New blog post written together with my friend @S0rryMybad about using the JIT to abuse a non-JIT bug in Chakra (CVE-2019-0812) phoenhex.re/2019-05-15/non…
I published the slides of the presentation I gave @BlueHatIL and @offensive_con about Attacking Edge through the JIT compiler. I also contains exploit code for CVE-2018-8266 github.com/bkth/Attacking…
My #pwn2own exploit chain from this year, essentially 3 logic bugs to go from Safari to kernel on macOS up to 10.13.3, is now open source: github.com/saelo/pwn2own2…. The README also links to a few slide decks which contain some more background information :)
Today we have a short new blog post about CVE-2018-4358, an infoleak bug in Safari found by @bkth_@5aelo and @_niklasb that got patched by Apple in their last updates: phoenhex.re/2018-09-26/saf…
First #Hack2win eXtreme winners, @_niklasb@bkth_@5aelo, 3 categories: Firefox RCE, Firefox InfoLeak and Chrome RCE, beautifully done, for a total prize of 170,000$USD. Still have 330,000$USD to give out to anyone that can show their skills - disclosure soon via @SecuriTeam_SSD
New blog post: Fuzzing the CS:GO map file loader with AFL in QEMU mode. Includes full fuzzing harness + triaging tools to reproduce. Will still find heap overflows, because Valve says these are not security issues :> So get yourself some 0days now! phoenhex.re/2018-08-26/csg…
I added a PKGBUILD to get a full debug build of the latest VirtualBox version for Arch Linux, with the 3D security fixes from July reverted: github.com/niklasb/3dpwn/…
I published a small Python Linux library for experimenting with HGCM and VBoxSharedCrOpenGL (3D accel) from a VirtualBox guest. Includes a full exploit for CVE-2018-30{55,85} demonstrating some useful heap exploitation techniques for the 3D component github.com/niklasb/3dpwn
385 Followers 1K FollowingInterested in Software Security | Life Long Learner | Love to learn, how things work under the hood | Always Philosophically intrigued.