Aviad
3.7K posts

Aviad
@_0xffd
''To fly as fast as thought, you must begin by knowing you've already arrived'' Spinning records for fun and containers for pain Opinions are my own. UwU
Israel Katılım Nisan 2011
491 Takip Edilen262 Takipçiler

@_0xffd The screenshot says LibFuzzer but yes there’s also support for AFL++
English

It’s coming soon :) 🐉 working on last touch ups before going open source.
Context: I wrote a ‘build system’/fuzzing framework that lets you compile, link, analyze and profile your harness/mutators for Apache fuzzing.
I’ll post more details when the time comes.


faulty *ptrrr@0x_shaq
grok generated a teaser for you
English

@yo_yo_yo_jbo Been there. Never trusting this mf again. Stay strong.
It’s great for frontend design/React apps though. So far it didn’t let me down, not even once in this field.
x.com/0x_shaq/status…
faulty *ptrrr@0x_shaq
you owe me money, not apology
English

@cherkaskyb הייתי ממליץ לעבוד מעל OTEL ולייצר לעצמך קולקטורים וכו..
מה שלוקח זמן...וקסטומיזציה...
ומתוך זה אנחנו באודיגוס (odigos.io) עושים את הכל אוטומטית ועם eBPF :) ויש גם גירסאת open source שבגדול מקימה לך הכל לבד ושולחת את המידע לאן שתרצה. חינם כמובן ;) דבר איתי לפרטים
עברית
Aviad retweetledi

@thedawgyg but then what if exploitation is not trivial? ie requires special heap grooming etc
So even if the exploit devel is difficult or non-trivial, it doesn't cancel the vuln. What happens in these cases?
English

@_0xffd it depends on the target. ASan is enough for some. Others you have to show a poc, others you have to have an actual exploit (for like google).
English

4 High / Critical vulns reported in the last couple of days for my target(s). Have 7 more unique crashes of lower severity (mediums, or maybe low end of high if lucky) so gonna give them time to look at the others before submitting more to avoid overwhelming them. but the fuzzing is going exceptionally well this week <3 #bugbounty #bugboutnytips #fuzzing #hacking #0day #hunting0days
English

@thedawgyg @Virdoex_hunter then I'd add that I'd be happy to read about your work and the infra below it!
English

@Virdoex_hunter i am using AFL, with custom wrappers written in C for my targets, with custom dictionaries and setup. currently using a macbook m4 max, macbook m1 pro, and an x86_64 gaming desktop in a swarm working together
English

So as some noticed, I am now doing alot of fuzzing. (11 0days found in the last 8 days between 3 major tools/libraries). Currently working on getting a UAF RCE triaged now. Would people find it helpful/useful if I were to blog about how I found them? #hacking #hacker #bugbounty
English

@intrnationalman @ThePrimeagen Building bridges is also key. You need to create genuine connections and relationships with others that can advocate for and talk about your professional skill and work. This extends beyond technical skill, particular for Staff or higher. Trust is everything.
English

Hi! I’m a Staff Engineer at Riot Games. This is hilariously incorrect.
Antonio Sarosi@antoniosarosi
Game programmers will do anything but write code
English











