Ben

189 posts

Ben

Ben

@XploitBengineer

Android Vulnerability Researcher, Pwn2Own 202{3, 5}

planet earth Katılım Nisan 2016
618 Takip Edilen1.1K Takipçiler
Ben
Ben@XploitBengineer·
@halvarflake LLMs are fantastic at finding useless bugs
English
0
0
1
100
Halvar Flake
Halvar Flake@halvarflake·
And I mean, one of my personality flaws is that I absolutely *love* shitty bugs, but each one of these bugs has remained there for a reason - people looked at it, decided it's too painful or impossible to use, and moved on.
English
5
0
39
2.3K
Halvar Flake
Halvar Flake@halvarflake·
I am doing this LLM vuln discovery wrong I fear. I have found a few genuine memory corruptions reachable from the network in software I care about, but so far one is a multi-free with no allocation in-between on modern glibc, and the other is overwriting a function pointer ...
English
6
6
59
9.9K
Ben
Ben@XploitBengineer·
Had a blast in Seoul with @munmap speaking at Zer0Con Huge thanks to @POC_Crew and the other attendees for being so welcoming. Definitely a great event for my first speaking gig
English
3
1
40
2.4K
Ben
Ben@XploitBengineer·
@0vercl0k Cheers mate :)
English
0
0
1
120
Ben
Ben@XploitBengineer·
@0x_shaq Or, hear me out here. Project Xoero. Pronounced Project Zero
English
0
0
0
44
faulty *ptrrr
faulty *ptrrr@0x_shaq·
Final offer: It’ll be Project XORO, pronounced as “Project Zoro”
faulty *ptrrr tweet media
English
3
0
25
2K
faulty *ptrrr
faulty *ptrrr@0x_shaq·
nobody: android drivers handling the smallest task:
faulty *ptrrr tweet media
English
11
13
338
21.1K
Ben
Ben@XploitBengineer·
@boredpentester I have not had much success at all with LLMs for kernel exploitation either. I'm not sure what we're doing wrong 😬
English
0
0
2
237
Josh
Josh@boredpentester·
VuLneRbiLitY reSeaRcH iS cOoKed
Josh tweet media
English
1
1
26
2.6K
Ben
Ben@XploitBengineer·
@iBSparkes Unfortunately it's going the opposite way. Samsung has preemptively rolled out locked bootloaders globally as of ~August 2025 - apparently due to the new "Radio Equipment Directive"
English
0
0
0
403
sparkey
sparkey@iBSparkes·
I think — genuinely — the only hope for jailbreaking at the point is if the EU forces manufacturers to have unlocked bootloaders. It is deeply fucked up to me that you can buy a $1000 computer and are not allowed to install your own software on it.
sparkey@iBSparkes

“Semi-jailbreak” makes me immensely sad

English
6
10
193
82.6K
Zhiyun Qian
Zhiyun Qian@pkqzy888·
Professors have approximately zero free time. And yet. 👀 Turns out LLMs as super assistants make exploit dev manageable and fun again. Pixel 10 root exploit (LPE) with an N-day. No public exploits exist for this thing. Maybe I should teach a course on this. #LLM #ExploitDev
Zhiyun Qian tweet mediaZhiyun Qian tweet media
English
8
11
155
13.9K
Ben retweetledi
rev.ng
rev.ng@_revng·
🎥 How does rev.ng detect jump table? In this presentation Ale explains how the rev.ng decompiler detects jump tables and, more in general, how it devirtualizes indirect jumps.
English
1
4
25
2.1K
Ben
Ben@XploitBengineer·
@SinSinology @InterruptLabs It's a mystery, for sure. Looks like you had a great time in Japan btw, solid work 💪🏻
English
1
0
1
105