Peter Vreugdenhil

831 posts

Peter Vreugdenhil

Peter Vreugdenhil

@WTFuzz

Mitigations bypassed: DEP, ASLR,KASLR, SafeSEH, CFG, Protected Mode, SMEP, PAC, ** ** list might be incomplete

شامل ہوئے Şubat 2010
34 فالونگ6.6K فالوورز
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
Following the herd to BlueSky: @wtfuzz.bsky.social Will start tweeting research stuff again in 2025.
English
1
0
2
283
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
Ran into a custom xml -> java deserializer. Limited in what it did. Used reflection to set fields, no setter getter. Lot of objects blocked. Deserialized object was not used. Exploited it by overwriting static field values on object that was used in Authentication. #ExploitFun
English
0
0
1
468
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
It’s always convenient when the app you are poking at has a straight up “please execute this command for me” api endpoint once you bypass the auth.
English
0
0
1
453
mdowd
mdowd@mdowd·
It's exhausting being the anchor being
English
1
0
11
2.7K
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
After mainly writing pocs in python and C I just finished a poc written entirely in Java. I was too lazy to rewrite their auth lib in python, but what a frustrating experience. 1/10 would not recommend. Anyways, auth bypass + command injection means:
Peter Vreugdenhil tweet media
English
0
0
5
619
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
@zlowram_ @alexjplaskett Looks like I have a bit more than 2 months to waste time trying to find the perfect latex lib to generate slides that can display objects in memory and their relationships. Leaving me 2 weeks for actual content 😁
English
0
0
4
73
Sergi Martinez
Sergi Martinez@zlowram_·
@WTFuzz @alexjplaskett Came here to also say OffensiveCon, and they've just opened the CFP today. Hope to see you there, Peter! 🙂
English
1
0
1
129
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
I’m thinking about turning some recent windows kernel research and exploits into a talk. Does anyone have suggestions for conferences that currently have their CFP open or will open shortly?
English
2
0
2
1.2K
Rodrigo Branco
Rodrigo Branco@bsdaemon·
@WTFuzz @alexjplaskett Offensive is great, I highly recommend. @h2hconference has a revolving CFP (we accept submissions at any time, even though we do announce it only when we have dates/venue for the year). This year will be our 21st year anniversary.
English
1
0
1
353
Alex Plaskett
Alex Plaskett@alexjplaskett·
@WTFuzz offensivecon CFP isn’t open yet but I assume will be at some point soon with it in May. Highly recommended..
English
1
0
1
267
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
After many years and tons of fun I left ExodusIntelligence recently. Enjoying some nice time off right now, spending time with the kids and not IDA 😁 No plans yet for 2024 but I’m sure something exciting will show up.
English
5
0
20
1.4K
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
I had almost forgotten what an assault Vegas is on the eyes and ears, but Vegas was luckily kind enough to remind me real quick.
English
0
0
1
0
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
Been a few years, but I'll actually be in Vegas for #bh2022 hoping to run into folks I haven't seen in ages.
English
0
0
5
0
Peter Vreugdenhil ری ٹویٹ کیا
Exodus Intelligence
Exodus Intelligence@XI_Research·
Hopes are high that some normalcy can return in 2021 and we can see our colleagues again at Blackhat. We're hosting an in-person 5-day training around that time and looking for feedback on timing. Plan before, during, or after the conference?
English
1
11
9
0
Peter Vreugdenhil ری ٹویٹ کیا
Exodus Intelligence
Exodus Intelligence@XI_Research·
We're looking for someone to take on our infrastructure, grow it, secure it, modernize it, automate it, and generally make it more awesome. If you live in central Texas and are interested in starting a dialog. Reach out to us via careers@exodusintel.com ninjajobs.org/job/4d179c3280…
English
0
12
9
0
Peter Vreugdenhil ری ٹویٹ کیا
Exodus Intelligence
Exodus Intelligence@XI_Research·
2019 was a great year for Exodus and 2020 is going to be even better. We're expecting to expand the team on a variety of fronts. If interested visit exodusintel.com/careers.html and email careers@exodusintel.com with a cv and references published work
English
2
17
29
0
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
ntdll!LdrpSetProtection(0xaddr, 0) good function for x64 exploits. 2 args and a fake PE Header (9 values) at 0xaddr and it'll mark it as RWX for you. Too bad its not exported. byte match: 48 89 5C 24 08 55 56 57 41 54 41 55 48 83 EC 40 45 33 C0 0F B6 EA 4C 8B E1 48 8B D1
English
1
24
82
0
Peter Vreugdenhil
Peter Vreugdenhil@WTFuzz·
I like how MS keeps insisting that UAC is not a security boundary but they do try to squash bugs and techniques to bypass it. But, it is indeed not as sturdy as some of the other protection they have despite recent changes.
English
0
0
2
0