
sigabrt
@sigabrt9
ID: 1013847422882275330
02-07-2018 18:10:36
73 Tweet
132 Followers
369 Following

Our writeup showing the 0-day we used to escape the linux kvmtools hypervisor to solve the hxp CTF challange indie_vmm! kalmarunionen.dk/writeups/2021/… by alexander krog Viktor Edström N00byEdge


Today I am releasing the final post of a 3 part series on “modern” browser exploitation targeting Windows. In this post we port our exploit primitives to Edge itself & combine 12 ROP chains in order to defeat ACG, CIG, DEP, ASLR, CFG, "no child processes" connormcgarr.github.io/type-confusion…






Celebrating #Pwn2Own 2022 week (Trend Zero Day Initiative) with a long-overdue writeup of how we successfully exploited a wild (unbounded) memcpy for a guest-to-host virtualization breakout of Parallels at last year's competition: blog.ret2.io/2022/05/19/pwn…



Curious about exploiting VMs or memory bugs in a safe language? Read my new blog post, where I attack Firecracker, AWS' VMM written in Rust. Learn about the various layers of virtualization + the attack surface, and how design decisions impact security. graplsecurity.com/post/attacking…







