P1umer

64 posts

P1umer banner
P1umer

P1umer

@p1umer

🌐 Security Researcher | 🤖 AI Enthusiast | 🎙️ BlackHat ASIA/EU/USA. 𝕏s are my own.

Katılım Kasım 2018
418 Takip Edilen851 Takipçiler
Sabitlenmiş Tweet
P1umer
P1umer@p1umer·
Our #BHUSA talk — Tool Part 1/3: Instead of fighting QL syntax, we let LLMs relax official queries by removing conservative pruning. github.com/P1umer/QL-Relax
English
0
2
15
1.6K
P1umer retweetledi
Samuel Groß
Samuel Groß@5aelo·
I've uploaded the slides of my recent talk "JS Engine Security in 2025": saelo.github.io/presentations/…. I think there'll also be a recording available at some point (otherwise I can make one as not everything's in the slides). Thanks for the fantastic conference @POC_Crew!
English
3
61
223
19.8K
P1umer retweetledi
Sebastian Lekies
Sebastian Lekies@slekies·
Today, we announced the official release of OSV-SCALIBR, Google's software composition analysis library. If you are working in vuln management / security scanning, SCALIBR is for you! SCALIBR is powering most of Google's vuln scanning. Please RT security.googleblog.com/2025/01/osv-sc…
English
3
75
210
14.8K
xvonfers
xvonfers@xvonfers·
Some of the best presentations about browsers, great talk about WASM/WASM-To-JS internals, bug hunting and exploitation. Many thanks to all the speakers, I recommend them to study!
P4nda@P4nda20371774

Our slides about WASM bugs in browsers are now available. Thanks to everyone who helped with the talk.🫡 Hope we can do better next time. 1. BH USA 2024: i.blackhat.com/BH-US-24/Prese… 2. GeekCon Shanghai 2024: geekcon.top/js/pdfjs/web/v… cc my partners (@p1umer @xmzyshypnc1 @q1iqF)

English
4
6
60
7.1K
P1umer retweetledi
P1umer
P1umer@p1umer·
A simple patch could fix it, but maybe afl need to clear up what the post process really means.
English
2
0
1
352
P1umer
P1umer@p1umer·
Maybe there's a potential hiccup with AFL's custom mutator post process design. If the post process happens in `write_to_testcase` and saves the sample afterward, it seems to go against the "before executing the target" guideline in the docs.
P1umer tweet media
English
1
0
4
539
P1umer retweetledi
Black Hat
Black Hat@BlackHatEvents·
During #BHUSA Briefing "Achilles' Heel of JS Engines: Exploiting Modern Browsers During WASM Execution" we will discuss some of the interesting vulnerabilities we found on attack surface of WebAssembly and demonstrate how to exploit them >> bit.ly/3yXSpfD
Black Hat tweet media
English
0
9
17
7K
P1umer retweetledi
Samuel Groß
Samuel Groß@5aelo·
Thanks to events like Pwn2Own or our V8CTF (~= exploit bounty program), we now have more data about the types of bugs exploited in V8. Based on that, we've gathered some basic statistics: docs.google.com/document/d/1nj…
English
4
63
235
38.6K
P1umer retweetledi
DEF CON
DEF CON@defcon·
Thanks to the fine folks at @nautilusinstitute the #defcon32 #ctf quals are in the books - you can read all about it at quals.2024.nautilus.institute. There's also a veritable feast of JSON dumps for the curious. Congrats to the winners, thank you to everyone who suited up and we'll see you in Las Vegas! #defcon
DEF CON tweet mediaDEF CON tweet media
English
2
23
77
15.7K