Alyosha Sintsov

4.3K posts

Alyosha Sintsov

Alyosha Sintsov

@asintsov

was born in '85, still alive...

Entrou em Şubat 2010
532 Seguindo3K Seguidores
Alyosha Sintsov retweetou
b1ack0wl
b1ack0wl@b1ack0wl·
"we would look at xrefs to strcpy() and write a highly reliable exploit by the end of the day"
b1ack0wl tweet media
English
3
69
499
31.3K
Alyosha Sintsov
Alyosha Sintsov@asintsov·
Is Ivanti 0days based on path traversal + command injection in backup endpoint?
English
1
0
0
663
Alyosha Sintsov retweetou
Cristofaro Mune
Cristofaro Mune@pulsoid·
Let me say that again... You store pointers at the _destination_ address of a memcpy. You glitch during memcpy (). You get that pointer into PC. No, it's not sci-fi. It's the "instruction corruption" fault model. And we pioneered that. See thread below 1/N.
Raelize@raelizecom

This attack showed that the data at the destination of a copy can be abused just like the data at the source. We had to improve this attack quite a bit as it simply took too long to get a successful glitch. The details for this optimization will be explained during our training.

English
1
14
39
10.6K
Alyosha Sintsov retweetou
Alex Matrosov
Alex Matrosov@matrosov·
Application Security and Vulnerability Assessment getting a significant advantage from GenAI (context-driven knowledgebase). That helps security teams understand the root cause of the problem faster and significantly reduces the latency in producing security fixes at scale.
Alex Matrosov tweet media
English
1
10
32
6.9K
Alyosha Sintsov
Alyosha Sintsov@asintsov·
@joernchen I call it D&D already. I also think we should have network map and mini-figures!
English
0
0
1
110
Alyosha Sintsov
Alyosha Sintsov@asintsov·
Also found interesting, that ChatGPT works much better if you ask to use LangSec approach: translate logic into grammar, and input as a language and try to find a Weird Machine, works more efficient at my example than just "check the pseudocode/logic for security issues"
English
0
0
1
291
Alyosha Sintsov
Alyosha Sintsov@asintsov·
And on other side: "fraud/propaganda" is also a language for creating "weird machines"...
English
0
0
0
225
Alyosha Sintsov
Alyosha Sintsov@asintsov·
Think lately about weird machines, and found myself that jokes and humor is an example of such for human beings.
English
1
0
0
353
VirusTotal
VirusTotal@virustotal·
Introducing VirusTotal Code Insight: empowering threat analysis with generative AI. This tool is based on Sec-PaLM (LLM) and helps explaining behavior of suspicious scripts. Code Insight is available now for all our users! More details by @bquintero: blog.virustotal.com/2023/04/introd…
VirusTotal tweet media
English
10
506
1.5K
269.1K
Alyosha Sintsov retweetou
PT SWARM
PT SWARM@ptswarm·
📝New research by @lmpact_l: "Fork Bomb for Flutter" There are more and more Flutter applications, and security analysis of these apps is in high demand. Our member Phil shares his knowledge and presents his reFlutter tool. Read the article: swarm.ptsecurity.com/fork-bomb-for-…
English
6
27
76
0
Alyosha Sintsov
Alyosha Sintsov@asintsov·
Future of hacking... ha ha, It is really fun, thx!
Alyosha Sintsov tweet media
English
1
3
6
0