JohnE Pwny
@erez_yonatan
Researcher && Internals lover | Pwn | Exploits | Python internals | Embedded | Windows tricks | 61st place on pwnable.kr | Co-author of NoxCTF
ID: 888827442093314049
https://github.com/YonatanErez 22-07-2017 18:25:50
182 Tweet
211 Followers
501 Following
Spectre-v2 is back! Disclosing Branch History Injection (#BHI/#Spectre-BHB), bypassing Spectre-v2 hw defenses to leak arbitrary kernel/host memory (e.g., root password hash below). Joint work by @Enrico barberis Pietro Frigo nSinus-R (@[email protected]) Herbert Bos Cristiano Giuffrida: vusec.net/projects/bhi-s…
Log4Harmony: we've heard that vulns in Android log device drivers are cool, so here are some UAF, race condition, and KASLR leak bugs in Huawei's hwlog from Gyorgy Miru (Gym), reachable from untrusted and isolated app: labs.taszk.io/blog/post/78_h… labs.taszk.io/blog/post/77_h… labs.taszk.io/blog/post/79_h…