Post #1181
192
Channel Public Channel
AL Alaid TechThread
@offensive_thread
Vulnerability discovery, threat intelligence, reverse engineering, AppSec
- Subscribers
- 1.14K
- Photos
- 7
- Videos
- 2
- Links
- 1.4K
Showing posts older than #1182 · Back to latest
Older Posts 20 shown
Post #1180
98
TCP/IP Vulnerability CVE-2022–34718 PoC Restoration and Analysis
https://medium.com/@numencyberlabs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf
https://medium.com/@numencyberlabs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf
- 👍 1
Post #1179
81
Concurrence: library for fuzzing multi-threaded targets
https://github.com/googleprojectzero/SockFuzzer/tree/main/third_party/concurrence
https://github.com/googleprojectzero/SockFuzzer/tree/main/third_party/concurrence
Post #1178
95
FixReverter: A Realistic Bug Injection Methodology for Benchmarking Fuzz Testing
https://www.usenix.org/system/files/sec22-zhang-zenong.pdf
https://www.usenix.org/system/files/sec22-zhang-zenong.pdf
Post #1177
87
Post #1176
69
Microsoft fixes driver blocklist placing users at risk from BYOVD attacks
https://www.malwarebytes.com/blog/news/2022/10/microsoft-fixes-driver-blocklist-placing-users-at-risk-from-byovd-attacks
https://www.malwarebytes.com/blog/news/2022/10/microsoft-fixes-driver-blocklist-placing-users-at-risk-from-byovd-attacks
Post #1175
66
Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect
SQL and Command Injection Vulnerabilities
https://pagabuc.me/docs/oakland23_witcher.pdf
SQL and Command Injection Vulnerabilities
https://pagabuc.me/docs/oakland23_witcher.pdf
- 👍 1
Post #1174
80
A journey of fuzzing Nvidia graphic driver leading to LPE exploitation
https://drive.google.com/file/d/1HEaQ3o1kSnrzMCec1aiYMkWYQZg7Vjb3/view
https://drive.google.com/file/d/1HEaQ3o1kSnrzMCec1aiYMkWYQZg7Vjb3/view
Post #1173
82
Post #1171
82
Post #1170
73
RedEye is a visual analytic tool supporting Red & Blue Team operations
https://github.com/cisagov/RedEye/
https://github.com/cisagov/RedEye/
Post #1169
76
CONFETTI: Amplifying Concolic Guidance for Fuzzers
https://www.youtube.com/watch?v=4WOPUFNeZXg
https://srg.doc.ic.ac.uk/klee22/talks/Kukucka-Confetti.pdf
YouTube CONFETTI: Amplifying Concolic Guidance for Fuzzers James Kukucka from George Mason University at the 3nd International KLEE Workshop on Symbolic Execution
KLEE Workshop 2022: https://srg.doc.ic.ac.uk/klee22/
Slides: https://srg.doc.ic.ac.uk/klee22/talks/Kukucka-Confetti.pdf https://www.youtube.com/watch?v=4WOPUFNeZXg
https://srg.doc.ic.ac.uk/klee22/talks/Kukucka-Confetti.pdf
Post #1168
116
Making Fuzzing Part of Your Software Development Lifecycle
https://www.youtube.com/watch?v=eg7SiXr31Qk
YouTube Making Fuzzing Part of Your Software Development Lifecycle - Jonathan Metzman, Google Making Fuzzing Part of Your Software Development Lifecycle - Jonathan Metzman, Google
Fuzzing is a testing technique that uses randomized inputs to find bugs in software. Fuzzing is the most successful automated vulnetability/bug-finding technique and has… https://www.youtube.com/watch?v=eg7SiXr31Qk
Post #1167
70
Fuzzing Host-to Guest Attack Surface in Android Protected KVM
https://www.youtube.com/watch?v=cJjjlSG6JEA
YouTube Fuzzing Host-to Guest Attack Surface in Android Protected KVM- Eugene Rodionov & Will Deacon, Google Fuzzing Host-to Guest Attack Surface in Android Protected KVM - Eugene Rodionov & Will Deacon, Google
Android 13 introduces native support of virtualization services built on top of Protected KVM (pKVM) for arm64 devices. Unlike in traditional KVM where… https://www.youtube.com/watch?v=cJjjlSG6JEA
Post #1166
111
Jit-Picking: Differential Fuzzing of JavaScript Engines
https://publications.cispa.saarland/3773/1/2022-CCS-JIT-Fuzzing.pdf
https://publications.cispa.saarland/3773/1/2022-CCS-JIT-Fuzzing.pdf
Post #1165
129
Attacking Firecracker: AWS' microVM Monitor Written in Rust - https://www.graplsecurity.com/post/attacking-firecracker
SecOps Insights Firecracker Security: How Does microVM Isolation Really Work? Why are more security teams adopting Firecracker? How secure is it, and how suitable is it for your organization? This guide dives into this trending innovation. Post #1164
140
Post #1163
148
Jazzer.Js Brings Fuzzing To JavaScript
https://www.code-intelligence.com/blog/jazzer.js
https://github.com/CodeIntelligenceTesting/jazzer.js
https://www.code-intelligence.com/blog/jazzer.js
https://github.com/CodeIntelligenceTesting/jazzer.js
Post #1162
160
eBPF ELFs JMPing Through the Windows - https://i.blackhat.com/USA-22/Thursday/US-22-Johnson-eBPF-ELFs-JMPing-Through-the-Windows.pdf
- 👎 1
Post #1161
126
Another Way to Talk with Browser: Exploiting Chrome at Network Layer - https://i.blackhat.com/USA-22/Thursday/US-22-Rong-Another-Way-to-Talk-with-Browser-Exploiting-Chrome-at-Network-Layer.pdf