
Daniël Trujillo
@thedantrujillo
PhD student in EECS at MIT.
MSc CS from ETH Zürich and BSc CS from VU Amsterdam.
ID: 1680258119325106179
15-07-2023 16:49:28
15 Tweet
142 Followers
53 Following

Our uncontained paper USENIX Security is online! Find out how the Linux kernel is the "container of" several type confusion bugs, detected by our sanitizer & static analyzer. Joint work by Jakob Koschel Pietro Borrello Daniele Cono D'Elia Herbert Bos Cristiano Giuffrida: vusec.net/projects/uncon…

Our FloatZone paper USENIX Security is online: a branchless memory sanitizer that efficiently catches buffer overflows (+ use-after-frees) with floating-point underflows! Joint work by Floris Gorter @Enrico barberis @teemperor Erik van der Kouwe Cristiano Giuffrida Herbert Bos: vusec.net/projects/float…

Paper from Victor van der Veen & me about using the DRAM row conflict signal as a sidechannel on uncached execution (for protection): dramsec.ethz.ch/papers/dramaqu… - the thought: can we mitigate all uarch side channels by selectively bypassing cache? answer: perhaps, but DRAM sidechannel remains


We built a RISC-V CPU fuzzer that generates test programs in a clever way and it rained CVEs! Cascade brings CI/CD to CPU designers 😀 Check Flavien's thread if you want to know more. To be presented at USENIX Security

Phantom just won a best paper award at MICRO 2024! Phantom shows the security implications of pre-decode speculation that is fundamental in achieving high performance. We are happy and deeply honored! (with johannes Daniël Trujillo)



The first ever end-to-end cross-process Spectre exploit? I worked on this during an internship with grsecurity! An in-depth write-up here: grsecurity.net/cross_process_…
