pwnmonk's profile picture.

pwnmonk

@pwnmonk

pwnmonk reposted

Say hello to Eternal Tux🐧, a 0-click RCE exploit against the Linux kernel from KSMBD N-Days (CVE-2023-52440 & CVE-2023-4130) willsroot.io/2025/09/ksmbd-… Cheers to @u1f383 for finding these CVEs + the OffensiveCon talk from gteissier & @laomaiweng for inspiration!


pwnmonk reposted
miniarchillect's tweet image.

pwnmonk reposted

I've been asked countless times how to learn VR & xdev. The answer is always: "do something you think is cool". It's hard to figure out what to do. Try the PhrackCTF which I've now open-sourced. It's not a contrived CTF - modeled after real vulnerabilities github.com/xforcered/Phra…


pwnmonk reposted

🔥 1/ In the last 6 months working on Linux kernel bug hunting/exploitation there has been a number of key resources which have been super useful (coming from a macOS/Windows background) to understand the state of things in 2022 🚀. Here's a short🧵 to recognise this + thoughts:

alexjplaskett's tweet image. 🔥 1/ In the last 6 months working on Linux kernel bug hunting/exploitation there has been a number of key resources which have been super useful (coming from a macOS/Windows background) to understand the state of things in 2022 🚀.

Here's a short🧵 to recognise this + thoughts:

pwnmonk reposted

pwncollege V8 Exploitation WP 上 loora1n.github.io/2024/11/27/%E3… pwncollege V8 Exploitation WP 中 loora1n.github.io/2024/12/02/%E3… pwncollege V8 Exploitation WP 下 loora1n.github.io/2024/12/24/%E3…


pwnmonk reposted

@steven_rossi_ and I taught a course on Binary Exploitation and Vulnerability Analysis at UMass Amherst for the past 2 years. After this semester's offering we decided to open source all course material including lecture vods, slides, and projects. pwn.umasscybersec.org


pwnmonk reposted

Getting a lot of DMs about how to start in the Web3 security space I’ve seen a few threads about this and honestly, they are all good, but This is what I did personally:👇


pwnmonk reposted

Breaking JIT range assumptions in JSC: here's my writeup for b3typer from bi0sCTF 2022! blog.bi0s.in/2023/01/23/Pwn…


pwnmonk reposted

Pwned GKE under Google's #kctf program again!

ky1ebot's tweet image. Pwned GKE under Google's #kctf program again!

pwnmonk reposted

Now this is creepy. This AI model can detect the pose of people in the room based just on WiFi signals. No camera needed.

WholeMarsBlog's tweet image. Now this is creepy. 

This AI model can detect the pose of people in the room based just on WiFi signals. No camera needed.

pwnmonk reposted

From 0 to 38 audits 🕵🏻‍♂️ In July, I quit my web2 dev job. I spent August grinding past CTFs to prepare for @paradigm_ctf Then was the Paradigm CTF, and that was the biggest charge of motivation I had ever had. In September I did my first security audit, and here I'm now 👇

jeiwan7's tweet image. From 0 to 38 audits 🕵🏻‍♂️

In July, I quit my web2 dev job. I spent August grinding past CTFs to prepare for @paradigm_ctf Then was the Paradigm CTF, and that was the biggest charge of motivation I had ever had. In September I did my first security audit, and here I'm now 👇
jeiwan7's tweet image. From 0 to 38 audits 🕵🏻‍♂️

In July, I quit my web2 dev job. I spent August grinding past CTFs to prepare for @paradigm_ctf Then was the Paradigm CTF, and that was the biggest charge of motivation I had ever had. In September I did my first security audit, and here I'm now 👇
jeiwan7's tweet image. From 0 to 38 audits 🕵🏻‍♂️

In July, I quit my web2 dev job. I spent August grinding past CTFs to prepare for @paradigm_ctf Then was the Paradigm CTF, and that was the biggest charge of motivation I had ever had. In September I did my first security audit, and here I'm now 👇

pwnmonk reposted

This really helped me to understand what auditing is: youtu.be/LLiJK_VeAvQ


pwnmonk reposted

Late christmas present: github.com/TheOfficialFlo… WebKit+Kernel exploit chain for all PS Vita firmwares. This is a WIP from 3 years ago that I never finished (exploit is fully working, but hasn't been turned into a jailbreak yet).


pwnmonk reposted

pretty good collection of exploitation-friendly linux kernel structs: blog.csdn.net/panhewu9919/ar… also recommend browsing the kCTF cook book: docs.google.com/document/d/1a9…


pwnmonk reposted

The Christmas open-obfuscator challenge is live at this address: obfuscator.re/challenges/ Thank you to @vector35 @build38dotcom and @eshard for sponsoring the prizes of this challenge.

rh0main's tweet image. The Christmas open-obfuscator challenge is live at this address:

obfuscator.re/challenges/

Thank you to @vector35 @build38dotcom and @eshard for sponsoring the prizes of this challenge.

pwnmonk reposted

I had some #flareon9 writeups i forgot to share: matth.dmz42.org/posts/2022/fla… but nothing revolutionary :-)


pwnmonk reposted

ITS FINALLY DONE Twas the night before an upgrade ⭐️🎄❤️

_sysengineer's tweet image. ITS FINALLY DONE 
Twas the night before an upgrade ⭐️🎄❤️

Loading...

Something went wrong.


Something went wrong.