I'm glad that public bug acquisition is fucked now. Now when you ruin my day, at least you won't get to enjoy the bounty >:)
Not that i lost many bugs due to external reports, but it's good to see cve farmers suffer
The full schedule for #Pwn2Own Vancouver is now available. We start tomorrow morning at 9:30 with @abdhariri targeting the #Adobe Reader for $50,000. Stay tuned for all the results.
https://t.co/iuLS3dfc8b
How do synchronization primitives work during speculative execution? THEY DON'T!
Disclosing #GhostRace (paper @USENIXSecurity). We turn all arch. race-free critical regions of OS/Hypervisors into Speculative Race Conditions. Joint work @vu5ec@IBMResearch: https://t.co/46Gjf2YyMF
@Myrtus0x0 It's just that I had no tooling for 13, if you have then I'm sure its solvable within an hour or two.
But if you don't, it's a world of pain
Blogged after a while on some research that me and @typeconfuser did back in 2020 regarding the exploitation of a range mis-computation issue in WebKit!
For those who got the wrong impression:
I'm not the one who reported the bug or the one who discovered it.
I just find it funny that the reporter thought it's ok to report someone's bug
> we are having the CTF, and while checking traffic, I noticed that one of the team's exploits is not GLES 3.1 or compute shader specific. I checked that it's a 0day.
> I eventually reported the issue to ensure that it actually is taken care of,
Finished 1st in HITCON 2021 again this year. We had an amazing time playing with @setuid0x0_, @jinmo123 and @yechan_bae. Thanks to @HacksInTaiwan for such a great CTF, we are looking forward to next year.