Bonfee

28 posts

Bonfee

Bonfee

@Bonfee1

Security researcher | CTF @aboutblankets

EL3 Katılım Aralık 2020
264 Takip Edilen794 Takipçiler
Bonfee retweetledi
Marco Bonelli
Marco Bonelli@mebeim·
Pwners in Paris
Marco Bonelli tweet mediaMarco Bonelli tweet media
CY
0
1
9
1K
Bonfee retweetledi
ECSC2024
ECSC2024@ecsc2024·
Hi @discord! We are hosting @ecsc2024 right now and we have our IP banned, we opened a ticket without answers, can you please write us? DM or info@ecsc2024.it ⚠️
English
2
27
83
16.9K
Bonfee retweetledi
mhackeroni
mhackeroni@mhackeroni·
New faces + old faces, playing DEF CON CTF and @hack_a_sat in parallel. Proud of us. 🍝
mhackeroni tweet media
English
2
35
201
24.7K
Bonfee
Bonfee@Bonfee1·
Cool kernel pwn challenge from corCTF 2023, CVE-2023-0461 + kCFI + limited set of available syscalls
Bonfee tweet media
English
1
11
155
16.9K
Bonfee
Bonfee@Bonfee1·
@hexacon_fr was amazing, congrats to the organizers :)
Bonfee tweet media
English
0
0
8
0
Bonfee
Bonfee@Bonfee1·
Another Ubuntu 21.10 LPE :) This bug doesn't even have a CVE yet. To pwn it I used the same technique described here: google.github.io/security-resea…. I'll clean the code just a bit, before releasing it
English
15
243
750
0
Alex Plaskett
Alex Plaskett@alexjplaskett·
@Bonfee1 Heh does the commit hash fixing the bug end in 2?
English
1
0
0
0
Alex Plaskett
Alex Plaskett@alexjplaskett·
@Bonfee1 Nice one! Your vuln object is on the kmalloc-2k cache? Interested to know if I know this bug 😂
English
1
0
0
0
Jamie Hill-Daniel
Jamie Hill-Daniel@clubby789·
@Bonfee1 Nice one - is this another bug that was introduced in 5.x, or does it go back further?
English
1
0
0
0
Bonfee
Bonfee@Bonfee1·
( Just to be clear, this is not a 0 day, i only saw the commit fixing the bug and developed the exploit for it. )
English
0
0
32
0
Bonfee
Bonfee@Bonfee1·
@raesene @Terenceliqiang With the proper ropchain yes. If you are talking specifically about google kctf, then no because the kernel is compiled without the required CONFIG_ :(
English
1
0
2
0
Bonfee
Bonfee@Bonfee1·
CVE-2022-25636 exploit - LPE on Ubuntu 21.10, using the FUSE technique ( which i first saw from @cor_ctf ). I also developed an exploit which is not using FUSE, but for now: github.com/Bonfee/CVE-202…. I'll soon publish a writeup with the exploitation details.
English
1
12
38
0
Bonfee
Bonfee@Bonfee1·
It finally arrived :)
Bonfee tweet media
English
0
0
21
0