co/A1bYtCT5dl
➡️ Slides: https://t.co/wMydKH0251
My #POC2022 slides + the iOS kernel r/w exploit can be found here :)
https://t.co/d4Ixz8C2zU
Thanks @POC_Crew for a fantastic conference and truly honored to have been part of it.
Last year, Apple shared a high-level overview of "Memory safe iBoot implementation". I thought it would be nice to reverse and write about it, hope you will find it interesting :) https://t.co/roMrVSHVU1
Your code might be vulnerable! Our cryptography team has discovered a number of Fiat-Shamir vulnerabilities affecting proof systems such as Bulletproofs and PlonK. Check out this blog series for details and contact us if you think your codebase might be… https://t.co/3vEJWxt6Qd
@roshunpatel Unlike eth, no one publishes the source and decompiling a solana program is hard since it’s all bpf. Once solana catches up with source code verifier and proper bpf RE tools are developed, watch the exploits roll
So, another IOMFB vulnerability was exploited ITW (15.0.2). I bindiffed the patch and built a POC. And, because it's a great bug, I just finished writing a short blogpost with the tech details, to share this knowledge :) Check it out! https://t.co/bWWbNl8RC7
🔥 Following our TCC talk with @_r3ggi I'm publishing two fully working exploits.
✅ CVE-2021-1784 - TCC bypass by mounting over the TCC.db directory / fixed in 11.3
✅CVE-2021-30782 - TCC bypass using App Translocation / fixed in 11.5
https://t.co/3l3B5Auyec
The slides and some scripts for @Sn0wfreeze's and my #BlackHat talk about the Apple U1 chip are available online :) If you missed the talk, there'll also be another one at DEF CON.
https://t.co/VNBYdiAqtu
Finished my talk at MOSEC'21. I spent much time on the slides (https://t.co/hKutwvQ7wX). Although the bug was discussed in my Zer0Con'21 talk, I added more attack attempts in the new talk, and put more background information regarding Mach ports. Hope you like it.
So excited to finally release my blog post- Kernel Pwning with eBPF: a Love Story. I cover eBPF, the verifier, debugging, exploitation, mitigations and other cool findings! I do root cause analysis and exploit CVE-2021-3490 for LPE with PoC included. https://t.co/pWt1psHEFa
So, as it turns out, an LPE vulnerability I found 4 months ago in IOMFB is now patched in iOS 14.7.1 as in-the-wild. I wanted to share some knowledge and details about the bug and some ways to exploit it. Hope you'll find it useful, check it out! https://t.co/fxLTJZgc3B