piers
27 posts


@_piers2 Congrats Piers! Are you based in Hanoi or HCM? :)
Română

Thankfully I was still able to find something 😖
TrendAI Zero Day Initiative@thezdi
Validated! Dungdm (@_piers2) of Viettel Cyber Security used two bugs, include the ever risky race condition, to exploit #Oracle VirtualBox. As a round 3 winner, they receive $20,000 and 4 Master of Pwn points. #Pwn2Own #P2OVancouver
English

Only 7 days left...
Not a good bug, but we'll have to exploit it somehow.
TrendAI Zero Day Initiative@thezdi
Just one week left to register for #Pwn2Own Vancouver! We hope to see you there.
English

@y0ny0ns0n I was first relieved when there is no cve in the released advisories. Then I self-doubt, so i update and check again. And they fixed it silently 😅
English

@_piers2 @vv474172261 Hey, please can we talk quickly in dm? Not related to this bug but a previous one you found a while ago on another target
English

In Vmware Workstation 17.5.1, a bug was silently patched, I was going to use it for Pwn2Own but i think that I probably found the same bug that was used in TFC 2023... :(
@vv474172261, is there a way i can confirm this with you ?
English

@testanull @dfsec_com Congrats! I was looking forward to seeing you at starlabs.
English

Just want to announce that I’m officially a part of @dfsec_com today!
English
piers retweetledi

Slides of our latest talks during #GreHack23 and @codeblue_jp are now available on our website!
synacktiv.com/ressources
English

piers retweetledi

Will still try to do a blog post on my @CSAW_NYUTandon CTF challenge, NERV Center, but for now here's a thread explaining the key mechanics. I put a lot of work into the aesthetics, like this easter egg credit sequence (all ANSI colors+unicode text) that contains key hints:
English
piers retweetledi

got hard carried by amazing teammates at @vcslab
TrendAI Zero Day Initiative@thezdi
That's a wrap on #Pwn2Own Toronto 2023! We awarded $1,038,250 for 58 unique 0-days during the event. Congratulations to Team Viettel (@vcslab) for winning Master of Pwn with $180K and 30 points. We'll see you at Pwn2Own Automotive in Tokyo next January.
English
piers retweetledi
piers retweetledi

Success! Team Viettel was able to execute an OOB write against the Sonos Era 100. They earn $30,000 and 6 Master of Pwn points. #Pwn2Own


English
piers retweetledi

I have finally found my favorite blog post about bug bounties: devblogs.microsoft.com/oldnewthing/20…
English

Analysis of VirtualBox CVE-2023-21987 and CVE-2023-21991
Written by @xikhud
qriousec.github.io/post/vbox-pwn2…
English





