seprioth
57 posts
seprioth
@newroot
There are known knowns. There are known unknowns; But there are also unknown unknowns there are things we do not know we don't know
انضم Temmuz 2009
292 يتبع294 المتابعون

Does anyone know working exploit for CVE-2020-12351(2)? Wanna know details of exploitation, not the result. It's either complex remote kernel exploitation with `a2mp_info_req` leak and `sock->data` type confusion OR POC video by @theflow0 was fake.
#bleedingtooth #bluetooth
English
if you havent read this alredy u shoult do it. static programm analysis by moller and schwartzbach: cs.au.dk/~amoeller/spa/…
English
from @gannimo block oriented programming for data only exploits. github.com/HexHive/BOPC nebelwelt.net/publications/f… nebelwelt.net/blog/20181231-… comes with compiler and research papers + short overview in a blog. nice work
English
(advanced)Data-Oriented Programming: huhong-nus.github.io/advanced-DOP/i… and automatic generation usenix.org/node/190963
English
(State of) The Art of War: Offensive Techniques in Binary Analysis cs.ucsb.edu/~vigna/publica…
English
Weird machines, exploitability, and provable unexploitability: ieeexplore.ieee.org/document/82268… from bright minds of halver, stealth, rpw, fx, sb,..
English
VisUAL: A highly visual ARM emulator bit.ly/2r9pDBD but only as binary download available @pdp
English
this e-book has a great coverage of x86/x64, ARM/ARM64, MIPS, Java/JVM:beginners.re
English
Quick introduction into SAT/SMT solvers and symbolic execution by yurichev: yurichev.com/tmp/SAT_SMT_DR…
English
BASIC/VB C/C++ ASM(sparc,mips, 86/64, arm) PHP PERL JAVA LUA #FirstSevenLanguages
English
goldie nobody had spend attention to: stackframeing nx and randomized image base on Windows (nergal style) in '04 bit.ly/2bolcPE
English
@dinodaizovii remember some codes fromsauron and spacewalker who using rop before (not ret2libc) and matrix_challege2.c was required to rop
English