Farzan Karimi

57 posts

Farzan Karimi banner
Farzan Karimi

Farzan Karimi

@jumpycastle

Black Hat + DEFCON Speaker | X-Google Red Team

Seattle, WA Katılım Haziran 2011
133 Takip Edilen576 Takipçiler
Farzan Karimi
Farzan Karimi@jumpycastle·
Dropping exploit code from my DEF CON 33 talk: Recursive Request Exploits (RRE) TL;DR: Trace API calls backward from a protected resource. If any upstream API is unauthenticated, you can bypass access to the whole chain. github.com/jumpycastle/rr…
English
2
0
5
286
Farzan Karimi
Farzan Karimi@jumpycastle·
@cptnsumo Great to know the content came through on the livestream. Phew! Thanks for supporting the talk
English
0
0
1
14
M
M@cptnsumo·
@jumpycastle super interesting talk at DEFCON today, nice job of rolling with the technical difficulties as well (stream showed slides the entire time).
English
1
0
1
44
Farzan Karimi
Farzan Karimi@jumpycastle·
I built Comment Crusader, a Burp Suite extension to uncover one of the more overlooked sources of data leaks in web apps: developer comments. Will be released this month. Enjoy a quick teaser.
English
1
0
3
296
Farzan Karimi
Farzan Karimi@jumpycastle·
@CryptoGangsta Funny you mention. I have an Odyssey G9 49” monitor and look at this tiny screen 99% of the time lol
English
0
0
1
26
Farzan Karimi
Farzan Karimi@jumpycastle·
Thrilled to share that my former Android Red Team has hit a major milestone with their first blog post! They detailed the exploitation of Android Binder (CVE-2023-20938), achieving root privileges on updated devices. Read more: androidoffsec.withgoogle.com/posts/attackin…
English
0
7
49
6.2K
Farzan Karimi
Farzan Karimi@jumpycastle·
I presented a lightning talk at Google Cloud Security Talks today focused on how our Android Red Team was able to attack modem chips to help drive important baseband mitigations in Android 12+ If you're interested in just the exploit demo, skip to 9:40 youtube.com/watch?v=BMbd2v…
YouTube video
YouTube
Farzan Karimi tweet media
English
0
4
37
2.7K
Farzan Karimi
Farzan Karimi@jumpycastle·
Excited to read "The Android Malware Handbook" by co-authors and colleagues Sebastian Porst and Salvador Mandujano on Android malware detection and analysis. It covers reversing, app static and dynamic analysis with hand on examples. Pre-order now! barnesandnoble.com/w/the-android-…
Farzan Karimi tweet media
English
0
0
5
551
Farzan Karimi
Farzan Karimi@jumpycastle·
Our Android Attack Tools team (an arm of Android Red Team) just published this article on continuous fuzzing. If your company is new to the fuzzing game and are looking for a recipe to build from, this is an excellent read. security.googleblog.com/2023/08/androi…
English
0
23
67
8.7K
Farzan Karimi
Farzan Karimi@jumpycastle·
Heard on a call today debating the pros and cons of fuzzing: "Fuzzing is just an expensive way to warm your living room in winter" Well said. It's both a pro and a con.
English
0
0
7
593
Farzan Karimi
Farzan Karimi@jumpycastle·
Honored to have presented with these world class researchers on the Android Red Team at #DEFCON and #BlackHat. Recordings should be out soon!
Farzan Karimi tweet media
English
1
2
12
645
Farzan Karimi
Farzan Karimi@jumpycastle·
If you saw our presentation on Red Teaming the Pixel modem at Black Hat and DEFCON this week, we referenced an article that directly captures the mitigations introduced in Android 14. Big steps forward for cellular security. security.googleblog.com/2023/08/androi…
English
1
18
53
6.9K
Farzan Karimi
Farzan Karimi@jumpycastle·
Our Black Hat and DEF CON talks are coming up this week. See you all there! Title: Over the Air, Under the Radar. Attack and Securing the Pixel Modem #blackhat : 3:20 pm Weds (Oceanside C) #defcon: 1:00 pm Fri (Track 2)
Farzan Karimi tweet media
English
0
4
18
2.1K
Farzan Karimi
Farzan Karimi@jumpycastle·
Come see our Android Red Team's review of the Pixel modem at DEF CON. We'll be demoing a full PoC of OTA RCE (all patched) Talk title: Over the Air, Under the Radar defcon.org/html/defcon-31…
English
0
1
6
748
Farzan Karimi
Farzan Karimi@jumpycastle·
Excited to announce our #Android #RedTeam was accepted to speak at both #BlackHat USA and #defcon31. We will be presenting "Over the Air, Under the Radar" covering attack surface we identified and mitigated on cellular comms Stop by if you're there! #over-the-air-under-the-radar-attacking-and-securing-the-pixel-modem-33009" target="_blank" rel="nofollow noopener">blackhat.com/us-23/briefing…
English
1
5
24
3.2K