h0ps

165 posts

h0ps

h0ps

@_h0p5

Pwn & Rev

Katılım Nisan 2020
1.1K Takip Edilen108 Takipçiler
h0ps retweetledi
Alex Kuleshov
Alex Kuleshov@0xAX·
Took me almost a month, but it’s finally done. I completely rewrote the first chapter of linux-insides about the Linux kernel initialization process. Now it should be aligned with modern kernels (up to master). github.com/0xAX/linux-ins…
English
11
221
1.3K
50.1K
h0ps retweetledi
Joe Desimone
Joe Desimone@dez_·
We open sourced the tool used to detect the Axios supply chain compromise! I built it Friday after a red eye home from RSAC. Also, wrote up the full story, including the hectic moments after that first critical alert github.com/elastic/supply…
English
33
253
1.3K
132.9K
h0ps retweetledi
SinSinology
SinSinology@SinSinology·
day 1: exploited by LiteLLM day 2: exploited by vim day 3: exploited by emacs day 4: exploited by axios day 5: echo "hello world" exploited me The threat model is now "software"
SinSinology tweet media
English
14
104
887
30.8K
h0ps
h0ps@_h0p5·
@RenwaX23 @kasturixbm5 This is not universally true. KalmarCTF last weekend had hard, well thought out challenges that could still be solved by AI.
English
0
0
0
25
Renwa
Renwa@RenwaX23·
@kasturixbm5 A CTF challenge is not worth playing nor a good quality if it's solved by AI, using firewalls and other boring stuff won't get you anywhere. All these years we just saw refurbished and low quality challenges it's just AI exposed them. I blame authors for any CTF slop.
English
1
0
4
560
h0ps retweetledi
Seth Jenkins
Seth Jenkins@__sethJenkins·
Just derestricted a now-fixed kernel bug in Pixel 10. I think this ranks as the most easily exploited kernel bug of all time😬 Thanks to @tehjh for collab'ing on this driver and full credits for noticing this bug in the first 5 minutes of auditing😂 project-zero.issues.chromium.org/issues/4634382…
English
5
44
187
16.6K
h0ps retweetledi
lcamtuf
lcamtuf@lcamtuf·
This is pretty darn impressive, and also a good counterargument to "nothing ever changes" criticisms of infosec: blog.calif.io/p/a-race-withi…
English
2
18
110
14.6K
h0ps retweetledi
Leo
Leo@leo_s0mething·
With a slight delay of three months, me and @bitfriends_ finally found the time to finish our writeup for Still Not Malloc from LakeCTF Quals. Shout out to @LakeCtf organizers for the cool pwn. See you soon in Lousanne! leo1.cc/posts/writeups…
English
0
7
27
1.1K
h0ps retweetledi
siunam
siunam@siunam321·
I started playing CTFs in 2022, and LLMs definitely changed the **competitive** CTF scene a lot, especially since mid-2025. I also started using LLMs in late 2025. Yes, those models did one-shot many challenges, but what's the fun of slopping them? I learned absolutely nothing 🥲
siunam tweet mediasiunam tweet media
English
21
97
623
103.4K
Faith 🇧🇩🇦🇺
Faith 🇧🇩🇦🇺@farazsth98·
Finally, here is the blog post containing all the details about how I wrote this PoC: faith2dxy.xyz/2025-12-24/cve… The ~4-5 millisecond race window was more than enough to trigger the vulnerability, but is it enough for a full exploit? Or do I need to extend it? We'll see 😉
English
1
6
33
1.5K
Faith 🇧🇩🇦🇺
Faith 🇧🇩🇦🇺@farazsth98·
In my previous post about CVE-2025-38352, I used a kernel patch to extend the race window to help trigger the vulnerability. I've since improved it to work without the kernel patch. @hackyzh 👀 I also wrote a "Part 2" of the blog post. It's linked at the end of this thread!
Faith 🇧🇩🇦🇺 tweet media
Faith 🇧🇩🇦🇺@farazsth98

After reading @streypaws blog post on CVE-2025-38352, I ended up writing my own PoC for it. I also wrote a blog post on my approach to analyzing and recreating the PoC. Hopefully it is useful to others! See link in the reply tweet below!

English
3
23
92
15K
h0ps retweetledi
ARESx
ARESx@ARESxCTF·
For the weekend ARESx had the honor of attending mimic ctf 2025 Big thank you to @XCTF_League for organizing the event 🎖🎖 Hope to see you all next year!
ARESx tweet mediaARESx tweet mediaARESx tweet mediaARESx tweet media
English
0
5
29
1.6K
Erebius
Erebius@ErebiusWhite·
Things to know to build a robot: - Soldering - CAD - Python - C++ Anything else?
English
227
53
1.2K
52.4K
h0ps retweetledi
ARESx
ARESx@ARESxCTF·
We are proud to announce, ARESx placed 3rd on m0leCon CTF!!! 🏆🇮🇹 Thank you for hosting! @pwnthem0le Looking forward to see everyone in Turin!! #pwnthem0le
ARESx tweet mediaARESx tweet media
English
0
9
39
5.3K