💻 After #OSCP & #OSWE, I spent a year on Offset Unlimited to tackle #OSEP & #OSED, earning #OSCE3.
🚀 Also completed: OSWP, OSTH, OSWA, OSIR, OSCC-SEC, OSCC-SJD, KLCP.
🙏 Big thanks to @offsectraining for the amazing trainings!
Huge computer science result:
A Tsinghua professor JUST discovered the fastest shortest path algorithm for graphs in 40yrs.
This improves on Turing award winner Tarjan’s O(m + nlogn) with Dijkstra’s, something every Computer Science student learns in college.
🍉 The AperiSolve website just got a fresh new look!
- ⚙️ RAM doubled
- ⚙️ CPU doubled
- 😎 Swag doubled
Got feedback? Drop a DM or open an issue: https://t.co/yTGVe2sGRo
https://t.co/W7kWoitnRU
Bug bounties ain't just web. Throwback to when @kernelpaniek and I got RCE on Steam Client via a buffer overflow in Server Browser 🚨
Root Cause:
🎯 Wide-char conversion without boundary checks inside serverbrowser.dll leading to stack corruption
Exploit:
🪲 Crafted oversized Unicode player name payload
🪲 Unicode-compatible ROP chain built from Steam.exe gadgets
🪲 Dynamic call to VirtualProtect to mark stack executable
🪲 Shellcode launches cmd.exe
Impact:
💥 Remote code execution (RCE) on Windows
🤔 Partial control on Linux (2 bytes of EIP)
🤔 SIGABRT on macOS (due to canaries)
Delivery:
📦 User tries to connect to a CS game via Steam client
📦 User visits malicious webpage triggering Steam protocol handler
Tools:
🛠️ Python for UDP server and payload generation
🛠️ Immunity Debugger for base address retrieval
🛠️ Steam Server Query documentation for packet crafting
Read the full report: https://t.co/ArdRSVLf3M
I’m happy to share that after more than eight years with the team, I'm now the President of @rootme_org.
Root-Me is more than just an e-learning platform to me - it's where I learned cybersecurity, met incredible people, and even got my first job in the field of reverse engineering. It's a part of my daily life, my resume, and my social network.
Over the years, I've witnessed countless individuals significantly boost their cybersecurity skills and secure jobs through Root-Me. I'm immensely proud of what we've built together.
Our former president, g0uZ, who did more to Root-Me than anyone else, will remain a permanent member of the organisation, as a Honorary President.
Thank you, everyone!
Iconv, set the charset to RCE: in the first blog post of this series, @cfreal_ will show a new exploitation vector to get RCE in PHP from a file read primitive, using a bug in iconv() (CVE-2024-2961) https://t.co/7GQvKPszrl
@Maltemo 5€ de VPS/mois et 2 domaines .fr/.com (15€/an ?). Idéalement il faudrait que je paie + pour avoir des bonnes perf' mais bon, je suis un rat 🐀.