liba2k

69 posts

liba2k

liba2k

@liba2k

Katılım Nisan 2020
60 Takip Edilen322 Takipçiler
liba2k retweetledi
Caleb Fenton
Caleb Fenton@caleb_fenton·
One of our security researchers demonstrated a local root shell on Linux using a page-cache poisoning primitive in AF_RXRPC’s RxGK path. We call it DirtyCBC: a sibling to DirtyFrag in the broader CopyFail / DirtyFrag / Fragnesia family. The issue is fixed on mainline. The candidate path was surfaced through Delphos’s agentic analysis workflow, then manually verified and exploited end to end. AES-256 was not broken. It just wasn’t the boundary that mattered. RxGK decrypted data in place before authentication completed. Under the right conditions, that write could land in the page cache. The HMAC check still failed and the connection was aborted, but the page-cache mutation had already happened. Two RESPONSE packets were enough to place a tiny ELF into the cached first page of a readable SUID-root binary. The file on disk stayed unchanged. The next exec produced a root shell. Full writeup and PoC on the Delphos Labs GitHub. delphoslabs.com/blog/36142374-…
Caleb Fenton tweet mediaCaleb Fenton tweet media
English
5
68
296
60.3K
liba2k
liba2k@liba2k·
We’re hiring 🚀 Security Researcher & Software Engineer @ Delphos Labs Build AI-powered systems for reverse engineering — tools where AI understands software, automates binary analysis, and scales how we reason about code. 🔗 jobs.ashbyhq.com/delphos-labs/a… #securityresearch #hiring
English
0
0
0
84
liba2k retweetledi
Delphos Labs
Delphos Labs@DelphosLabs·
XZ backdoor (liblzma.so.5.6.1) fully exposed in minutes with Delphos Labs. Black-box binaries? No more. Traditional tools would still be unpacking. That’s software, verified.
Caleb Fenton@caleb_fenton

Black-box binaries? Over. We ran the xz-utils backdoor (liblzma.so.5.6.1) through our AI and it lit up: runtime JMP patching, custom byte-table crypto, encrypted IPC—caught in minutes. Full teardown 👉 delphoslabs.com/uploads/f382eb… What would you audit next? #xzbackdoor #ReverseEngineering

English
0
3
5
529
liba2k retweetledi
Caleb Fenton
Caleb Fenton@caleb_fenton·
Binary highlight: “Cyberpunk 7777 / QubePi” ELF. Text-menu game with hard-coded Postgres creds. Every login/chat/coord sent in clear on 5432—no TLS, no sanitization. Delphos auto-exposed the creds & flow in minutes. Sample: delphoslabs.com/uploads/26cc38… #ReverseEngineering
Caleb Fenton tweet media
English
1
3
8
453
liba2k
liba2k@liba2k·
At @DelphosLabs, we're building tools to automate reverse engineering, no source code required. Help shape what we build next 👇 docs.google.com/forms/d/e/1FAI… It takes just a few minutes. Anonymous unless you opt in. Thanks for your input! 🙏
English
0
0
2
68
liba2k retweetledi
Delphos Labs
Delphos Labs@DelphosLabs·
Machine Learning Meets Malware. If cognition becomes an API call and malware can be reverse-engineered by an LLM, then what’s left of “zero trust”? Caleb Fenton joined @patio11 for a chat on AI, nation-states, and the new front in software security. 🎧complexsystemspodcast.com/episodes/machi…
English
1
5
4
272
sysxplore
sysxplore@sysxplore·
What is your favourite Linux Command?
sysxplore tweet media
English
776
112
2K
209.1K
Inon Cohen
Inon Cohen@Coheninon1·
יש הרבה סטנדאפיסטים גרועים, אבל אדיר מילר הוא הגרוע שבהם
עברית
85
5
732
72.8K
liba2k retweetledi
Caleb Fenton
Caleb Fenton@caleb_fenton·
If you like building platforms and infrastructure and want to get in on the ground floor of a cyber security startup doing AI and reverse engineering, DM me.
English
0
2
6
909
liba2k
liba2k@liba2k·
Of course the code doesn't work, but it's a start :D
English
0
0
2
90
liba2k retweetledi
Brandon Dalton
Brandon Dalton@PartyD0lphin·
Happy Friday everyone! Want a ProcMon for macOS? Ever wish you had your own Endpoint Security client you could task? Want to peer behind the macOS EDR curtain? Have a go and let us know what you think! github.com/redcanaryco/ma…
English
9
174
442
54.7K
liba2k retweetledi
Sipeed
Sipeed@SipeedIO·
New Tiny #tinyML #AIoT module M0S coming out~ Based on BL616, WiFi6+BT5.2+Zigbee, 384MHz #RISCV RV32GCP, 4MB Flash + 512KB SRAM, and USB2.0 HS in tiny 10x11mm stamp module! It would be <2$ ~
Sipeed tweet media
English
33
197
1K
180.6K
liba2k
liba2k@liba2k·
A device that no one REALLY needs, but fun project anyway. Here is my Caliper/Digital indicator WiFi adapter. github.com/liba2k/VINCA_r…
English
0
0
1
0
liba2k
liba2k@liba2k·
@caleb_fenton Depending on your point of view. Since it's all a simulation, everything is a dream. Saying that, in this iteration of the simulation I did use my Heelys in the office. Now we have carpets and I need to take them to Costco.
English
0
0
1
0
Caleb Fenton
Caleb Fenton@caleb_fenton·
@liba2k You got them also? I think I remember you wearing them in the office but that was the before times and I can't be sure I didn't dream it.
English
1
0
0
0
liba2k retweetledi
Assaf Carlsbad
Assaf Carlsbad@assaf_carlsbad·
Yesterday @liba2k and I presented our talk "Breaking Secure Boot with SMM" at @1ns0mn1h4ck. The slides, exploit code, and some additional resources are now online and available here: github.com/liba2k/Insomni… Thanks to everyone who attended, we hope to see you all again next time!
Assaf Carlsbad tweet mediaAssaf Carlsbad tweet media
English
2
59
157
0
liba2k
liba2k@liba2k·
@retrage Are you planning to submit a PR to DSecurity? You should it's a useful feature.
English
1
0
0
0
retrage
retrage@retrage·
My Weekend Project: Ghidra version of efiXplorer vulnerability scanner. I reimplemented the SMM callout checker as an extension of efiSeek. It can detect CVE-2021-3452. github.com/retrage/efiSee…
retrage tweet media
English
2
53
115
0