Puzzor

396 posts

Puzzor

Puzzor

@Puzzorsj

PhD/Fuzzing/USENIX Security/MVSR 2020/Pwn2Own 2020/MSRC Top100 2016,2017/GeekPwn 2017

Katılım Ağustos 2012
624 Takip Edilen995 Takipçiler
Puzzor retweetledi
Thuan Pham
Thuan Pham@thuanpv_·
Can't agree more: "A comparison to other fuzzers may be conducted optionally if the authors wish to establish the new fuzzer as the new state-of-the-art. However, note that the observed improvements may be largely due to design and engineering differences (e.g.,Honggfuzz vs AFL)"
Marcel Böhme👨‍🔬@mboehme_

Good news! Our ICSE'22 paper "On the Reliability of Coverage-Based Fuzzer Benchmarking" is freely available as Gold Open Access. Check out our discussions and recommendations in Sections 6 & 7 📝 mboehme.github.io/paper/ICSE22.p… 👩‍💻 doi.org/10.5281/zenodo… by/with @lszekeres & @metzmanj

English
1
4
14
0
zenhumany
zenhumany@zenhumany·
@Puzzorsj 企业里有大量的代码需要fuzzing,完成手工编写testcase,fuzzer driver人手不够;目前这些都有一些自动化的初步解决方案,但是都是针对简单的情况,对于一些复杂的场景,要完全做到自动化还是很有挑战的,值得投入人力去做。
中文
2
0
1
0
zenhumany
zenhumany@zenhumany·
年底了,发一个蔚来汽车的安全岗位。 欢迎投简历,可年后入职。 base 上海或者北京。 高级工程师或专家(fuzzing工具与平台开发) nio.jobs.feishu.cn/referral/m/pos…
zenhumany tweet media
中文
1
2
5
0
Puzzor
Puzzor@Puzzorsj·
I appreciate this work very much. Especially it points out the deterministic problem. IMHO, most of the Evaluations in existing works ignore this, and I even consider this might be a "trick" to get better performance
Abhishek Arya@infernosec

Results from @Google #FuzzBench: ​​An Open Fuzzer Benchmarking Platform and Service is now published in ESEC/FSE’21 (thanks to the authors - @metzmanj, @lszekeres, @lsim99, @sprabery and me :). Check it out here - research.google/pubs/pub50600/

English
0
0
1
0
Thuan Pham
Thuan Pham@thuanpv_·
Roberto @rnatella and I are going to present #ProFuzzBench - our Benchmark for Stateful Protocol Fuzzing in the tool demonstrations track @issta_conf. Join us in two different time bands to discuss the opportunities and challenges in #fuzzing network protocol implementations!
English
1
1
13
0
Alisa Esage Шевченко
Official: I won Pwn2Own competition in the Virtualisation category. It’s an essential milestone in a professional hacker’s career, and a major goal personally. I am super hyped! And relieved Details of the exploit that I developed are now under embargo of responsible disclosure
English
54
106
1.9K
0
Puzzor retweetledi
Ivan Fratric 💙💛
Ivan Fratric 💙💛@ifsecure·
Security researchers messaging each other after today
GIF
English
28
452
2.2K
0
Puzzor
Puzzor@Puzzorsj·
@_jsoo_ working well for me😂
English
0
0
0
0
Pedro Ribeiro
Pedro Ribeiro@pedrib1337·
Western Digital pulled a trick on us and dropped a major OS 5 release for their NAS 5 days before Pwn2Own. Our RCE still works in the older, STILL SUPPORTED OS 3 release, and affects LOTS of other @westerndigital devices too. @RabbitPro and I should:
English
3
5
11
0
Puzzor
Puzzor@Puzzorsj·
we are the first and the last team to demonstrate the exploit. Nice work & team. btw, our bug for WD NAS is dead before the match, or we can try to get master of pwn😂 anyway, not bad, thank you all guys🥰
TrendAI Zero Day Initiative@thezdi

Confirmed! The team of @starlabs_sg, @hi_im_d4rkn3ss, @Puzzorsj & @c3xp1r used a race condition and an OOB read to get root access on the Synology NAS. They close out the contest by earning $20,000 and 2 Master of Pwn points.

English
0
1
19
0
Puzzor
Puzzor@Puzzorsj·
MSRC sent an email saying that they will provide a 1-year license for Visual Studio Enterprise subscription for those 2020 MSRC Most Valuable Security Researchers. Very nice of them, thanks :) @msftsecresponse
English
0
0
13
0
Marcel Böhme👨‍🔬
Marcel Böhme👨‍🔬@mboehme_·
Coverage of the call graph (with the root on top) when #fuzzing freetype2 for 24 hours with AFL and Honggfuzz.
GIF
English
3
2
25
0
Marcel Böhme👨‍🔬
Marcel Böhme👨‍🔬@mboehme_·
Fuzzer coverage over time (#Honggfuzz vs #AFL on Freetype2 in 24h). Call graph. Green nodes are covered in all 20 trials. Orange/yellow nodes are covered in at least one trial. Grey nodes are not covered in any trial. Data from @stephanlipp. Inspired by @gamozolabs cookie_dough.
GIF
English
2
29
133
0
Puzzor retweetledi
Mathias Payer
Mathias Payer@gannimo·
CCS delivers again: three CCS second round papers, all hard rejected with very harsh reviews. All three had person years of improvements added to their previous submissions. I'm not sure what to do with CCS anymore.
English
7
3
46
0
Puzzor
Puzzor@Puzzorsj·
cool
Puzzor tweet media
English
1
2
37
0
Puzzor
Puzzor@Puzzorsj·
@_jsoo_ 哈哈哈哈好!等我去喝酒😋😋
日本語
0
0
1
0