Theori's N-Day Full Chain Exploits Series: Part 2
How did we escape the chrome sandbox?
Want to dive deep into the first Windows kernel in-the-wild vulnerability(CVE-2023–21674) discovered in 2023?
Check it out now.
#Theori#티오리#windows#sandbox
https://t.co/zv6YfRixeB
We're revealing details of an obscure debugging feature in the Apple A12-A16 SoC’s that bypasses all of the hard-to-hack hardware-based memory protections on new iPhones. Its not used by the firmware and we don't know how the attackers found out about it. https://t.co/hsQo6JIPMJ
New blogpost by @FuzzySec and I! Patch Tuesday -> Exploit Wednesday: Pwning Windows afd.sys in 24 Hours. We reverse engineer a bug + write an exploit using a cool new primitive. We also find out that it's been exploited in the wild (previously unknown). https://t.co/DAuok3g7Ci
To wrap up 2022, I'm releasing the final part of my 3-part browser exploitation series on Chrome!
In this post, we demonstrate the practical use of the concepts we've learned throughout the series by analyzing and exploiting CVE-2018-17463.
Enjoy!
https://t.co/Xhrnh4fqNB
Today I am releasing part 2 of my 3-part browser exploitation series on Chrome!
In part 2, we take a deep dive into the V8 compiler pipeline by understanding what happens under the hood in Ignition, Sparkplug, and TurboFan!
Enjoy!
https://t.co/XAnbzdnjeQ
Here is my new blog "Technical Analysis of Windows CLFS Zero-Day Vulnerability CVE-2022-37969 - Part 1: Root Cause Analysis", Part 2 will be released soon. Stay tuned!
Following up from last month, the Trend Micro Research Team returns with details about CVE-2022-30136 - another remote, unauthenticated RCE (at SYSTEM) in #NFS. They cover the root cause and offer detection guidance. Read all the details at https://t.co/Pga8lJLjZ5
As promised, I wrote about my Windows 11 post exploitation technique to go from an arbitrary write/increment to a full read/write through I/O rings: https://t.co/z7ZDs9UTMC
The latest blog from the Trend Micro Research Team looks at CVE-2022-26937: a Microsoft Windows NFS NLM Portmap stack buffer overflow that could lead to RCE. They provide root cause, source code walkthrough, and detection guidance. https://t.co/FhKhIeoG35
We do not always have success in everything we do. We even missed out some CVE while trying to figure out how to dig deeper. But it's part of our process & we hope that our documentation here will be useful You can read about @PTDuy 's blog post out here:
https://t.co/DjnqPQXJTZ
I had written these a while back, but I'm publishing them now as a four-part series. Here are the technical analysis details of the information disclosure #vulnerabilities I've found last fall while #fuzzing#Windows GDI+ with @ifsecure's #WinAFL. 🧵
RCA for 1 of the 2 CLFS bugs patched in April 2022. While we can't determine the CVE, we did managed to exploit it ;) ... credit: @b1thvn_
https://t.co/OBDKYVKfe6
Crypto3/Hydseven exploit chain: a Firefox RCE + sandbox escape. Links w/ the CVE-2019-11707 (RCE)+CVE-2019-11708 (sandbox escape) Firefox exploits were emailed at Coinbase in a phishing campaign targeting exclusively the FF browser on Win, Linux, Mac
https://t.co/dNWzat4h0U
I wrote a blogpost on turning a binary only target that takes file based inputs into a snapshot fuzzable harness that takes inputs from memory. This is a commonly asked question. It should be beginner friendly (i am one). https://t.co/Aq7HqSQQhZ
Happy Patch Tuesday!
Back in November 2021, I found and reported a local privilege escalation vulnerability in the Windows Print Spooler. The patch for the vulnerability (possibly CVE-2022–22718, CVSS 7.8) was released today. Read all about it here:
https://t.co/JEzVtaj7UH