red0xff

38 posts

red0xff banner
red0xff

red0xff

@red0xff

Vulnerability research at  @apple Open Source / Offensive Security

Paris, France 参加日 Temmuz 2020
721 フォロー中504 フォロワー
red0xff
red0xff@red0xff·
Second time I complete flare-on :p, despite the busy month. ping @RandoriSec
red0xff tweet media
English
2
0
37
0
red0xff
red0xff@red0xff·
Hello, I will be at @hexacon_fr, come say hi ! I will be glad to discuss anything. We are also hiring at @RandoriSec ;)
English
0
0
23
0
hardwear.io
hardwear.io@hardwear_io·
🔮Breaking into 📱iPhone's last Security Barrier 💡@tihmstar will present his work on attacking the iPhone's hardware AES crypto core through an EM-sidechannel in order to retrieve the hardware fused GID and UID keys 🎟️Grab your tickets 👉bit.ly/3BSDXU6 #hw_ioNL2022
hardwear.io tweet media
English
1
8
63
0
Alex Xu
Alex Xu@alexxubyte·
/1 How do Apple Pay and Google Pay handle sensitive card info? The diagram below shows the differences. Both approaches are very secure, but the implementations are different. To understand the difference, we break down the process into two flows.
Alex Xu tweet media
English
456
8.6K
35.8K
0
red0xff
red0xff@red0xff·
@Shawan_J Hello, my DMs are disabled? I'm checking
English
0
0
0
0
red0xff
red0xff@red0xff·
A random idea I had that turned into a short new blog post. (This post does not demonstrate a vulnerability, but rather a logic flaw in the execution environments of the most popular competitive programming platforms). red0xff.github.io/posts/cracking…
English
1
3
27
0
red0xff がリツイート
Man Yue Mo
Man Yue Mo@mmolgtm·
This might be the best bug I found. Never thought I'd be writing a kernel exploit as reliable, clean and fast as a browser exploit. For a while I actually used this to root my research phone when can't be bothered to patch the rom: github.blog/2022-07-27-cor…
English
7
124
423
0
red0xff がリツイート
Hexacon
Hexacon@hexacon_fr·
Hajime! We are glad to announce our second ring0 sponsor! 🙏 Thank you @RandoriSec for helping us to gather the infosec community in Paris ⛩️ To find out more about RandoriSec, visit their website at randorisec.fr #HEXACON2022
Hexacon tweet media
English
0
7
21
0
red0xff がリツイート
HyperDbg
HyperDbg@HyperDbg·
Here are 11 reasons why we should use #HyperDbg, the differences between HyperDbg and #WinDbg, and how HyperDbg will change our debugging/reversing journey. A thread (24 tweets) 🧵:
English
13
99
326
0
red0xff がリツイート
RandoriSec
RandoriSec@RandoriSec·
Today is a great day ! @red0xff is joining us as a reverser 🔬 Welcome on board !
English
2
6
34
0
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
If you're curious, the list of scientists/hackers they use (along with a brief comment about each) is here. We used a similar strategy for generating anonymized team names for @Rode0day, but with insect names (bugs, get it?) :) #L120-L836" target="_blank" rel="nofollow noopener">github.com/moby/moby/blob…
English
1
1
6
0
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
Just got "unruffled_elbakyan" as a container name :)
English
1
0
16
0
red0xff
red0xff@red0xff·
Just published a new article about Keccak/Sha3 (explains its steps in simple words, and explains how leaking the internal state can lead to unwanted consequences) red0xff.github.io/posts/invertin… Feedback is welcome (PS: I'm not a cryptographer)
English
1
9
33
0
~
~@oosindf·
@red0xff Congrats man 🔥
English
1
0
1
0