DiegoAltF4
@diego_altf4
Binary Exploitation & Fuzzing enthusiast with a special focus on Hypervisors | @zeroclicksh
ID: 1125427403327725568
06-05-2019 15:49:37
36 Tweet
696 Followers
1,1K Following
Leaking Host KASLR from Guest VMs Using Tagged TLB by renorobert Article Highlight #14 - check it out in Paged Out! #4 page 58 pagedout.institute/download/Paged…
Well written blog post on exploiting a Use-after-Free (UaF) in Linux kernel (CVE-2024-0582, io_uring) blog.exodusintel.com/2024/03/27/min… Credits Oriol Castejón (Exodus Intelligence) #iouring #infosec
A few months ago, the FreeBSD Foundation appointed us to audit two #FreeBSD critical components: the Bhyve hypervisor and the Capsicum sandboxing framework. Today, related advisories and patches have come out 🧵 1. Multiple vulnerabilities in libnv freebsd.org/security/advis…
Android Virtualization Framework - runs the "host" (Android and Linux kernel) in a VM and launches isolated envs. (= pVMs). Based on KVM but offloads complex code to the host VM. pVM firmware is in Rust - youtube.com/watch?v=K24dmA… - source.android.com/docs/core/virt… - android.googlesource.com/platform/packa…
Blog post coming soon with an in-depth analysis and exploit development for CVE-2023-22098, discovered by the incredible Andy Nguyen! Stay tuned, VM wizards!
Outstanding! Nguyen Hoang Thach (Thach Nguyen Hoang 🇻🇳) of STARLabs SG used a single integer overflow to exploit #VMware ESXi - a first in #Pwn2Own history. He earns $150,000 and 15 Master of Pwn points. #P2OBerlin