kost

11.9K posts

kost banner
kost

kost

@k0st

Security/Hack. FLOSS security software contributor.

Katılım Mayıs 2008
3.1K Takip Edilen1.7K Takipçiler
kost retweetledi
OtterSec
OtterSec@osec_io·
We recently achieved guest-to-host escape by exploiting a QEMU 0day. We’ll share details on a new technique leveraging the latest glibc allocator behavior and what we believe is a novel QEMU-specific heap spray/RIP-control primitive. Writeup coming next week.
English
36
189
1.5K
71.2K
kost retweetledi
Clandestine
Clandestine@akaclandestine·
GitHub - cisagov/decider: A web application that assists network defenders, analysts, and researchers in the process of mapping adversary behaviors to the MITRE ATT&CK® framework. github.com/cisagov/decider
English
0
74
283
14.4K
kost retweetledi
JS0N Haddix
JS0N Haddix@Jhaddix·
A 13 year old coded a botnet control framework that utilizes pastebin and github for control of hosts in red teaming… This makes the hacker in me so hopeful. Check out pastebomb when it’s dropped!
JS0N Haddix tweet media
English
31
239
2.5K
223.4K
kost retweetledi
Flipper Devices
Flipper Devices@flipper_net·
Btw, you don't need a Flipper Zero to "hack" dumb radio protocols. The piece of wire is enough. Check out how to receive and decode 433MHz radio signal just with a PC sound card.
English
42
922
4.2K
441.3K
kost
kost@k0st·
@retBandit @IBM Good luck and hope both IBM and you will grow!
English
0
0
1
123
Chris Thompson
Chris Thompson@retBandit·
I’m happy to share that I’m starting a new position as Global Head of X-Force Red @IBM! I'm excited to lead X-Force Red onto the next phase of our journey, incorporating tradecraft from and lessons learned building one of the world's top red teams; X-Force Adversary Services. Thank you to @angus_tx for getting us to where we are today and best of luck on your next adventures!
English
24
26
248
31.6K
kost
kost@k0st·
@jduck Covered all in presentation, but in short: CPU with Intel CET/AMD Shadow stack support, Linux kernel 6.6+, glibc 2.39+, ELF binary compiled with x86 feature: SHSTK (all 64 bit!). Yep, it needs recompilation, but some distros (like Ubuntu) already correctly compiled some binaries.
English
0
0
1
147
Joshua J. Drake
Joshua J. Drake@jduck·
@k0st Any further details? Doesn't this require specific hardware and recompiling everything?
English
1
0
0
439