pwningsystems's profile picture. Security Engineer @ Google, likes fuzzing, static analysis and VR.

The opinions stated here are my own, not those of my company.

Jordy Zomer

@pwningsystems

Security Engineer @ Google, likes fuzzing, static analysis and VR. The opinions stated here are my own, not those of my company.

Pinned

Yay! My writeup on finding (half) Spectre-v1 gadgets in the Linux kernel using #CodeQL is finally live 😁😁 github.com/google/securit…


TAINT TRACKING BAYBEEE 🔥 one query away from bugs, one missing .decl away from madness

pwningsystems's tweet image. TAINT TRACKING BAYBEEE 🔥
one query away from bugs, one missing .decl away from madness

I’m starting to think these “routine” police controls at the German borders are not so random. Like literally every time they do a control it’s always me 😂


Jordy Zomer reposted

I've been asked countless times how to learn VR & xdev. The answer is always: "do something you think is cool". It's hard to figure out what to do. Try the PhrackCTF which I've now open-sourced. It's not a contrived CTF - modeled after real vulnerabilities github.com/xforcered/Phra…


Jordy Zomer reposted

At long last - Phrack 72 has been released online for your reading pleasure! Check it out: phrack.org

phrack's tweet image. At long last - Phrack 72 has been released online for your reading pleasure! 

Check it out: phrack.org

The eiffel tower is looking pretty today 🦅

pwningsystems's tweet image. The eiffel tower is looking pretty today 🦅

Why is it so fucking hot in NYC rn, I am literally dying


Jordy Zomer reposted

I really like that hacking zines are now in this trend of having printed copies! It is about time. I got a few to give to folks that can't buy. Lets spread it.

We've reached a huge milestone in terms of Paged Out! prints - they are now available in the first online bookstore with global shipping: lulu.com/search?contrib… There are 4 versions there - a normal one and 3 "sponsorship" ones if you want to donate a bit more to the project.

gynvael's tweet image. We've reached a huge milestone in terms of Paged Out! prints - they are now available in the first online bookstore with global shipping:
lulu.com/search?contrib…
There are 4 versions there - a normal one and 3 "sponsorship" ones if you want to donate a bit more to the project.


I’m writing a CodeQL like language for fun that works on Binary Ninja IR, by lowering OOP primitives to datalog for “fun” can’t wait to finds some bugs with it! 😁😁


Jordy Zomer reposted

Slides from my talk are here: dillonfrankesecurity.com/OffensiveCon-2… And the recording is here! youtu.be/USQtPedx9Xg?fe…

dillon_franke's tweet card. OffensiveCon25 - Dillon Franke

youtube.com

YouTube

OffensiveCon25 - Dillon Franke

Had an absolute blast In Berlin at @offensive_con! So many awesome people, conversations, and events. Thanks so much to the organizers for having me and putting on a fantastic event!!

dillon_franke's tweet image. Had an absolute blast In Berlin at @offensive_con! So many awesome people, conversations, and events. Thanks so much to the organizers for having me and putting on a fantastic event!!
dillon_franke's tweet image. Had an absolute blast In Berlin at @offensive_con! So many awesome people, conversations, and events. Thanks so much to the organizers for having me and putting on a fantastic event!!
dillon_franke's tweet image. Had an absolute blast In Berlin at @offensive_con! So many awesome people, conversations, and events. Thanks so much to the organizers for having me and putting on a fantastic event!!
dillon_franke's tweet image. Had an absolute blast In Berlin at @offensive_con! So many awesome people, conversations, and events. Thanks so much to the organizers for having me and putting on a fantastic event!!


Arrived in Berlin today for @offensive_con 😁


Jordy Zomer reposted

My team (AI Systems Security) at Google Zürich🇨🇭is hiring a Security Engineer for AI Vulnerability Research! We're looking for experts to tackle asset exfiltration, tampering and computational resources abuse. Apply: google.com/about/careers/…


Awesome work by Adam! 😁

My latest Spectre research is now public! See intra-mode BHI CPU vulnerability disclosure and PoC at github.com/google/securit…. This user-to-kernel attack bypasses eIBRS, BHB clearing and other mitigations.



Jordy Zomer reposted

ok ok fine, for old time's sake haxx.in/files/limit-yo…

bl4sty's tweet image. ok ok fine, for old time's sake 
haxx.in/files/limit-yo…

Jordy Zomer reposted

Branch Race Conditions Predictor causes recent predictions to be added after more recent privilege switches (→ wrong privilege, eIBRS💥) prediction flushes (→ retained valid, IBPB💥) finish. @sparchatus eventually figured it out 🙌

Disclosing Branch Predictor Race Conditions (BPRC), a new class of vulnerabilities where asynchronous branch predictor operations violate hardware-enforced privilege and context separation in virtually all recent Intel CPUs. @wiknerj @kavehrazavi : comsec.ethz.ch/bprc

sparchatus's tweet image. Disclosing Branch Predictor Race Conditions (BPRC), a new class of vulnerabilities where asynchronous branch predictor operations violate hardware-enforced privilege and context separation in virtually all recent Intel CPUs. @wiknerj @kavehrazavi : comsec.ethz.ch/bprc


Implementing a custom #CodeQL extractor + libs for an unsupported language is pure torture but hey I found some bugs already so I guess it’s worth it


Going to hacker bridge at 1337 😎🤙

pwningsystems's tweet image. Going to hacker bridge at 1337 😎🤙

That moment when you found a bug but it's a PITA to reach so you just point afl++ at it :')


Jordy Zomer reposted

I would like to praise @gabrielnb outstanding contributions to the security community and hacking, not only as editor of the magazine for the past 6+ years, but also for his sharing of perspectives, guidance and technical contributions. In this edition we wrote another small…

#H2HC2024 (Revista #19) versao Online finalmente lancada! github.com/h2hconference/… - Mais de 100 paginas de conteudo gratuito, exclusivo e de alto nivel. Agradecemos o trabalho do editor @gabrielnb em todos esses anos, sendo esta sua ultima participacao como editor!



Woop woop bought tickets for @WHY2025Camp 😎😎


Wrote a MCP server for #CodeQL, tried it out with Cursor and it's quite fun so far! I think the next step would be adding support for query-models. Allowing an LLM to easily add sources/sinks to existing queries could be very promising😁 github.com/JordyZomer/cod…


Loading...

Something went wrong.


Something went wrong.