Davide Ornaghi

74 posts

Davide Ornaghi banner
Davide Ornaghi

Davide Ornaghi

@TurtleARM97

A pentester doing security research while dumping NTDS

Milan Bergabung Haziran 2022
71 Mengikuti378 Pengikut
Tweet Disematkan
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
LPE for CVE-2023-0179 is live! Compatibility with other versions should be just a matter of offsets. It was nice not having to deal with stack offset randomization. github.com/TurtleARM/CVE-…
English
2
32
65
14.9K
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
While testing and fixing a couple of NPDs in nftables, I found that reusing the subsystem after crashing triggers a UAF read on the previously freed task_struct when reacquiring the commit mutex, maybe worth a look? github.com/torvalds/linux…
English
0
0
4
449
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
Syzkaller being mad about my custom grammar
Davide Ornaghi tweet media
English
0
0
1
257
Davide Ornaghi me-retweet
Lau
Lau@notselwyn·
Exciting news! 🚀 Just dropped my blogpost unveiling the universal Linux kernel LPE PoC for CVE-2024-1086 (working on v5.14 - v6.7) used for pwning Debian, Ubuntu, and KernelCTF Mitigation instances, including novel techniques like Dirty Pagedirectory 🧵 pwning.tech/nftables
English
12
264
780
114.6K
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
CVE-2023-3338 represents a series of issues I found in the Linux DECnet Layer (a 20-year-old protocol) that caused it to be removed from all LTS releases, the most obvious one being this NPD openwall.com/lists/oss-secu…
English
0
0
4
299
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
Quick gdb tip to access per-cpu variables in case lx_per_cpu doesn't work: x __per_cpu_offset[$lx_current().cpu] + (unsigned long) var
English
0
0
7
564
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
Spent hours trying to mask timer interrupts on gdb to prevent LAPIC events when all I had to do was update QEMU
English
0
0
1
251
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
Writing CodeQL queries that actually do what you expect feels like magic
English
0
0
1
284
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
When your UAF read reallocation isn't behaving
Davide Ornaghi tweet media
English
0
0
4
655
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
Why is SystemTap so hard to run on custom kernels ☹️
English
0
0
0
204
Davide Ornaghi me-retweet
Nikias Bassen
Nikias Bassen@pimskeks·
I will be at @HITBSecConf #HITB2023AMS this week, if you are around, pull up, they have a free CommSec track too!
English
0
5
6
3.2K
Davide Ornaghi
Davide Ornaghi@TurtleARM97·
Looks like I’ll be speaking at @HITBSecConf about kernel (in)security and other exciting stuff!
English
0
0
2
420