jeff (@jeffssh) 's Twitter Profile
jeff

@jeffssh

Forever standing on the shoulders of giants

ID: 1011304122182758406

linkhttps://jeffs.sh calendar_today25-06-2018 17:44:26

95 Tweet

889 Takipçi

281 Takip Edilen

jeff (@jeffssh) 's Twitter Profile Photo

Rough copy of the FORCEDENTRY code is now available. Most relevant code is here: github.com/jeffssh/CVE-20… Blog soon!

Anthony Weems (@amlweems) 's Twitter Profile Photo

I've been reverse engineering the xz backdoor this weekend and have documented the payload format and written a proof-of-concept exploit for the RCE. The payloads are signed with an ED448 key, so I patched my own key into the backdoor for testing. :-) github.com/amlweems/xzbot

I've been reverse engineering the xz backdoor this weekend and have documented the payload format and written a proof-of-concept exploit for the RCE. The payloads are signed with an ED448 key, so I patched my own key into the backdoor for testing. :-)

github.com/amlweems/xzbot
r3tr074 (@r3tr074) 's Twitter Profile Photo

Allocating new exploits Pwning browsers like a kernel & Digging into PartitionAlloc and Blink engine phrack.org/issues/71/10.h…

Disconnect3d (@disconnect3d_pl) 's Twitter Profile Photo

Pwndbg 2025.01 is out! It adds official LLDB support including support for macOS and Mach-O binaries, improved performance, enhanced embedded debugging & many more! Also, want to support us or buy us a coffee? See our GH sponsors: github.com/sponsors/pwndbg github.com/pwndbg/pwndbg/…

Adam Crosser (@unc1739) 's Twitter Profile Photo

I'm thrilled to announce that my talk Ghost Calls: Abusing Web Conferencing for Covert Command & Control was accepted to #BHUSA 2025 (CC: Black Hat) blackhat.com/us-25/briefing…

chompie (@chompie1337) 's Twitter Profile Photo

Me and the homies are dropping browser exploits on the red team engagement 😎. Find out how to bypass WDAC + execute native shellcode using this one weird trick -- exploiting the V8 engine of a vulnerable trusted application. ibm.com/think/x-force/…

Brendan Dolan-Gavitt (@moyix) 's Twitter Profile Photo

As the operator of a soup kitchen, I don’t see why I should be expected to fix health code violations people report. After all, we are run almost entirely by volunteers

Seth Jenkins (@__sethjenkins) 's Twitter Profile Photo

We really should be talking about this more....KASLR is just not working properly on Android right now, and it hasn't for a long time. googleprojectzero.blogspot.com/2025/11/defeat…

cts🌸 (@gf_256) 's Twitter Profile Photo

speedrunners reinvented Use After Free and called it "stale reference manipulation" one day theyre gonna invent type confusion and call it item abuse

speedrunners reinvented Use After Free and called it "stale reference manipulation"

one day theyre gonna invent type confusion and call it item abuse