Asteris Ch (@jac0wl) 's Twitter Profile
Asteris Ch

@jac0wl

ID: 1002538536594300928

calendar_today01-06-2018 13:13:08

624 Tweet

119 Followers

679 Following

ohjin (@pwn_expoit) 's Twitter Profile Photo

macrumors.com/2023/04/17/app… 4403769: ios: Enable PartitionAlloc for week four and remainder of 112 stable. | chromium-review.googlesource.com/c/chromium/src… chrome IOS Fullchain really come true?

Yordan Stoychev (@yordanstoychev) 's Twitter Profile Photo

Finished a write-up of a vulnerability in the io_uring subsystem of the Linux Kernel. This one is interesting because it gives you an incredibly powerful primitive - a multipage-wide OOB read and write to physical memory. anatomic.rip/cve-2023-2598/

1ce0ear (@1ce0ear) 's Twitter Profile Photo

More APVI bugs were disclosed, including two page UAF and PFN leaks: bugs.chromium.org/p/apvi/issues/… bugs.chromium.org/p/apvi/issues/… bugs.chromium.org/p/apvi/issues/…

Alex Plaskett (@alexjplaskett) 's Twitter Profile Photo

Jailbreaking the Sonos Era 100 research.nccgroup.com/2023/12/04/sho… The Era 100 is Sonos’s flagship device, released on March 28th 2023 and is a notable step up from the Sonos One. NCC Group Research & Technology found multiple weaknesses within the bootloader which could lead to full compromise #sonos

Jailbreaking the Sonos Era 100

research.nccgroup.com/2023/12/04/sho…

The Era 100 is Sonos’s flagship device, released on March 28th 2023 and is a notable step up from the Sonos One. <a href="/NCCGroupInfosec/">NCC Group Research & Technology</a> found multiple weaknesses within the bootloader which could lead to full compromise

#sonos
daem0nc0re (@daem0nc0re) 's Twitter Profile Photo

To dive more advanced low layer things such as hypervisor, I'm reviewing Windows kernelmode rootkit techniques, and created a repositry for research and educational purpose. More PoCs will be added later (filesystem/network mini-filter things especially). github.com/daem0nc0re/Vec…

VUSec (@vu5ec) 's Twitter Profile Photo

Disclosing #SLAM, aka how to combine Spectre and Intel LAM (& co.) to leak kernel memory on future CPUs (demo below). Thousands of exploitable "unmasked" (or pointer chasing) gadgets in the Linux kernel. Joint work by Mathé Hertogh Sander Wiebing Cristiano Giuffrida: vusec.net/projects/slam

Sunjoo Park (@grigoritchy) 's Twitter Profile Photo

It is interesting to see similar shift/unshift race condition issues that i found and exploited webkit in 2018 (github.com/grigoritchy/un…) are exploited on safari, chrome these days as an in the wild bug

Yuri Sagalov (@yuris) 's Twitter Profile Photo

A high school student reverse engineered the iMessage protocol and published a cross-platform proof of concept. jjtech.dev/reverse-engine…

stephen (@_tsuro) 's Twitter Profile Photo

The first #v8CTF submission is now public: bughunters.google.com/reports/vrp/38… Note that the current flag is still up for grabs, maybe M118 is unhackable? ;P You should also check out @madstacks3's excellent writeup at madstacks.dev/posts/Start-Yo…

Hossein Lotfi (@hosselot) 's Twitter Profile Photo

Apple Safari In-The-Wild type confusion vulnerability (CVE-2024-23222 [267134]) happens because DFG constant property load does not check the validity at the main thread: github.com/WebKit/WebKit/…

j j (@mistymntncop) 's Twitter Profile Photo

Exploit for CVE-2022-4262. Fukin finally! Shoutout to clem1 for finding the ITW exploit. And shoutout to Samuel Groß, Jack Ren, Alisa Esage Шевченко for their RCA's and prior analysis of the vuln :). github.com/mistymntncop/C…