Aobo Wang

37 posts

Aobo Wang

Aobo Wang

@M4x_1997

Katılım Temmuz 2018
810 Takip Edilen372 Takipçiler
Aobo Wang
Aobo Wang@M4x_1997·
@3072_l 这个基本是纯静态的,中间我只提供了一些他要的调试信息
中文
0
0
1
160
tgtg
tgtg@3072_l·
@M4x_1997 纯静态吗?感觉让agent自己用kd调试堆很费劲啊😰
中文
1
0
1
285
Aobo Wang
Aobo Wang@M4x_1997·
I miss the old days when I had to learn, reverse, PoC, and exploit vulnerabilities myself, instead of watching AI generate working exploits while I'm still learning the basics. Though those "old days" were only a few years ago.😧
Aobo Wang tweet media
English
1
0
9
572
Aobo Wang
Aobo Wang@M4x_1997·
Can't agree more. Same situation here. Last week LLM ran for many hours, claiming ~99.9% success rate for an exploit but ultimately gave it up. I had to manually root-cause and fix it quickly. The highlight is that it did find a vulnerability I likely would have missed, mainly because I'm not familiar with the internals. However, it also overlooked some deeper vulnerabilities until I prompted "what if...". IMO, LLMs can indeed help with bug hunting, but don't fully rely on them, especially for exploits, at least, for now.
Jonathan Bar Or (JBO) 🇮🇱🇺🇸🇺🇦@yo_yo_yo_jbo

And to summarize - I wasted roughly 15 hours of my life and tons of tokens to eventually give up, reverse engineer manually and find the cause of what I was looking for in like 1 hour. LLMs are great but are no replacement for real, hardcore research.

English
0
2
16
11.3K
Aobo Wang
Aobo Wang@M4x_1997·
@hyprdude However, most of my hunting was done on the Windows platform. I think they shared some codebase, that's why I saw similar patterns. Since Windows has non-admin users by design—so almost all my reports were triaged as valid.😂 (2/2)
English
0
0
1
93
Aobo Wang
Aobo Wang@M4x_1997·
@hyprdude Fun fact: I also reported 18+ bugs to MediaTek earlier this year, which have resulted in 7 CVEs (a few are still pending and some collided with yours, I suspect, as I noticed similar patterns in your blog). (1/2)
English
1
0
2
145
hypr
hypr@hyprdude·
We're back, baby! This time with 19+ bugs I reported to MediaTek over the past year + PoCs for each one! I'll also tell you a *fun* story about MediaTek's "creative" impact assessment process. They earned a spot on the naughty list this year :) Check it ⬇️
English
8
29
183
26.9K
Aobo Wang
Aobo Wang@M4x_1997·
@0gtweet It's a parsing artifact. Explorer uses ::{GUID} paths, but some file APIs misinterpret the first : as a drive letter. This forces Windows to auto-generate a "current directory" var (=::) for this non-existent drive, which then gets inherited by all child processes.
English
1
0
20
1.3K
Grzegorz Tworek
Grzegorz Tworek@0gtweet·
Can anyone explain the mystery behind "=::=::\"? It really exists in the PEB -> ProcessParameters -> Environment, is returned by GetEnvironmentStringsW() but is not shown by the "SET" command. And I could see it many times in different Windows versions.🤔
Grzegorz Tworek tweet media
English
6
7
93
26.7K
Watch This Space
Watch This Space@wtsdev·
Just learned from Apple I was not the first one to report that Wi-Fi bug I found. Looking at the security notes, there were a few others. @M4x_1997, @theevilbit, @_r3ggi: which one of you got their report in before I did, lol? Or maybe it was the anonymous researcher.
English
4
0
4
1.1K
Aobo Wang retweetledi
flyyy
flyyy@f1yYY__·
I've invited some friends of Tea Deliverers and @Water_Paddler to create some interesting challenges for AliyunCTF. We also offer great bonuses: 1st: about 21000$ 2nd: about 11000$ 3rd: about 7000$ Time: 4.21 13:00 UTC- 4.23 13:00 UTC. Come join us! 🥳🥳 ays.cn/AGWz
English
2
2
45
19.4K
Aobo Wang retweetledi
Real World CTF
Real World CTF@RealWorldCTF·
2022 The 4th Real World CTF is about to start. Only one round Online Jeopardy will directly decide the championship this year. 21:00,21th Jan. ~ 21:00,23th Jan. 2022 (GMT+8) WE WANT YOU! Follow us on CTFTime:ctftime.org/event/1507, or official website:realworldctf.com
Real World CTF tweet media
English
0
8
47
0
Aobo Wang retweetledi
Real World CTF
Real World CTF@RealWorldCTF·
There may be some uncertainty both in hacking & living. But just like Team @Sauercl0ud just showed, we will finally make it!✊#realworldctf
Real World CTF tweet media
English
1
14
86
0