fatalbit_'s profile picture. Vuln. Researcher

fatalbit

@fatalbit_

Vuln. Researcher

fatalbit 已轉發

Obsidian is now free for work. Starting today, the Obsidian Commercial license is optional. Anyone can use Obsidian for work, for free. If Obsidian benefits your organization, you can still purchase Commercial licenses to support development. Nothing else is changing. No…

obsdmd's tweet image. Obsidian is now free for work.

Starting today, the Obsidian Commercial license is optional. Anyone can use Obsidian for work, for free. If Obsidian benefits your organization, you can still purchase Commercial licenses to support development.

Nothing else is changing. No…

fatalbit 已轉發

dare i say: lmao


fatalbit 已轉發

It's not in any sense surprising, but at some level of abstraction you still have to marvel at the political elite of this country being outraged at students protesting an ongoing massacre but indifferent to, if not enthusiastically supportive of, the massacre itself.


fatalbit 已轉發

Simple x86/x64 assembler and emulator: github.com/zodiacon/AllTo…

zodiacon's tweet image. Simple x86/x64 assembler and emulator:
github.com/zodiacon/AllTo…

fatalbit 已轉發

Is remote code execution in UEFI firmware possible? Yes it is. Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers. Full details by @fdfalcon and @4Dgifts in our new blog post: blog.quarkslab.com/pixiefail-nine…

quarkslab's tweet image. Is remote code execution in UEFI firmware possible?
Yes it is. 
Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers.
Full details by @fdfalcon and @4Dgifts in our new blog post:
blog.quarkslab.com/pixiefail-nine…

my bug finding music is 10hr white noise.


fatalbit 已轉發

cursedCTF 2024 Halloween Teaser 31/10/23 - 01/11/23 this CTF teaser committed tax fraud against multiple 501c5 organizations


we actually were so close to giving a run for first for hackasat, i wrote the ironbank script to backtrack but unfortunately it didn’t land.


fatalbit 已轉發

It is "bad", not only for desktops but also for mobiles. Last year, I exploited the Pixel 6/S22 kernel with an io_uring bug, the exploit now is available at github.com/Markakd/bad_io…. I will present the technique @BlackHatEvents, come see my talk if you're interested! #badiouring

"Why io_uring so bad?"



worst part of reading neoliberal interpretations of price increases is they just have a economic terms for saying “we were waiting for enough people to depend on the trains again to price gouge them”

Breaking News: The cost of a subway ride or bus trip in New York City will increase for the first time in eight years, from $2.75 to $2.90 by late August. nyti.ms/44SE3aO

nytimes's tweet image. Breaking News: The cost of a subway ride or bus trip in New York City will increase for the first time in eight years, from $2.75 to $2.90 by late August. nyti.ms/44SE3aO


fatalbit 已轉發
vxunderground's tweet image.

fatalbit 已轉發
Nick_Newman's tweet image.

nah wtf is this

It’s time to embrace goblin mode.



fatalbit 已轉發

Introducing acropalypse: a serious privacy vulnerability in the Google Pixel's inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot. Huge thanks to @David3141593 for his help throughout!

ItsSimonTime's tweet image. Introducing acropalypse: a serious privacy vulnerability in the Google Pixel's inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot. Huge thanks to @David3141593 for his help throughout!

binutils is either the safest or most vulnerable set of binaries given how many nerds fuzz it for their thesis.


fatalbit 已轉發

Published writeup and exploit for CVE-2022-20452, privilege escalation on Android 13 via Parcel use-after-recycle() github.com/michalbednarsk…


fatalbit 已轉發

The Android team has open sourced our internal Rust Training! It's a four day course covering the full spectrum of Rust, from basic syntax to advanced topics like generics and error handling. It also includes Android-specific content on the last day. google.github.io/comprehensive-…


fatalbit 已轉發

@kiks7_7 and I released a blogpost about the exploitation of CVE-2022-2602: a Linux use-after-free vulnerability in the io_uring subsystem. exploiter.dev/blog/2022/CVE-…


Loading...

Something went wrong.


Something went wrong.