We recently achieved guest-to-host escape by exploiting a QEMU 0day.
We’ll share details on a new technique leveraging the latest glibc allocator behavior and what we believe is a novel QEMU-specific heap spray/RIP-control primitive.
Writeup coming next week.
-Drops a unsandboxed chrome RCE!!!
-Gets Rewarded $250k!!!!!!!!
-Asks for the report to be made public to help the community and vendors
-Drives into horizon
Virtual Machines render fonts. It’s kind of insane.
TrueType has its own instruction set, memory stack, and function calls.
You can debug it like assembly. It’s also exploitable:
ksmbd - Fuzzing Improvements and Vulnerability Discovery
Another article by @73696e65 about fuzzing the ksmbd module with syzkaller.
https://t.co/0xVehcOrYu
Charlie Kirk being killed rocked me. Gun violence is rampant in the US and anyone can be killed anytime
Charlie strongly believed you need to defend yourself and if you want to defeat your enemies, the best thing you can do is arm yourself with my undefeated B2B sales techniques
Here is our 0day for kernelCTF🩸
- 82k bounty
- quickest submission ever
- all instances pwned😎
https://t.co/0sb11m8ITD
Disclaimer: We apologize for abusing the red black tree family. Turning grandparents against grandchildren is only acceptable in the context of pwn😤
It is pretty interesting that as I age and geohot ages, I end up noticing that we agree on more things than I thought in the past.
This here is a good read:
https://t.co/1QU0oVlWbi -- it's
Here is the second part of the Windows IPC series.
As planned, I've started with RPC.
The third and fourth parts will come soon.
https://t.co/8LqgWzNhTF
NEW EPISODE - Amat Cama
Amat talks about Pwn2Own, the transition from CTF to real-world exploitation, or what a VR candidate should look like.
He also shares a funny story on how he actually got in computer sciences.
Thanks @amatcama for the fun chat!
https://t.co/uahemPqljj
We discoverd New Fivem 0day exploit - PoC 🚨
⚠️ Unauthorized access to the Vmenu Admin panel on any FiveM server can be achieved by exploiting game network traffic packets.
Credit : @Mohnad@Omarzzu@N4waF_Almutairi
"Interactive Linear Algebra"
A 477 page book on this.
- University of British Columbia Edition
For understanding systems of linear equations both algebraically (writing equations for their solutions) and geometrically (drawing pictures and visualizing).