Dor (@dor00tkit) 's Twitter Profile
Dor

@dor00tkit

ID: 1090715609791414279

linkhttps://dor00tkit.github.io/Dor00tkit/ calendar_today30-01-2019 20:57:20

482 Tweet

278 Followers

629 Following

s1r1us (@s1r1u5_) 's Twitter Profile Photo

Ben Sadeghipour Pick a niche, become an expert, find bugs maybe even 0days or reverse n-days, and write blogs. Even if you don’t hit those $100k bounties, it’ll be a stepping stone toward a $100k job. What niche? How to pick? Examples? infosec being so vast from web3 sec to web2, mobile,

Alex Plaskett (@alexjplaskett) 's Twitter Profile Photo

Embrace the now! Life's not just about the destination, it's the journey that shapes us. Enjoy every moment, every twist and turn.

Xeno Kovah (@xenokovah) 's Twitter Profile Photo

A small but important note: so far I’ve received exactly $0 in compensation from OST2 over the past 3 years. I will accept honorariums, the same as other instructors, only when OST2 can afford to pay them out. So donations and/or company Sponsorships help us reward instructors!

CICADA8Research (@cicada8research) 's Twitter Profile Photo

Hello everyone! Our team loves everything related to LPE exploits. However, there is no publicly available list on the web with fresh LPE exploits (2023-2024) for Windows. However, we do have such a list. And we are sharing it with you! github.com/MzHmO/Exploit-…

chiefpie (@cplearns2h4ck) 's Twitter Profile Photo

Seems like there's some focus on static binary instrumentation for kernel again recently. Therefore I decide to public my toy for fuzzing Windows kernel drivers with coverage. Wrote this last year and it works for MS released drivers on Windows 11. github.com/Y3A/winkafl

cts🌸 (@gf_256) 's Twitter Profile Photo

My videos for Flare-On 2024 are live! Watch me reverse engineer all the challenges from start to end. + Commentary video featuring SuperFashi, where we review the chals together. * 45 hours of content * 400+ GB of raw footage Merry Christmas! youtube.com/watch?v=vwW9xv…

Or Yair (@oryair1999) 's Twitter Profile Photo

Excited to release LDAPNightmare! The first PoC tool exploiting CVE-2024-49112 that I created with Shak Mo ! Check out the repo and blog post detailing about the vulnerability: github.com/SafeBreach-Lab… Honored to be a part of the SafeBreach labs team once again🫠

hackyboiz (@hackyboiz) 's Twitter Profile Photo

[Research] Fuzzy Fuzzing with WinAFL Part 1 hackyboiz.github.io/2021/05/23/fab… Diving into WinAFL for bug hunting, we've crafted a Harness to execute target functions repeatedly without process termination. Tested with DynamoRIO, our setup's ready for action. Now, let's fuzz like crazy to

Connor McGarr (@33y0re) 's Twitter Profile Photo

Today I’m sharing a blog post on the implementation of kernel mode shadow stacks on Windows! This post covers actively debugging the Secure Kernel and also outlines why VTL 1 is relied on to help maintain the integrity of the supervisor shadow stacks! connormcgarr.github.io/km-shadow-stac…

chiefpie (@cplearns2h4ck) 's Twitter Profile Photo

Here's my new post on finding a handful of bugs in Windows by simple tricks and custom fuzz. We then completed exploitation for LPE. Microsoft patched the bugs by restricting access, which means the bugs are not diffable and still Admin->Kernel 0days. Hope you enjoy the read!

SkelSec (@skelsec) 's Twitter Profile Photo

Well, it happened. The company I worked at for 6 years will be closing and thus I got laid off. This doesn't affect Octopwn operations in any negative ways, but I'm actively looking for a new day job. If someone has something please DM me. Retweets are appreciated.

OpenSecurityTraining2 (@opensectraining) 's Twitter Profile Photo

📣"Fuzzing 1001: Introductory white-box fuzzing with AFL++" by Francesco Pollicino is now released!📣 ost2.fyi/Fuzz1001 This class covers progressively more features and functionality of AFL++ to teach students how to find real past vulnerabilities.

Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks github.com/Dor00tkit/BamE…

Attila Szasz (@4ttil4sz1a) 's Twitter Profile Photo

First drop from my upcoming release: 130+ Linux-based IoT CVEs (2024 & earlier) with real vulnerable firmware. All hand-curated. 👉 github.com/attilaszia/lin… Includes vulnerable binary paths — soon, finding the exact vulnerable effective addresses will be very simple, stay tuned:)