Georgios Baltas

56 posts

Georgios Baltas

Georgios Baltas

@gebaltas

All things systems security. Opinions are my own.

Seattle, WA Katılım Ocak 2016
76 Takip Edilen619 Takipçiler
Georgios Baltas retweetledi
Microsoft Security Response Center
Microsoft Security Response Center@msftsecresponse·
File system redirection has long been a tool for attackers seeking privilege escalation. RedirectionGuard, a new Windows mitigation, is designed to block malicious junction-based redirection by default, strengthening system security. Key Features of RedirectionGuard: •Blocks junction traversal only when followed by an opted-in process and when created by a non-admin user. •Stores privilege metadata in an admin-only alternate data stream to verify junction trustworthiness. •Already enabled in Windows Insider builds for User Profile Service, AppX Deployment Service, and Installer Service, historically among the most vulnerable components. Learn more in our new blog by Mike Macelletti (@pintostart), Senior Security Researcher, Microsoft: msft.it/6018SIil0 Many thanks to Georgios Baltas (@gebaltas) and James Forshaw (@tiraniddo) for their contributions.
Microsoft Security Response Center tweet media
English
4
26
61
10.4K
Georgios Baltas retweetledi
Axel Souchet
Axel Souchet@0vercl0k·
Andrew Calvano and I wrote a proof of concept exploit targeting the Meta Quest2 VR headset to understand how to secure it better as part of Meta's Native Assurance team. Go check it out 🔥🔥! "Meta Quest 2: Defense through offense" engineering.fb.com/2023/09/12/sec…
English
1
7
22
1.9K
Georgios Baltas retweetledi
Axel Souchet
Axel Souchet@0vercl0k·
Zenith is an (unreliable) exploit I wrote to compromise the TP-Link AC1750 Smart Wi-Fi Router for Pwn2Own Austin 2021. It remotely exploits an integer overflow in the NetUSB kernel driver that results in a heap-buffer overflow 🔥 github.com/0vercl0k/zenith
GIF
English
8
106
334
0
Georgios Baltas
Georgios Baltas@gebaltas·
Our day-to-day consists of in-depth security reviews, building & running static/dynamic analysis tools and mitigating classes of bugs. People can pick their focus area based on their interests.
English
1
0
0
0
Georgios Baltas
Georgios Baltas@gebaltas·
It's been over a year since I've joined FB's native product security. People might not realize, but we have a lot of native code to work on, in all types of software; from firmware to mobile apps.
English
1
0
3
0
Georgios Baltas retweetledi
James Forshaw
James Forshaw@tiraniddo·
It's happening!!! Well probably😁
James Forshaw tweet media
English
5
11
83
0
Georgios Baltas
Georgios Baltas@gebaltas·
@halvarflake It seems to me that the level of security (or lack thereof) is already baked into the price of software. The security community can facilitate more informed decisions, but ultimately consumers decide what they pay for.
English
0
0
1
0
Halvar Flake
Halvar Flake@halvarflake·
For a single severe bug and a 90 day fix, this means "75% securetime". Now establish that customers paid for 99% securetime, and get a refund for any percentage below that. For free-but-monetized software like Android, they get a corresponding cut of the generated revenue.
English
8
4
16
0
Halvar Flake
Halvar Flake@halvarflake·
Ill-thought-out idea to start the week - this time on regulating software providers to improve security: Establish the metric "securetime", equivalent to "uptime": The number of days in the past calendar year that the software had no severe vulnerabilities known to the vendor.
English
8
21
48
0
Georgios Baltas retweetledi
Axel Souchet
Axel Souchet@0vercl0k·
If you were to draw on a canvas the virtual address space of a 64-bit Windows process running on 19H1 this is what you would see 🧐🧐
Axel Souchet tweet mediaAxel Souchet tweet media
English
3
21
118
0
0x5A1F
0x5A1F@Saif_Sherei·
Today was sadly my last day at MSRC @msftsecresponse , it was truly a pleasure and honour to be part of this epic team, I learnt so much from everyone, and Thank you all for being a part of my journey.
English
16
2
102
0
Georgios Baltas
Georgios Baltas@gebaltas·
Today is my first day at @Facebook's Product Security team, where I will be working on native code vulnerability research and exploit mitigation
English
1
1
17
0
Georgios Baltas
Georgios Baltas@gebaltas·
@guhe120 FWIW report quality is always determined by engineers and we are incentivized to reward highly actionable reports. It is not influenced by the potential payout.
English
1
0
1
0
Yuki Chen
Yuki Chen@guhe120·
The same situation, many cases closed without any conversation, and dirty reasons (e.g. saying your reports are low quality) to refuse to pay bounty
English
6
2
22
0
Vasileios Kemerlis
Vasileios Kemerlis@vkemerlis·
I'm deeply honored for being awarded a @GreekDiasporaFP Fellowship by @IIEglobal, @FulbrightGreece, and @SNForg! I look forward to visiting again @AUEB, my alma mater, and working with George Polyzos and George Xylomenos on IoT security! #BrownResearch #BrownCS #AUEB #MMlab
Brown CS@BrownCSDept

This year, only 3 of the 36 @GreekDiasporaFP Fellowships were in CS or CS education, and one of them has gone to @BrownCSDept Prof. @vkemerlis for IoT software hardening. He shares it w. George Polyzos of @AUEB. bit.ly/30B5W7Z

English
16
0
69
0