TGViewer
Linux Kernel Security Linux Kernel Security @linkersec · 4.74K subscribers
Post #28 859
Brandon Falk continues hacking an old Motorola phone

The first two streams that included writing a kernel exploit to get arbitrary code execution were posted above. These few cover extracting a phone snapshot including all physical memory and register states and running it in QEMU. The streams are quite long, but can be partially skipped through to get an idea of what he's doing.

Stream 3: https://www.youtube.com/watch?v=RLzZPSPI8ds
Stream 4: https://www.youtube.com/watch?v=NJjpkzuc1k4
Stream 5, part 1: https://www.youtube.com/watch?v=6TzdYokXoF8
Stream 5, part 2: https://www.youtube.com/watch?v=hlW8ktQkyPA
Stream 6: https://www.youtube.com/watch?v=kATF_EIltHc
YouTube Dumping register and physical memory state with our Android exploit In this video we dump register and physical memory state "atomically" from the kernel with our exploit to get ready to lift the kernel into QEMU for fuzzing or analysis.
More from @linkersec
  1. Sep 28, 2026PageJack in Action: CVE-2022-0995 exploit Article by Jean Vincent describing how a relativ…
  2. Sep 21, 2026CROSS-X: Generalized and Stable Cross-Cache Attack on the Linux Kernel Paper by Dong-ok Ki…
  3. Sep 16, 2026Testing race conditions with memory access tracing and stack-based delay injection Article…
  4. Sep 8, 2026SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free Article about exploiting C…
  5. Aug 14, 2026Gone in 60 Frames – USB Video Exploitation Article (and slides) by Alex Plaskett and Rober…
  6. Aug 11, 2026IonStack part III: Rooting Android 17 with GhostLock Article about adapting the exploit of…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →