crixer
@pwning_me
working at ssd-labs (@LabsSsd) aka. crixer
You might like
💪😎
Our 1st #Pwn2Own #AfterDark concludes with the Mofoffensive Research Team combining a heap overflow and a stack-based buffer overflow to gain code execution on the LAN interface of the NETGEAR R6700 router. Their efforts earn $5,000 and 1 Master of Pwn point. #P2OAustin
Attention Speakers: Our 2024 Call for Papers is now open! Want to headline #TyphoonCon24? Learn all about it: typhooncon.com/call-for-paper…
🌪️TyphoonCon CTF🌪️ is back for the 3rd year in a row and registration is now open! Test your skills and get a chance to win up to $5,000 in prizes🎁 Register at: typhooncon.com/ctf/
🌪️ TyphoonPWN is back for its 5th edition! Show off your skills with Linux, Chrome and many others for your chance to win up to $250,000 in prizes! The event is open to worldwide remote participation. Learn more at: typhooncon.com/typhoonpwn-202…
i'm confusion because i used this bug to pwn in aution 2021 on netgear. I thought this vulnerability didn't be triggerble when I looked at the latest version of netatalk. zerodayinitiative.com/advisories/ZDI…
[ZDI-23-094|CVE-2022-43634] Netatalk dsi_writeinit Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 9.8; Credit: @Synacktiv) zerodayinitiative.com/advisories/ZDI…
🌪️ TyphoonCon 2023 Early bird tickets are now available in limited quantities! 🌪️ Don’t miss out on the best All Offensive Security Conference in Asia. Get your #TyphoonCon23 tickets today! typhooncon.com/register/
typhooncon.com
Register
Register
Zero Day Vulnerability: Chromium v8 js engine issue 1303458 — Use After Free in x64 Instruction Optimization Vulnerability Analysis infosecwriteups.com/zero-day-vulne…
Are browser exploits part of your daily routine? Do you forget from time to time that Safari is also a place you can visit? We are offering up to $300,000 for Safari Remote Code Execution vulnerabilities. Visit ssd-disclosure.com/safari-vulnera… and get the BIG payouts you deserve!
CodeQL is seriously underrated as a tool for exploit development
CodeQL int getOffset(Type t, Field f) { f.getDeclaringType() = t and ( (f.getType().getSize() = 4 and result = f.getByteOffset()) or exists(Field f2 | f2.getDeclaringType() = f.getType() and result = f.getByteOffset() + getOffset(f.getType(), f2)))} lgtm.com/query/84522036…
Exploit CVE-2020-8835 (another kernel bpf bug). Same approach i did exploiting CVE-2017-16995 in the previous tweet. Overwriting bpf_map ops from array_of_map to array_of_maps_map_ops to gain arbitrary write, then overwriting modprobe_path to get root gist.github.com/d4em0n/e8d209e…
Pwning VMware, Part 2: ZDI-19-421, a UHCI bug nafod.net/blog/2020/02/2…
Do you still plan on writing your exploit scripts in elisp^Wpython2? Be ready in a few months to plug in, dial that modem, heap spray some cats, pop some BGP boxes and ~ b l a z e ~ like there's no tomorrow. Rolling big blunts @ 4/20/2020, hacking like it's 4/20/1999.
VM escape exploit for CVE-2019-6778 in QEMU. I'm too lazy to write an English version writeup, sorry for the inconvenience😅 github.com/Kira-cxy/qemu-…
Here's the slides for my #MOSEC / #OBTS talk "A few JSC tales": iokit.racing/jsctales.pdf
"Context Switching your Kernel Fuzzing" - Slides from Eric Sesterhenn's talk about fuzzing kernel code in user space at @BSidesStuttgart: github.com/x41sec/slides/…
I wrote a thing about my macOS sandbox escape & LPE from Pwn2Own phoenhex.re/2019-05-26/att…
I found a bug CVE-2019-11693 in firefox for going to pwn2own but it occurs only linux. mozilla.org/en-US/security…
United States Trends
- 1. Grammy 251K posts
- 2. Clipse 15.1K posts
- 3. Dizzy 8,820 posts
- 4. Kendrick 53.6K posts
- 5. olivia dean 12.4K posts
- 6. addison rae 19.5K posts
- 7. AOTY 17.7K posts
- 8. Katseye 102K posts
- 9. Leon Thomas 15.5K posts
- 10. gaga 91.6K posts
- 11. #FanCashDropPromotion 3,505 posts
- 12. Kehlani 30.6K posts
- 13. ravyn lenae 2,838 posts
- 14. lorde 11.1K posts
- 15. Durand 4,566 posts
- 16. Alfredo 2 N/A
- 17. Album of the Year 56.3K posts
- 18. The Weeknd 10.5K posts
- 19. Alex Warren 6,200 posts
- 20. #FursuitFriday 11.3K posts
You might like
-
Dohyun Lee
@l33d0hyun -
POC_Crew
@POC_Crew -
Alex Plaskett
@alexjplaskett -
Theori
@theori_io -
ohjin
@pwn_expoit -
INSU YUN
@insu_yun -
aSiagaming
@vngkv123 -
c2w2m2
@c2w2m2 -
chillbro4201
@chillbro4201 -
Xion
@0x10n -
adm1nkyj
@adm1nkyj1 -
Jioundai
@Jioun_dai -
Juno | ChainLight
@junorouse -
hk
@harsh_khuha -
Andrew Wesie
@andrewwesie
Something went wrong.
Something went wrong.