Bryan Alexander

1.4K posts

Bryan Alexander banner
Bryan Alexander

Bryan Alexander

@dronesec

researcher. exploit dev. hacking @ stripe stop using twitter. find me @ [email protected]

Portland, OR انضم Haziran 2012
333 يتبع1.7K المتابعون
Bryan Alexander أُعيد تغريده
James Forshaw
James Forshaw@tiraniddo·
The Kerberos PAC verification bypass me and @monoxgas showed at the end of our BH presentation and was fixed last month is now open in the issue tracker. Certainly an interesting one :) bugs.chromium.org/p/project-zero…
English
1
34
83
0
Bryan Alexander أُعيد تغريده
stephen
stephen@_tsuro·
Breaking the Chrome Sandbox with Mojo - the recording of my black hat talk is out: youtu.be/qhhJCLy0YBA (I'm painfully aware of the red shift :) )
YouTube video
YouTube
English
1
39
146
0
Bryan Alexander أُعيد تغريده
JF Bastien
JF Bastien@jfbastien·
Wherein I propose that C++ initialize all stack variables to zero, preventing ~10% of CVEs. Cost: none. 🔗 wg21.link/P2723R0 🔗
JF Bastien tweet mediaJF Bastien tweet mediaJF Bastien tweet mediaJF Bastien tweet media
English
75
250
1.7K
0
Bryan Alexander أُعيد تغريده
Shane Huntley
Shane Huntley@ShaneHuntley·
Six actively exploited 0days patched today by Microsoft including one found by @benoitsevens & @_clem1 from TAG. duo.com/decipher/micro… 2022 and we are still seeing active IE scripting exploitation 😔 Thanks to Microsoft for the quick turnaround and patch.
English
1
25
58
0
Bryan Alexander
Bryan Alexander@dronesec·
@drone" target="_blank" rel="nofollow noopener">infosec.exchange/@drone for those that are migrating
English
0
0
0
0
Bryan Alexander أُعيد تغريده
raptor
raptor@0xdea·
Now this is a pretty handy tool... "A plugin to introduce interactive symbols into your debugger from your decompiler" // by @mahal0z github.com/mahaloz/decomp…
raptor tweet media
English
0
16
38
0
Bryan Alexander أُعيد تغريده
Will Oremus
Will Oremus@WillOremus·
Inside Elon Musk's "free speech" Twitter, a culture of secrecy and fear has taken hold. Managers and employees have been muzzled, Slack channels have gone dark, and workers are turning to anonymous gossip apps to find out basic info about their jobs. washingtonpost.com/technology/202…
English
103
727
1.9K
0
Bryan Alexander أُعيد تغريده
Brandon Azad
Brandon Azad@_bazad·
I’m really excited for us to shed light on some really cool work we’ve been doing to harden the XNU allocator! This has been a huge effort by so many people, and I’m very proud of the direction: security.apple.com/blog/towards-t…
English
6
95
394
0
Bryan Alexander أُعيد تغريده
nedwill
nedwill@NedWilliamson·
A couple months overdue, here's the open source release of Concurrence, my new fuzzing library for thread-based targets. Integration code to SockFuzzer, plus Mach process/IPC/VM/etc. support are coming soon. Check it out at github.com/googleprojectz…
English
5
62
239
0
Bryan Alexander أُعيد تغريده
kylebot
kylebot@ky1ebot·
Finally, here is the blog documenting the crazy 7 days that I spent on CVE-2022-1786 to pwn kCTF (and won a lot of cash)! Let me know what you think of the blog! blog.kylebot.net/2022/10/16/CVE…
English
5
225
742
0
Bryan Alexander أُعيد تغريده
Andrey Konovalov
Andrey Konovalov@andreyknvl·
Slides for "Sanitizing the Linux kernel: On KASAN and other Dynamic Bug-finding Tools", the talk I just gave at Linux Security Summit Europe 2022. Covers: 🐧 Generic KASAN implementation 🔥 Other Sanitizers 🗡 Extending KASAN and KMSAN to find more bugs docs.google.com/presentation/d…
Andrey Konovalov tweet media
English
7
75
258
0
Bryan Alexander أُعيد تغريده
CTurt
CTurt@CTurtE·
New blog post! Part 1 in my new PlayStation hacking series: An **unpatched** PS4 / PS5 userland exploit that also allows pirating PS2 games. mast1c0re: Hacking the PS4 / PS5 through the PS2 emulator - Part 1 - Escape: cturt.github.io/mast1c0re.html Video demo: youtube.com/watch?v=GIl1mR…
YouTube video
YouTube
English
61
311
1.2K
0
Bryan Alexander أُعيد تغريده
Kostya Serebryany
Kostya Serebryany@kayseesee·
We had quite some fun for the last 2.5 years fuzzing CPUs. We wrote one system, scratched it, and wrote another one. This week we open-sourced most of it, and hope to open-source more in the future. github.com/google/silifuzz
English
5
135
602
0