w0 retweeted
💥BOOM!💥 Another privilege escalation blog, this time showcasing how to convert arbitrary file deletions 🗑️ to SYSTEM command prompt🌈 CVE-2023-27470. Learn about TOCTOU, pseudo-symlinks, MSI rollback exploits, and, of course, how to protect yourselves!
mandiant.com/resources/blog/…
w0 retweeted
PS5 Release: Kernel Exploit (Webkit – v1.03) compiled for ESP8266
Blog post:
wololo.net/2023/08/13/ps5-re…
Downloads :
github.com/frwololo/PS4_PS5-…
w0 retweeted
Hello.. is this thing still on?
It's 2023, so here's a fun new blogpost on how we used Intel's x86 CPU JTAG to dump the infamous "secret bootrom" in Microsoft's original Xbox: blog.ret2.io/2023/08/09/jtag…
w0 retweeted
Enhancing Chromium’s Memory Safety with Armv9 -- community.arm.com/arm-commun…
w0 retweeted
Me, starting to analyze a new piece of software: I basically know how this works already, I just need to learn a few of the finer details
Me, a week later: I don't know anything about this software, or computers in general.
w0 retweeted
A rowhammer-style but different (and worse?) mechanism to induce DRAM bit flips.
Get popcorn.
w0 retweeted
CVE-2023-2008 - Analyzing and exploiting a bug in the udmabuf driver by @dialluvioso_ and @esanfelix labs.bluefrostsecurity.de/bl…
I can finally have closure and peace of mind
We've been asked to share the kernel challenge we had at OffensiveCon. You can download it at static.bluefrostsecurity.de/… and give it a try. It was meant to be solved live at the conference, but apparently the noisy environment and german keyboard layout made it too hard :').
w0 retweeted
Driver adventures for a 1999 webcam blog.benjojo.co.uk/post/quic…
w0 retweeted
New blog post is up! Dumping the AMLogic A113X/A113D BootROM (and eFUSE/OTP data): haxx.in/posts/dumping-the-am…
w0 retweeted
Here are the slides for my keynote, 'Mobile Exploitation, the past, present, and the future' at #Zer0Con2023. Zer0con was a blast as always, thank you @POC_Crew!! 🚀💫
github.com/externalist/prese…
w0 retweeted
✨Amazing detection and analysis by @_clem1 and Google TAG on 2 different campaigns using 5 different 0-days and numerous n-days. Android, iOS, and Samsung devices were targeted
blog.google/threat-analysis-…
w0 retweeted
mast1c0re: Part 3 – Escaping the PS5 emulator reddit.com/r/netsec/comments…
w0 retweeted
It's time everybody!!! the OffensiveCon23 ticket shop is now open! Get your tickets quickly, as they tend to run out pretty soon. offensivecon.org/register.ht…
w0 retweeted
Old news for us, but others might find it interesting: willsroot.io/2022/12/entrybl…
See: nitter.cf/grsecurity/status/1128… (2019) nitter.cf/grsecurity/status/9547… (2018)
Users should not take too seriously the cover stories used to disguise embargoed vulnerability fixes.
Based solely on what you've read from Linus (git.kernel.org/pub/scm/linux…) and publications like LWN, (lwn.net/Articles/738975/ lwn.net/Articles/741878/) do the current KAISER/PTI implementations prevent defeating KASLR via Meltdown on Intel CPUs?
36%Yes
64%No
109 votes • Final results w0 retweeted
Exploiting CVE-2022-42703 - Bringing back the stack attack googleprojectzero.blogspot.c…
w0 retweeted
KmsdBot Botnet Is Down After Operator Sends Typo In Command packetstormsecurity.com/news…
w0 retweeted
How the 8086 processor's microcode engine works righto.com/2022/11/how-8086-…