Jens Müller (@jensvoid) 's Twitter Profile
Jens Müller

@jensvoid

Hack the Planet! On a #yolo trip around the word during a pandemic.
Involved in hacking-printers.net, #efail, #pdfex. Raw tech. No chit-chat.

ID: 1300837339

linkhttps://www.nds.rub.de/chair/people/jmueller/ calendar_today25-03-2013 19:37:45

231 Tweet

1,1K Takipçi

224 Takip Edilen

Jens Müller (@jensvoid) 's Twitter Profile Photo

Together with @murgi, @chearix, vladislav mladenov, Sebastian Schinzel @[email protected], and @joergschwenk, we had a look at the capabilities of malicious OOXML and ODF documents, resulting in a WOOT Paper: usenix.org/system/files/w… | Artifacts: github.com/RUB-NDS/Office…

Jens Müller (@jensvoid) 's Twitter Profile Photo

You can even leak complete directories in some mail clients. Interestingly, Evolution shows a warning if you want to include a single file, but the full home directory is fine. (2/4)

Jens Müller (@jensvoid) 's Twitter Profile Photo

Such *simple stupid* mailto:?attach tricks worked in Thunderbird for Debian, GNOME Evolution (CVE-2020-11879), KDE KMail (CVE-2020-11880), IBM/HCL Notes (CVE-2020-4089), and Pegasus Mail. (3/4)

Jens Müller (@jensvoid) 's Twitter Profile Photo

This flaw, among others, is described in our IEEE CNS paper "Mailto: Me Your Secrets. On Bugs and Features in Email End-to-End Encryption" with -, Damian Poddebniak, Sebastian Schinzel @[email protected], and @joergschwenk: nds.ruhr-uni-bochum.de/media/nds/vero… (4/4)

Albert Astals Cid (@tsdgeos) 's Twitter Profile Photo

James Henstridge Jens Müller Yes. See me other answer, for some reason this escaped KDE Security Team radar and i thought it had not been reported to KDE while it had indeed been.

- (@lambdafu) 's Twitter Profile Photo

We found another flaw in the design of TLS! If you have servers that share certificates across services you might want to take a look at this: alpaca-attack.com. 🧵👇

We found another flaw in the design of TLS! If you have servers that share certificates across services you might want to take a look at this: alpaca-attack.com. 🧵👇
Black Hat (@blackhatevents) 's Twitter Profile Photo

- & juraj somorovsky evaluate the real-world attack surface of web browsers and widely-deployed email and FTP servers in lab experiments and with internet-wide scans in this #BHUSA Briefing informatech.co/3cy70QQ

heise Security (@heisec) 's Twitter Profile Photo

Angreifer könnten digitale Unterschrift in LibreOffice und OpenOffice fälschen heise.de/news/Angreifer… #LibreOffice #OpenOffice

Jens Müller (@jensvoid) 's Twitter Profile Photo

Lol. HackenProof a reputable bug bounty platform sends out invites for their program to attack Russian critical infrastructure (SCADA, banks, energy). Crazy times & Happy hunting. #StandingWithUkraine hackenproof.com/ukraine-will-w…