Fikret Garipay

117 posts

Fikret Garipay banner
Fikret Garipay

Fikret Garipay

@erd0spy

Security Researcher

The Netherlands Katılım Kasım 2020
648 Takip Edilen142 Takipçiler
Fikret Garipay retweetledi
hardwear.io
hardwear.io@hardwear_io·
Dilithium, XMSS, SPHINCS+ —strong names, stronger math...but still human-made systems😬 At #hw_ioNL2025 @erd0spy showed a few carefully crafted voltage faults that can bypass checks and forge signatures without touching the core crypto 👉youtu.be/Qdk4KT8nWu0?si… #FaultInjection
YouTube video
YouTube
English
0
1
4
612
Fikret Garipay retweetledi
Black Hat
Black Hat@BlackHatEvents·
#BHUSA Briefings "Bypassing PQC Signature Verification with Fault Injection: Dilithium, XMSS, SPHINCS+" presents practical voltage fault injection attacks on three major PQC signature schemes.💻Demonstrating how to forge valid signatures without breaking the underlying cryptographic primitives >> bit.ly/4kwDGdr
English
0
1
6
4K
Fikret Garipay retweetledi
Specter
Specter@SpecterDev·
I've published a write-up on reversing and analyzing Samsung's H-Arx hypervisor architecture for Exynos devices, which has had a lot of changes in recent years and pretty interesting design. Hope you all enjoy :) dayzerosec.com/blog/2025/03/0…
English
3
111
498
51.8K
Fikret Garipay retweetledi
Raspberry Pi
Raspberry Pi@Raspberry_Pi·
Security through transparency: all chips have vulnerabilities, and most vendors' strategy is not to talk about them. In contrast, we aim to find and fix them. Read the results of our RP2350 Hacking Challenge: rpltd.co/rp2350-challen…
Raspberry Pi tweet media
English
15
198
909
107.3K
Fikret Garipay retweetledi
Raelize
Raelize@raelizecom·
The slides for the keynote our Cristofaro Mune(@pulsoid) has given at @h2hconference "False Injections: Tales of Physics, Misconceptions and Weird Machines" are now available here: raelize.com/upload/researc… Enjoy!
English
0
16
28
17.1K
Fikret Garipay retweetledi
mjos\dwez @m-jos.bsky.social
mjos\dwez @m-jos.bsky.social@mjos_crypto·
The new NIST IR 8547 "Transition to Post-Quantum Cryptography Standards" (draft out today) makes RSA, Elliptic Curve crypto disallowed by 2035. Hybrid (trad./pqc) solutions are accommodated by NIST. nvlpubs.nist.gov/nistpubs/ir/20…
mjos\dwez @m-jos.bsky.social tweet media
English
7
86
234
46.1K
POC_Crew
POC_Crew@POC_Crew·
[POC2024] SPEAKER UPDATE 1⃣5⃣ 👥 @binerdd & @kaanezder - "Fake it till you make it: Bypassing V8 Sandbox by constructing a fake Isolate" #POC2024
POC_Crew tweet media
English
4
19
76
20.9K
Fikret Garipay retweetledi
ic3qu33n
ic3qu33n@nikaroxanne·
Excited to share the first post in my new blog series with @LeviathanSec: UEFI is the new BIOS This blog series dives deep into UEFI RE/xdev. This first post is your UEFI intro. Check it out, hmu with feedback/q’s ✨ leviathansecurity.com/blog/uefi-is-t…
English
4
64
185
18.1K
Alisa Esage Шевченко
Alisa Esage Шевченко@alisaesage·
Happy Solstice! Time to celebrate Truth and Justice. I appreciate your support; and I want to let you try one of my value-packed & expensive commercial masterclasses: ☀️ Masterclass: Hacking Fuzzers for Smarter Bughunting (on-demand video) #fuzzing" target="_blank" rel="nofollow noopener">zerodayengineering.com/training/maste… This class will give you a core level grasp of modern evolutionary coverage-guided fuzzing as pro hackers use it. It goes fast from fuzzing essentials to advanced customization & examining how code coverage works on CPU assembly level, 4 hours hands-on video. Free access from 21st to 23rd June (access conditions below)
English
67
77
162
47.3K
Fikret Garipay
Fikret Garipay@erd0spy·
@raelizecom I wondered something. Which version of PicoScope 2000 series are you using in training? Or which version's buffer is sufficient to store the trace containing the glitches? 🙂
English
1
0
0
46
Raelize
Raelize@raelizecom·
Building effective Fault Injection setups, even when off-the-shelve tooling is used, is not always so trivial. You will experience how to do this to perform advanced Fault Injection attacks where you glitch more than just a check... There are still tickets avialable for our #TAoFI training at @_ringzer0's #BOOTSTRAP24 in Austin TX: ringzer0.training/trainings/the-…
Raelize@raelizecom

You will learn how to create complex Fault Injection setups in order to perform advanced Fault Injection attacks with commercially available tooling. We focus on tool agnostic knowledge and therefore this training is also useful if you different tooling yourself!

English
1
3
8
1.6K