alvise

52 posts

alvise banner
alvise

alvise

@HBitmasks

PhD Student @vu5ec (Systems Security). Previously: decompilers @_revng, rockets @skyward_er

───○─ 🔊 Katılım Eylül 2018
250 Takip Edilen187 Takipçiler
alvise retweetledi
Mark Ermolov
Mark Ermolov@_markel___·
Hardware glitching masters have taken on Intel's microarchitecture - very, very cool! I'm so glad our work is contributing to research that was previously unimaginable. Research into hardware attacks on Intel processors has enormous potential... download.vusec.net/papers/microsp…
English
1
36
167
23.1K
alvise retweetledi
Erik van der Kouwe
Erik van der Kouwe@EKouwe·
Just a few days left to apply to our PhD and PostDoc positions available at @vu5ec. If you love low-level systems hacking and would you like to work at a top systems security research group in Amsterdam, consider applying: workingat.vu.nl/vacancies/phd-…
English
2
11
31
2.3K
alvise retweetledi
rev.ng
rev.ng@_revng·
😎 We’re going to REcon 2024! 😎 This will be the first talk in which we introduce the decompiler since the open source release. It will be very much an hands on talk. Don’t miss it. See you in June in Montreal! ⚜️🌹☘️ cfp.recon.cx/recon2024/talk…
English
0
8
39
3.8K
alvise
alvise@HBitmasks·
If you ever happen to look for Spectre gadgets manually and feel pain and loneliness, you should check github.com/vusec/inspectr… ... It's been a wild ride, but working with @SanWieb was the best thing ever :) Also, BHI is back baby
VUSec@vu5ec

Branch History Injection (BHI) is back! Disclosing Native BHI, bypassing deployed Spectre-v2/BHI mitigations (e.g., eBPF=off) to leak arbitrary kernel/host memory (e.g., root password hash below). Joint work by @SanWieb @HBitmasks @herbertbos @c_giuffrida: vusec.net/projects/nativ…

English
0
5
13
2K
alvise retweetledi
VUSec
VUSec@vu5ec·
Disclosing #SLAM, aka how to combine Spectre and Intel LAM (& co.) to leak kernel memory on future CPUs (demo below). Thousands of exploitable "unmasked" (or pointer chasing) gadgets in the Linux kernel. Joint work by @MatheHertogh @SanWieb @c_giuffrida: vusec.net/projects/slam
GIF
English
1
58
180
22.9K
alvise retweetledi
Emanuele Vannacci
Emanuele Vannacci@vanema94·
I'm thrilled to announce that our paper "Speculation@Fault" @USENIXSecurity is online! Read about how we automatically find information leakages arising from CPU exceptions by fuzzing against speculative contracts.
Jana Hofmann@jana_tweets_cs

Now that the embargo is finally lifted🥳: I'm excited to share details about our most recent work (appearing at USENIX this week) on modeling and testing microarchitectural information leakage of CPU exceptions (think Meltdown 👻and alike).

English
1
6
19
2.9K
alvise retweetledi
Stefano Zanero
Stefano Zanero@raistolo·
I am extremely happy about this paper, which is the brainchild of my PhD student @__L4w__ and my colleague @JinBlackx. BINO addresses the irksome problem of identifying inlined functions (specifically from C++ template classes) in binaries. authors.elsevier.com/c/1hD5Kc43v0Znn
English
2
15
81
13.1K
alvise retweetledi
Djordje Todorovic
Djordje Todorovic@djtodoro·
Debug Location coverage for the variables in the optimized binaries compiled with the newest release of LLVM look nice. A bit longer post is at djolertrk.github.io/2023/05/14/Deb…. We started from 45%, and now we are at 71%, nice! @llvmorg
Djordje Todorovic tweet media
English
0
4
38
5.8K
alvise retweetledi
NDSS Symposium
NDSS Symposium@NDSSSymposium·
Should we lose hope already on Rowhammer attacks? Andrea Di Dio from Vrije Universiteit Amsterdam is showing us at #NDSS23 that it is feasible to devise a software-based design to mitigate ECC-aware Rowhammer attacks.
NDSS Symposium tweet media
English
1
4
13
2.5K
alvise retweetledi
Linuxopsys
Linuxopsys@linuxopsys·
The Linux kernel, this is really cute!
Linuxopsys tweet media
English
10
423
1.7K
113K
alvise retweetledi
Filippo Cremonese
Filippo Cremonese@fcremo·
Easily the highest impact bug I found (yet)
Zellic@zellic_io

We audited SPL-Token-2022 for the @SolanaFndn. It's an update for the SPL-Token program. In our review, we found an inflationary bug that would've allowed infinite minting of tokens for free. The audit was pre-launch. The code was not enabled, so no funds were at risk. 👇🧵

English
0
1
14
0
alvise
alvise@HBitmasks·
Great talk by @fcgorter about his project DangZero at @acm_ccs! Featuring also a nice little meme about @gregkh approving the work :) gg
alvise tweet media
English
0
5
19
0