置顶推文
rtmcx
530 posts

rtmcx
@rtmcx
Member of the Synack Red Team. Researcher, pentester, shellcoder and reverse engineer. OSCE|OSCP|SLAE|eCPPT|CISSP.
加入时间 Ağustos 2013
1.2K 关注887 粉丝
rtmcx 已转推

Slide decks on getting started with Linux kernel exploitation
"Linux Kernel Exploitation for Beginners" by Kevin Massey:
rvasec.com/slides/2025/Ma…
"Control Flow Hijacking in the Linux Kernel" by Valeriy Yashnikov
pt-phdays.storage.yandexcloud.net/Yashnikov_Vale…
#Linux #infosec


English
rtmcx 已转推

I am developing a dirt cheap hardware to perform voltage glitching attacks: mkesenheimer.github.io/blog/pico-glit…

English
rtmcx 已转推

Pwndbg 2025.01 is out! It adds official LLDB support including support for macOS and Mach-O binaries, improved performance, enhanced embedded debugging & many more!
Also, want to support us or buy us a coffee? See our GH sponsors: github.com/sponsors/pwndbg
github.com/pwndbg/pwndbg/…
English
rtmcx 已转推

🚨 The Certified WiFiChallenge Professional course is live NOW! 🚀 Exclusive discounts for the first 50 buyers, up to 50% off! Don’t miss out! 💻 #WiFiChallenge
wifchall.com/cwp
English
rtmcx 已转推

🛡️ Master the art of auditing Wi-Fi networks! The CWP course at WiFiChallenge Academy is designed for both beginners and experts. Get ready to tackle real-world challenges with confidence in the WiFiChallenge Lab. Launching September 23rd! wifchall.com/cwp
#WiFiChallenge
English
rtmcx 已转推

🔍 Want to learn how to hack Wi-Fi networks? The CWP course from WiFiChallenge Academy will take you from beginner to expert with hands-on labs and real-world scenarios. Join the mailing list to be the first to know when it launches! #WiFiChallenge
academy.wifichallenge.com

English
rtmcx 已转推

Hi All,
We are giving away $500 every time we post to our timeline this August.
Whether you love us or really love us all you have to do is REPOST or REPLY to our timeline posts to enter.
And, to our handful of haters, you, of course, can enter too.
Rules are here:
stickermule.com/500-terms
Tag your friends so they join the fun.
Anthony Constantino
CEO, Sticker Mule
P.S. We're still thinking about giving away another Cybertruck.
English
rtmcx 已转推

This was an excellent writeup on how to pwn WatchGuard firewalls
Credits @ambionics
web.archive.org/web/2023062813…
#infosec #watchguard



English
rtmcx 已转推

Interesting series on how virtualization works (VMware, XEN, QEMU)
Credits @LordNoteworthy
Part 1: docs.saferwall.com/blog/virtualiz…
Part 2: docs.saferwall.com/blog/virtualiz…
Part 3: docs.saferwall.com/blog/virtualiz…
Part 4: docs.saferwall.com/blog/virtualiz…
#virtualization #infotech




English
rtmcx 已转推

Series on fuzzing open source software using fuzzuf by @RicercaSec
ricercasecurity.blogspot.com/2023/07/fuzzin…
ricercasecurity.blogspot.com/2023/07/fuzzin…
ricercasecurity.blogspot.com/2023/07/fuzzin…
ricercasecurity.blogspot.com/2023/07/fuzzin…
#fuzzing #cybersecurity




English
rtmcx 已转推

Framework for multi architecture emulation and firmware fuzzing (Icicle)
Paper: arxiv.org/pdf/2301.13346…
github repo (pre-release): github.com/icicle-emu/ici…
#fuzzing #firmware #rustlang #cybersecurity




English
rtmcx 已转推

In this excellent blog post, Olivier Laflamme (@olivier_boschko) goes through practical examples of how Shambles, a tool by Lian Security, can be used to reverse engineer and find vulnerabilities in embedded/IoT devices
boschko.ca/shambles/
#infosec #iot #cybersecurity




English
rtmcx 已转推

Nice short reading for anyone interested in starting with embedded/IoT devices analysis and reversing.
Credits @CyberWolf_2077
whiterose-infosec.super.site/mjsxj09cm-reco…
#embedded #infosec



English
rtmcx 已转推
rtmcx 已转推
rtmcx 已转推

Series to learn IoT/embedded devices reverse engineering (credits @Palantir555)
Debug Ports: jcjc-dev.com/2016/04/08/rev…
Firmware: jcjc-dev.com/2016/04/29/rev…
Data: jcjc-dev.com/2016/05/23/rev…
Flash: jcjc-dev.com/2016/06/08/rev…
Digging the Firmware: jcjc-dev.com/2016/12/14/rev…
#iot




English
rtmcx 已转推

Learning the basics of Linux kernel exploitation
Excellent series by @k3170Makan
Debugging with QEMU: blog.k3170makan.com/2020/11/linux-…
Stack Overflows: blog.k3170makan.com/2020/11/linux-…
RIP control: blog.k3170makan.com/2021/01/linux-…
#cybersecurity #infosec #Linux #kernel




English
rtmcx 已转推

Excellent blog post on TrustZone Exploitation (AMLogic A113X) by @boredpentester
boredpentester.com/retreading-the…
Based on this work by @bl4sty
haxx.in/posts/dumping-…
#embedded #trustzone #cybersecurity




English
rtmcx 已转推

Excellent series on ARM64 reversing and exploitation.
Credits @8kSec
Heap overflow: 8ksec.io/arm64-reversin…
UaF: 8ksec.io/arm64-reversin…
ROP: 8ksec.io/arm64-reversin…
NX and mprotect: 8ksec.io/arm64-reversin…
#arm #exploit #infosec




English
