whw

81 posts

whw banner
whw

whw

@WHW_0x455

Defense things this time

Beigetreten Ocak 2021
343 Folgt388 Follower
whw
whw@WHW_0x455·
@cutesmilee__ I don’t have a computer with IDA by hand now. But this part in GTIG’s blog is basically right. You can check the RWTransfer::Get and RWTransfer::Give.
whw tweet media
English
1
0
0
175
Tommaso
Tommaso@cutesmilee__·
@WHW_0x455 are you sure about that? I looked a bit at it and to me it looks like it builds krw, it was messing with fds and thread states in order to get respectively aaw and aar
English
1
0
0
128
whw
whw@WHW_0x455·
These ITW chains remind me the 2023 Predator. THE ipc_right_destroy bug is like a nightmare to me. The mach ipc really changed a lot after that. But I guess I just can’t forget such a special bug, especially after investing time and didn’t figure that out.
English
1
1
15
1.5K
whw
whw@WHW_0x455·
@cutesmilee__ The sample gets krw from another process. Maybe Webcontent or something else. Like the watcher passes krw to the helper in the sample.
English
1
0
0
152
Tommaso
Tommaso@cutesmilee__·
@WHW_0x455 have you looked at the intellexa sample to see how they managed to get krw with that?
English
1
0
0
221
whw
whw@WHW_0x455·
@khanhduytran0 Always update your daily device. I do know someone who got attack in December 2025.
English
1
0
1
1.9K
whw
whw@WHW_0x455·
@khanhduytran0 @devtosbaha I will try ! For unknown reason, I can’t set x0 when -[AMFIPathValidator_macos validateWithError:] returns in LLDB. I hope this will work
English
1
0
0
155
Duy Tran
Duy Tran@khanhduytran0·
@WHW_0x455 @devtosbaha You can also put a breakpoint at `-[AMFIPathValidator_macos validateUsingMacOSProvisioningProfileWithRestrictedEntitlements:andSoftRestrictedEntitlements:andApplicationIdentifier:]` and return 0
English
1
0
0
165
Duy Tran
Duy Tran@khanhduytran0·
All 3 have been pwned via Safari 15.4.1 arm64 16.5 arm64e 17.0 arm64e
English
25
56
632
86.1K
whw
whw@WHW_0x455·
@devtosbaha I'm trying amfidont. Looks like lldb cannot get codePath from amfid
English
1
0
0
618
Mustafa
Mustafa@devtosbaha·
@WHW_0x455 Use amfidont which is listed as option 2 in the repo.
English
1
0
0
630
whw
whw@WHW_0x455·
@matteyeux iOS version ?
Español
0
0
0
519
matteyeux
matteyeux@matteyeux·
Infecting myself with the Coruna exploit chain right now. You can see the chain being triggered and the C2 communication
matteyeux tweet media
English
10
26
245
15.9K
whw
whw@WHW_0x455·
All right…. Being busy these days and missing a lot of things. Any sample for Coruna ? Public or private share will be appreciated !
English
1
0
2
405
whw retweetet
Sean Heelan
Sean Heelan@seanhn·
What mathematicians call "literature review" should be familiar to you as "vulnerability research". Or, put another way: erdosproblems.com is currently the best benchmark for LLM capabilities in finding 0days.
Sean Heelan tweet media
Dmitry Rybin@DmitryRybin1

Recently I gave a talk on LLMs for Math Research (mostly to an audience of pure and applied mathematicians) I tried to compile the latest progress in one presentation pdf and video recording: drive.google.com/drive/folders/…

English
6
19
172
29.7K
whw retweetet
blackorbird
blackorbird@blackorbird·
A full iOS zero-day exploit chain used in the wild against targets in Egypt. #Intellexa #Predator Stage 1: Initial RCE via JSKit Framework (Safari WebKit Exploitation)Entry Point: The chain starts with a zero-day RCE vulnerability in Safari's WebKit rendering engine, patched by Apple as CVE-2023-41993 (a memory corruption issue in the JIT compiler). Stage 2: Sandbox Escape and Kernel Privilege EscalationVulnerabilities Exploited: CVE-2023-41992: Kernel IPC use-after-free (sandbox escape + local privilege escalation, LPE). CVE-2023-41991: Code-signing bypass (LPE). Stage 3: Persistence and Surveillance Setup (PREYHUNTER Modules)Components: Divided into two modules—"watcher" and "helper"—deployed via the escalated privileges from Stage 2. cloud.google.com/blog/topics/th… github.com/blackorbird/AP…
blackorbird tweet mediablackorbird tweet media
English
7
87
410
54.4K
whw
whw@WHW_0x455·
@wwwGUIA 可以检查一下 vmware nat的dhcp,我最常遇到的就是 nat 的 dhcp不工作了。所以我习惯关闭 nat 的 dhcp,自己手动指定ip和网关。
中文
0
0
2
607
鬼鵝🌙
鬼鵝🌙@wwwGUIA·
求救!VMware 其中一個虛擬機不聯網。
中文
34
0
26
18.2K
whw retweetet
Lorenzo Franceschi-Bicchierai
SCOOP: A man who worked on developing hacking tools for defense contractor L3Harris Trenchant was notified by Apple that his iPhone was targeted with spyware. It's unclear who targeted him, but he believes he was the scapegoat of a leak investigation. techcrunch.com/2025/10/21/app…
English
12
129
435
186.4K