Christian Werling

31 posts

Christian Werling

Christian Werling

@_cwerling

Berlin, Deutschland เข้าร่วม Mayıs 2018
257 กำลังติดตาม219 ผู้ติดตาม
Christian Werling รีทวีตแล้ว
Max Hoppenstedt
Max Hoppenstedt@m_hoppenstedt·
The researchers also say they were able to prove the existence of the "Elon mode" (non restricted, fully self driving) and they were able to turn the mode on. All by a voltage glitch attack on the board with cheap equipment #37c3 Full story in German :spiegel.de/netzwelt/gadge…
English
0
1
3
3.3K
Christian Werling รีทวีตแล้ว
Max Hoppenstedt
Max Hoppenstedt@m_hoppenstedt·
Security researchers say they were able to access restricted parts of the autopilot board in Tesla vehicles, access the neural networks and reverse engineer most of the program. Even recover deleted footage from a Tesla vehicle. Here is what they told me: spiegel.de/netzwelt/gadge…
English
2
3
2
3K
Christian Werling รีทวีตแล้ว
Max Hoppenstedt
Max Hoppenstedt@m_hoppenstedt·
Drei Berliner Sicherheitsforschern haben mir berichtet, dass sie per Voltage-Glitch Teslas Autopilot-Platine gehackt und den gesperrten Elon-Modus eingeschaltet haben. Heute stellen Sie beim #37c3 ihre Forschung ausführlich vor, hier eine Übersicht spiegel.de/netzwelt/gadge…
Deutsch
1
6
12
2.2K
AI Safety First!
AI Safety First!@aisafetyfirst·
@_cwerling Christian this is very valuable research, have you looked at AMD Zen 4 CPUs with faulTPM yet? Very important for people to know if faulTPM is still possible on Zen 4 CPUs otherwise they need to be avoided like the plague for anything that requires reasonable security.
English
1
0
0
31
Christian Werling
Christian Werling@_cwerling·
Disk encryption is critical in securing your data when you lose your device or an attacker gets physical access. But we found that if you don't use a BitLocker passphrase on an AMD system (before Windows even comes up), your data is not adequately secured: arxiv.org/abs/2304.14717
English
4
66
146
33K
Christian Werling รีทวีตแล้ว
Lionel Rivière
Lionel Rivière@mangeurdpommes·
#jailbreaking-an-electric-vehicle-in--or-what-it-means-to-hotwire-teslas-x-based-seat-heater-33049" target="_blank" rel="nofollow noopener">blackhat.com/us-23/briefing… Why testing fault injection attacks on integrated circuits matters? ⚡️🚗🔐 At BlackHat 23, a research team from @TUBerlin: Christian (@_cwerling), Niclas, Hans and Oleg will show voltage glitch attack against AMD Secure Processor (ASP) used in Tesla cars!
English
0
5
11
2.2K
Christian Werling รีทวีตแล้ว
Positive Security
Positive Security@positive_sec·
We built a stealth AirTag clone that is not detected by Apple’s tracking protection. It works by only sending one beacon per generated public key. positive.security/blog/find-you
English
5
34
67
0
Christian Werling รีทวีตแล้ว
Positive Security
Positive Security@positive_sec·
New blog post: Windows 10 RCE via an argument injection in the ms-officecmd URI handler. While our RCE vector (MS Teams) has been fixed, the argument injection still persists. positive.security/blog/ms-office…
English
1
106
255
0
Christian Werling
Christian Werling@_cwerling·
@WangTielei While checking out the Nailgun Attack paper [0], I saw an acknowledgment to you for checking iOS devices. Any insights you would be willing to share? Wondering whether the M1 might be susceptible, too. [0] compass.sustech.edu.cn/nailgun/
English
1
0
0
0
Christian Werling รีทวีตแล้ว
Positive Security
Positive Security@positive_sec·
Unpatched, critical vulnerabilities in the PlingStore app and Pling-based Linux marketplace websites and patched, lower-severity vulnerabilities in KDE Discover and the Gnome Shell Extensions website positive.security/blog/hacking-l…
English
0
4
7
0
Christian Werling รีทวีตแล้ว
Security Research Labs
Security Research Labs@SecReLabs·
Different port, same exploit: Our research found how a patched vulnerability in ZyXEL NAS devices was still exploitable due to incomplete patching srlabs.de/bites/zyxel-ze…
English
0
5
8
0
Christian Werling รีทวีตแล้ว
Positive Security
Positive Security@positive_sec·
Apple AirTags: Arbitrary data can be uploaded from non-internet-connected devices by sending Find My BLE broadcasts to nearby Apple devices: positive.security/blog/send-my
English
4
97
170
0
Christian Werling รีทวีตแล้ว
dmnk.bsky.social
dmnk.bsky.social@domenuk·
After months of hard work, we're releasing #LibAFL ✔️Scales across cores and machines ✔️Windows, Android, no_std, ... ✔ Different Modes like binary-only Frida mode (120k execs/sec on a phone anyone?) ✔ Easy to extend with grammar fuzzing, etc. ✔️Rust ;)
Andrea Fioraldi@andreafioraldi

#libafl is now public! github.com/AFLplusplus/Li… We decided to make it public even without so much documentation so people can start hacking on it. With @domenuk @srubenst1341 @hackerschoice

English
2
65
211
0
Christian Werling
Christian Werling@_cwerling·
@OrangeCMS Thanks a lot for your PR. Looking forward to check it out on the weekend! :)
English
1
0
1
0