Matt Jones
1.3K posts


@dave_au @ChangeAus "... and if they don't, we'll do it for them!"
🚔🚔🚔
English

Alfred's owners: Alfred's Pizzeria should be open for lunch on Fridays - Sign the Petition! chng.it/7SwFCLHp via @ChangeAUS
English
Matt Jones retweetledi

New blog release "Accessing Access Token for UIAccess" on restoring some small part of the older token stealing attack which was killed in Windows 10 RS5. Contains an example PS script to script an admin command prompt 😄 tyranidslair.blogspot.com/2019/02/access…
English
Matt Jones retweetledi

Here's the video recording for my presentation at #bluehatil last week on "Trends, Challenges, and Strategic Shifts in the Software Vulnerability Mitigation Landscape" youtube.com/watch?v=PjbGoj…

YouTube
English
Matt Jones retweetledi

Check out our blog post about research @adam_iwaniuk and I did that lead to CVE-2019-5736!
blog.dragonsector.pl/2019/02/cve-20…
English
Matt Jones retweetledi

Android: binder use-after-free via fdget() optimization bugs.chromium.org/p/project-zero…
English

@S9k His work is incredibly valuable, let's not lose that fact.
It's common for orgs to underinvest on internal staff & prevention, missing common bug classes in implementation. I'm certain adding to their internal staff would help them more efficiently than him doing it at his $ rate
English

Incredibly great ROI for one top #bugbounty hunter.
Incredibly terrible ROI for the org paying this much for 4 hours of his professional time.
For those paying attention, he's one of about 100/350,000 on the platform who has made over $100k, 1 of 2 who cleared over $1M last year
dawgyg - WoH@thedawgyg
The fist 6 figure pay day of 2019. $119,650 Thanks Oath and @Hacker0x01
English
Matt Jones retweetledi

For those interested in coverage-guided fuzzing, I've just released CmpCov - an instrumentation module for clang/SanitizerCoverage, which breaks down CMP/strcmp()/etc. into bytes and writes the extra coverage data to standard .sancov files. Get it here: github.com/googleprojectz…
English
Matt Jones retweetledi

The always erudite @timoreilly on why the SV “blitzscaling” mantra causes more harm than good.
I feel that part of the reason so many security products are so user-hostile (& mostly suck) is because currently, VCs pick winners instead of customers.
qz.com/1540608/the-pr…

English
Matt Jones retweetledi

8 years and 27K bugs later, ClusterFuzz is now available for anyone to use - opensource.googleblog.com/2019/02/open-s…
English
Matt Jones retweetledi

Posted the slides from my #bluehatil talk covering trends, challenges, and strategic shifts in the software vulnerability landscape. Questions, comments, and alternative perspectives welcome 🙂 github.com/Microsoft/MSRC…
English
Matt Jones retweetledi

Also we have to say, while @lady_nerd has spoken at many conferences such as #Kiwicon+#Blackhat, co-authored Agile Application Security and is paid to facilitate training. Laura has genorously decided to volunteer her time as well as pay her own way to Australia to teach! 😍💕
English

We promised a 4th course and we're excited to announce that we're balancing out our offensive heavy theme of courses with @lady_nerd 's Secure development course complete with threat assessment and code review!
To find out more about the course: 0xcc.sh/secure-develop…
English

pls RT: who are the 3-5 best, most natural Threat Modeling minds? Esp for NonSecurity people. @adamshostack is a given
English
Matt Jones retweetledi

Project Zero blog: "The Curious Case of Convexity Confusion" by Ivan Fratric (@ifsecure) - googleprojectzero.blogspot.com/2019/02/the-cu…
English
Matt Jones retweetledi

To go with a release of NtObjectManager v1.1.19 I've written a brief history of BaseNamedObjects and the "new" BNO isolation feature sneaked into Windows 10. tyranidslair.blogspot.com/2019/02/a-brie…
English
Matt Jones retweetledi

Project Zero blog: "Examining Pointer Authentication on the iPhone XS" by Brandon Azad (@_bazad) - googleprojectzero.blogspot.com/2019/02/examin…
English

@damienmiller @mdowd Yeah in high school for me it was quite heavy, esp. with stolen generation
English