Roberto Paleari retweetledi
Roberto Paleari
241 posts

Roberto Paleari retweetledi
Roberto Paleari retweetledi
Roberto Paleari retweetledi

FAQ: How to find vulnerabilities?
gynvael.coldwind.pl/?lang=en&id=659
English

@xoreaxeaxeax Thanks!! And kudos again for your research! ..enjoy BH now ;-)
English

@xoreaxeaxeax congrats for the cool x86 paper! we used a similar approach some years ago: roberto.greyhats.it/pubs/issta10-n…
English
Roberto Paleari retweetledi

Working exploit for Win7 IE11 <= 11.0.37 (CVE-2017-0037 and CVE-2017-0059):
redr2e.com/cve-to-exploit…
English

@evilsocket Years ago (italian) bundled apps were used to self-update via plain HTTP ;-) twitter.com/rpaleari/statu…
Roberto Paleari@rpaleari
In 2014, developers still update their TV apps via plain HTTP.What could go wrong?(bundled 3rd-party app,not Samsung)
English
Roberto Paleari retweetledi

So you want to work in security, but are too lazy to read @laparisa's excellent essay: lcamtuf.blogspot.com/2016/08/so-you…
English

Interacting with Samsung radio layer from unprivileged applications roberto.greyhats.it/2016/05/samsun… (“stealth call” video: twitter.com/rpaleari/statu…)
Roberto Paleari@rpaleari
On several Samsung phone models, unprivileged applications can perform "stealth calls" (i.e., with no visible clue)
English

@jcase @jduck @cheru2 yep, you just have to switch USB configuration before Details are here github.com/ud2/advisories…
English

@ObregonJose1 @joystick we don't have an S5 device, but it should work. You can test it using the PoC at github.com/ud2/advisories…
English

@rhcp011235 @joystick never tried on a S7 (still too expensive for us :-)). btw we notified samsung on 12/2015, so maybe they fixed it..
English

We just posted the details of the Samsung "lock bypass" video we tweeted some months ago (with @joystick): github.com/ud2/advisories…
English
Roberto Paleari retweetledi

Find this 2016's #EasterEggs using #BinDiff. Now available for free:
security.googleblog.com/2016/03/bindif…
zynamics.com/software.html

English
Roberto Paleari retweetledi
Remember when we mentioned a Samsung's secfilter bypass? Here it is: github.com/ud2/advisories… cc: @rpaleari
English




