Ramon de C Valle

14 posts

Ramon de C Valle

Ramon de C Valle

@rcvalle

Vulnerability researcher at @Google. Views are my own. @[email protected]

Katılım Mart 2009
3 Takip Edilen973 Takipçiler
Ramon de C Valle retweetledi
Brad Spengler
Brad Spengler@spendergrsec·
@standa_t @rcvalle This is why we've been helping fund the development of gccrs (Rust front-end for gcc) since 2021: opensrcsec.com/open_source_se… What's mentioned in Ramon's blog is great work, but only solves the CFI subset of the larger "mixed binary" problem, and only within the LLVM ecosystem.
English
1
2
8
2.8K
Ramon de C Valle retweetledi
Satoshi Tanda
Satoshi Tanda@standa_t·
Porting part of a C/C++ program into Rust can make the program less secure. It has been known for quite some time but was new to me. Great read and work driven by @rcvalle bughunters.google.com/blog/480557116… Read one of the linked papers for more details.
English
1
33
118
12K
Ramon de C Valle retweetledi
H2HC
H2HC@h2hconference·
17th edition of H2HC Magazine (the one that we've distributed printed to attendees at H2HC 20th) is finally online, with articles in English as well (Attacking the Linux Kernel Free List Hardening & LLVM Rust CFI): h2hc.com.br/revista
English
1
13
36
9.3K
Ramon de C Valle retweetledi
Google VRP (Google Bug Hunters)
Want to know how we are working with the Rust community to add LLVM CFI and cross-language LLVM CFI to the Rust compiler? Eliminating the most critical instances of cross-language attacks in mixed-language binaries (cont) spklr.io/l/6015mABf
English
1
8
53
10.7K
Ramon de C Valle
Ramon de C Valle@rcvalle·
This eliminates the most critical instance of cross-language attacks in mixed-language binaries, helping not only Google, but also the industry with secure Rust adoption. Here is the article/blog post for my talk at #H2HC: rcvalle.com/blog/2023/12/0…
English
1
0
1
227
Ramon de C Valle
Ramon de C Valle@rcvalle·
Last Saturday I talked at @h2hconference and shared the results of working with the Rust community to add LLVM CFI and cross-language LLVM CFI to the Rust compiler...
Ramon de C Valle tweet media
English
2
5
44
4K
Ramon de C Valle
Ramon de C Valle@rcvalle·
@spendergrsec I don't think it's properly fixed yet. I made a note more recently about it, which was the last time I looked at it, at #appendix" target="_blank" rel="nofollow noopener">rcvalle.com/2020/09/16/rus…
English
1
0
1
134
Brad Spengler
Brad Spengler@spendergrsec·
@rcvalle that seems to be read-implies-exec though (which also was never an issue for us, and I think upstream maybe addressed recently?) and not this, which is just normal PT_GNU_STACK implementation stuff.
English
1
0
0
157