Alejandro G.
31 posts

Alejandro G.
@lockedbyte
Android kernel vulnerability researcher | Mathematics student
Spain Tham gia Ağustos 2018
912 Đang theo dõi2.7K Người theo dõi

I developed an N-day exploit for CVE-2022-2586: Linux kernel nft_object Use-After-Free (UAF). I sent my exploit and writeup to the oss-security mailing list: openwall.com/lists/oss-secu…
GIF
English

This vulnerability was used in Pwn2Own Vancouver by @Seasecresponse: congratulations and thanks for this amazing discovery!
English

This is a in-depth write-up of one of the CLFS bugs I worked on recently. Thanks @XI_Research for giving me the opportunity to conduct this research.
Exodus Intelligence@XI_Research
Exploiting a use-after-free in Windows Common Logging File System (CLFS): blog.exodusintel.com/2022/03/10/exp…
English

Thanks to the researchers from @cor_ctf for pumping out this awesome bug!
English

Now that the discoverers have published their exploit and writeup, I sent my exploit and writeup for CVE-2022-0185 (Linux kernel integer underflow to slab OOB write) to the oss-security mailing list: openwall.com/lists/oss-secu…
GIF
English

@dor0n1 I tested it and works on multiple VMs, people tested it and works for them, it is your problem to find the issue and fix it, not mine
English


@dor0n1 what do u mean? My last commit was 9 hours ago, this repo was created 6 hours ago...
English


@0xdea @AdeptsOf0xCC Huge thanks for feedback! Appreciate it a lot
English

@AdeptsOf0xCC Happy anniversary! I’ve especially enjoyed all exploits and posts by @lockedbyte. He’s very talented ✊
English
Alejandro G. đã retweet

ProFTPd UAF (@lockedbyte), API hacking (@hakluke and @Farah_Hawaa), file extension tricks on cloud storage (@mrd0x), built-in AD searching with ADSI (@Gr1mmie), DCE/RPC fingerprints (@hdmoore), SAML issues (@Secureworks, @joonas_fi), and more! blog.badsectorlabs.com/last-week-in-s…
English

CVE-2021-31956: Heap Overflow => LPE in ntfs.sys
Massive credits: @d0lph1n98
Looking forward to part 2 of the blog to defeat LFH randomization @alexjplaskett

English
Alejandro G. đã retweet

A very detailed exploit demonstration of @Nosoynadiemas 's CVE-2020-9273 (ProFTPd UAF)
Adepts of 0xCC@AdeptsOf0xCC
Dear Fellowlship, How is your summer going? Our N-Day owl @lockedbyte was bored in his holidays and decided to build an exploit for CVE-2020-9273. Check our post: Having fun with a Use-After-Free in ProFTPd (CVE-2020-9273) adepts.of0x.cc/proftpd-cve-20…
English
Alejandro G. đã retweet

Dear Fellowlship, How is your summer going?
Our N-Day owl @lockedbyte was bored in his holidays and decided to build an exploit for CVE-2020-9273. Check our post:
Having fun with a Use-After-Free in ProFTPd (CVE-2020-9273)
adepts.of0x.cc/proftpd-cve-20…
English
Alejandro G. đã retweet

Exim RCE (@lockedbyte), Windows kernel exploit writeup (@33y0re), plaintext RDP creds from memory (@jonasLyk, @n00py1), MS Defender ATP bypasses (@Tyl0us), hashcat 6.2.0 (@hashcat), persist and blend C2 with Teams (@BlackArrowSec), and more! blog.badsectorlabs.com/last-week-in-s…
English






