@the_navs

Security Researcher at █████████████              Strike First. Strike Hard. No Mercy.

Austin, TX
Joined April 2009
Cyber. Peacekeeping.
Do you think that United Nations should engage in cyber peacekeeping missions? If so, how should it look like and when it should be deployed? Also, are we even serious? :-) Also: "disarmament of software applications that can be used for cyber warfare"! academic.oup.com/jcsl/articl…
2
6
32
Replying to @windsheep_ @matalaz
We've got many "professional grade" customers who think otherwise.
1
4
Computer hacking advice from superstar @ThatBigRon, compliments of @nudehaberdasher.
6
43
8
172
This getting 6k retweets is absolutely *hilarious* when you think about it. Hacker, comedian, master of irony... @mdowd is a true Renaissance man.
If the FBI want to get into an iPhone w/o users permission, they should ask someone who's done it before, like U2
2
4
63
A new vulnerability detection: Use of Uninitialized Memory. Using REVEN, it also works when it involves interprocess communication. A post to introduce the new addition to our series of vulnerability detection scripts: url.tetrane.com/KfLyk/248d
1
6
1
11
"I looked at this new Android exploit sample and it's either from a CTF or a nation-state attack." -- @maldr0id
Did my experiment work? No. But did I learn from it? No. But did it help me grow as a scientist? Also no.
309
4,832
871
57,623
navs retweeted
but most of all, samy is my hero
Tell us you work in security without telling us you work in security.
5
24
Sometimes, the best way to learn how to hack something is to build it first.
9
31
6
355
pitch: like @TheFckingRecipe, but for bug advisories
“Bond007”
You’re unable to view this Post because this account owner limits who can view their Posts. Learn more
1
2
Honestly I’m probably going to get some backlash on this, but can the news articles that glorify that Apple hack stop calling @samwcyo et al “security researchers”. It significantly discounts actual security research.
20
1
3
25
New blog entry: An Exhaustively-Analyzed IDB for ComRAT V4. This is one of the most thorough analyses I've ever done; certainly the largest. msreverseengineering.com/blo…
16
244
9
576
Replying to @ruskin147
It is unfortunately common for many in academia to overweight the value of ideas & underweight bringing them to fruition. For example, the idea of going to the moon is trivial, but going to the moon is hard.
513
1,235
195
14,987
Man people doing crime just aren't following any of the rules anymore, are they? What's the world coming to? nitter.cf/tylerni7/status/129869…
This is just cheating: pay an employee $1M to install ransomware on a corporate network, then ask for a $5-10M ransom? That's not even hacking! Where's the skill? the pizzazz? Doesn't need to be 0days but at least find an unpatched system or phish someone! zdnet.com/article/russian-ar…
1
5
12
Over the past 5 years I have been building security programs based on and writing about Adversary-Based Threat Modeling and Risk Analysis. Now it's a training course! Let me know if you want your team to build and operate with adversary intelligence. adversarybased.training/
1
5
19
Ghidra's, and IDA 7.5's new, "folders" feature is incredibly useful for large-scale reverse engineering. I've found it especially provides clarity when organizing reconstructed data structures.
4
19
2
152
Reinstalled my OS yesterday. Apologies to anyone who lost their persistence, and congratulations to anyone who kept theirs 💪
2
27
2
161
when your company transitions from using personal credit cards to mandatory corporate cards for expensing... losing the perk of gaining cc points for work purchases. this picture summarizes my feelings. @the_navs
1
1
1
Want to know how to escape the Chrome sandbox exploiting Android's Binder with CVE-2020-0041? Check out our latest post by @esanfelix and @jgrusko labs.bluefrostsecurity.de/bl…
97
1
162