Zhongyu Pei

62 posts

Zhongyu Pei

Zhongyu Pei

@BrieflyX

Security researcher from Alibaba Inc. / Tsinghua University CTF player of Tea-deliverers / Blue-lotus Fuzzing / Binary Analysis

Katılım Mayıs 2017
205 Takip Edilen691 Takipçiler
swing
swing@bestswngs·
这周一个同学和我一起学习了下 CVE-2024-21762 这个漏洞,感觉整体利用起来还是蛮有意思的。🧐
中文
11
2
44
16.2K
cxm95
cxm95@cxm95·
🤡
cxm95 tweet media
QME
6
0
23
0
swing
swing@bestswngs·
关于 CVE-2022-0847 这个漏洞的另外一个影响: 1. 昨天 ph 师傅在 Docker 里复现这个漏洞的时候发现: 如果修改了容器内的文件,重启一个新的容器发现文件也被修改了 2. 那么这个有什么影响呢? 对!这个漏洞可以影响同一个镜像的不同容器,即他可以在各个容器内横向移动!
swing tweet media
中文
7
52
311
0
Zhongyu Pei
Zhongyu Pei@BrieflyX·
Really enjoy defcon ctf 29 finals and excellent challenges! We would all remember @oooverflow's effort to make this game awesome. I write a small retrospective blog (in Chinese) to memorize this last masterpiece from OOO. brieflyx.me/2021/dc29-memo/
English
0
5
46
0
flyyy
flyyy@f1yYY__·
Looking for a new job. Remote or in Chengdu. :)
English
2
1
8
0
swing
swing@bestswngs·
write exploit for CVE-2020-15257
English
5
1
21
0
Zhongyu Pei
Zhongyu Pei@BrieflyX·
@r3tr0sp3ct2019 Well I guess there is no 'oops=panic' parameter when booting kernel, thus the GFP as a non-fatal exception just makes the process die, instead of making kernel panic.
English
1
0
3
0
2019
2019@r3tr0spect2019·
@BrieflyX I think it is due to some compilation flag of this specific kernel image, which makes it process the fault without rebooting the system.
English
1
0
0
0
2019
2019@r3tr0spect2019·
Trigger a crash in kernel to leak the addresses...I am quite surprised by this technique...😂Since in my impression a crash in kernel always causes reboot...
Zhongyu Pei@BrieflyX

I solved spark in HITCON CTF 2020. The CONFIG_SLAB_FREELIST_HARDENED made it hard to exploit via a single UAF and costs much of my time. Eventually another out-of-bound bug in query algorithm saved me. Thanks to @david942j for 2 interesting kernel chals! github.com/BrieflyX/ctf-p…

English
1
0
8
0
Zhongyu Pei
Zhongyu Pei@BrieflyX·
I solved spark in HITCON CTF 2020. The CONFIG_SLAB_FREELIST_HARDENED made it hard to exploit via a single UAF and costs much of my time. Eventually another out-of-bound bug in query algorithm saved me. Thanks to @david942j for 2 interesting kernel chals! github.com/BrieflyX/ctf-p…
English
3
8
47
0
Zhongyu Pei
Zhongyu Pei@BrieflyX·
@david942j I vote for atoms since many teams solved it via unintended bugs. I would like to see how to trigger the real deadlock XD.
English
1
0
1
0
David Chiang
David Chiang@david942j·
Well no one votes for a writeup? Seems I can slack off this time 😛
English
1
0
1
0
POSIX
POSIX@po6ix·
Thanks for sending me many messages. To my honour, I became a member of @FlatNetworkOrg 🌐
English
11
1
79
0