We cut a microscopic wire inside a chip with an ion beam, then brought it back to life with platinum gas!
My latest video is a collaboration with @Zeptobars, and I’m releasing it as a Youtube premiere at 18:00 CEST on Tuesday 12th May.
https://t.co/PUMzld8nYp
(1/4) It has risen...
After 25 years of being locked away behind some of the most insane software/hardware protection I've ever seen for a $25 unlicensed console accessory, SEGA Dreamcast's DreamMovie has been unlocked, and is available for all!
DOWNLOAD
https://t.co/bNMs0XzWC0
Took me almost a month, but it’s finally done.
I completely rewrote the first chapter of linux-insides about the Linux kernel initialization process. Now it should be aligned with modern kernels (up to master).
https://t.co/IHwrDtMSpw
Today, we're releasing two lecture-levels of our new course: Fundamentals of ARM Exploitation! These levels will be free for everyone, indefinitely, as part of a course-preview.
You can try them with a free demo account, or by following the links in the posts below!
I've been doing normal voltage glitching so far, but that has a chance to soft brick the F4 - so I'm going to take a stab with the same EMFI parameters I used beforehand. I fell down a bit of a rabbit hole enabling ETM tracing. Turns out, you can configure the ETM macrocell, hit a soft reboot, and it will be enabled IN THE BOOTROM. This ends up giving you a (rough) instruction trace on the SWO line, which is insanely helpful for profiling.
RDP1->RDP0: Good to go
RDP2->RDP1 (reliably): In progress!
Grab your d20 and your text editor! ⚔️
Turn your daily debugging into a high-fantasy quest with the Syzkaller Dungeon. Slay real kernel panics, earn XP, unlock epic loot, and defend your corporate kingdom.
Roll for initiative: https://t.co/kug12yEGqJ
We're excited to announce the launch of a new course on RET2 WarGames: Fundamentals of ARM Exploitation!
This is an accelerated,⚡️ 5-chapter course 📚meant to quickly build familiarity with binary-exploitation on ARM platforms.
Check it out!
https://t.co/wMxetMhRKv
The Nintendo Talking Flower firmware does not check the size of the language index table when loading it from SPI flash into RAM, allowing me to corrupt the stack, execute arbitrary code, and dump the protected STM32 firmware🤣
(SHA1 51ec2ee3bbc12772cd4abed1bf2d26b02e541e14)
chips have become smarter about power supply attacks to bypass access port protection etc so now they literally EMP specific parts of the chip (sometimes with a gantry system to iterate over every area of the chip) to glitch it and break protection. It’s nuts.
@i2cjak It's pretty wild that it actually works, I put together some slides on this a while ago that you might find interesting: https://t.co/xZkdgFERz9
I'm looking for a new role!
I've spent the last several years doing offensive security work across both government and commercial environments: red teaming, penetration testing, threat intel and malware analysis. Before that, several years as an Navy intelligence analyst.
Certs: OSCE3 | OSCP | GIAC CTI | CRTO
Looking for remote roles where I can keep doing hands-on offensive work: red team, pentesting, or threat research.
If something sounds like a fit, feel free to reach out.
#OpenToWork #RedTeam #OffensiveSecurity #CyberSecurity #OSCE3