This is the first paper I ever worked on. It was exciting and a lot of fun.
Thank you @lavados for the opportunity to work in your group during the summer break!
In our new paper "KASLR: Break It, Fix It, Repeat", we reverse engineer Intel #Meltdown patches, break #KASLR again (#echoload) and propose #FLARE, a mitigation for all known microarchitectural KASLR break. #AsiaCCS@lavados@misc0110 @marv0x90 @rizerev
https://t.co/GZVC9yo0fw
Last Friday I received the "Student Research Excellence Award" from the Institute of Applied Information Processing and Communications @tugraz for my bachelor thesis and my contribution to the paper "Finding and Exploiting CPU Features using MSR Templating".
#research#award
Time to catch up on Twitter again. In case you missed it: the paper "Finding and Exploiting CPU Features using MSR Templating" that I worked on has been accepted at S&P'22.
If you are interested in undocumented CPU features I recommend taking a look!
Our paper "Finding and Exploiting CPU Features using MSR Templating" got accepted at S&P'22! Together with @weber_daniel@rizerev@mlqxyz@lavados@misc0110 we analyze the effects of MSRs on system security and show our findings in six case studies.
Paper: https://t.co/ELNyjTHQRz
Our browser-based #ZombieLoad data-leakage attack is the first MDS attack running in a recent unmodified version of Firefox. We also show the first LVI attack on #ARM CPUs, injecting arbitrary values into the transient execution of a victim process
https://t.co/yZ1Stgj8Zz
Delighted to announce that our paper 'Rapid Prototyping for Microarchitectural Attacks' has been accepted at @USENIXSecurity'22 #usesec22! Preprint at https://t.co/sxZmpbutib. /cc @misc0110 @marv0x90 @lavados@Dynatrace
Finished my habilitation (venia docendi). Thus, my official title is now "https://t.co/Et6geynYTi. Priv.-Doz. Dipl.-Ing. Dr.techn. BSc" (the "Priv.-Doz." is new).
The habilitation thesis is now public on my website: https://t.co/DK4sIcJkN1
@RealityAbsorber @lavados@tugraz I'm currently creating my website and will upload my thesis there once the site is up and running. I'll make sure to let you know.
It's been such a busy time that I forgot to mention that I recently defended my bachelor's thesis, "Finding and Analyzing Undocumented Model-Specific Registers on x86_64", at IAIK @tugraz. It has been great fun, and I learned a lot while working on it. 1/2
Thank you, @misc0110, for being such a great advisor. Big thanks also to everyone in the whole CoreSec group to always be there for various discussions about the matter and other absolutely unrelated things. I'm looking forward to continuing to work with you! 2/2
Yesterday night, my car broke down due to a weather-related incident. A big thank you to everyone who stopped and asked if they could help. Especially thank you, Manfred, for towing me and my car back to my place. I did not expect such kindness from a stranger.
The recipient of the EuroSys Roger Needham PhD Award 2020 is Michael Schwarz (@misc0110) from Graz University of Technology—congratulations! https://t.co/3DYnHnbVmM
Interestingly, #EchoLoad is the inverse of LVI-NULL. Instead of injecting zero values, we retrieve them via a Meltdown-type attack to break KASLR. https://t.co/PSXQW5PQxC https://t.co/GZVC9yo0fw @misc0110@rizerev @marv0x90 @lavados@jovanbulck @danielmgmi @mlqxyz
With #LVI (Load Value Injection), we present a new class of transient-execution attacks that extends the classification tree by an entirely new branch. https://t.co/yKQe0LmJfM /cc @jovanbulck @danielmgmi @mlqxyz@lavados
@tugraz Awesome, thank you! Unfortunately, I can't send you a DM. I guess you would either have to change your privacy settings or follow me for that to work.
NSA: we are open sourcing a multi million line of code SRE tool to democratize the malware analysis space. Microsoft: Hold my beer https://t.co/B5LhPcMS4g
I've been using https://t.co/DrwfqJwnlP for years and just few weeks ago I found out there's an advantage to actually create an account: you can filter different versions of a particular function, data structure or algorithm based on your target C++ version.
No more clutter!
#cpp
I’ve probably shared this before but “What Every Programmer Should Know About Memory” (https://t.co/LakztLaV9u) is an awesome resource - also for cases where you deliberately want to *avoid* caching and make sure a row in RAM is activated ;-)
Just submitted the first paper this year to #arXiv. Responsible disclosures are over. Will be public on January 7 at 1am GMT. /cc @misc0110@aionescu@anders_fogh