Security
Hacking everything, by Chris Evans / scarybeasts
Monday, June 19, 2017
Introducing Qualys Project Zero?
›
Google's Project Zero team was announced in July 2014 . Since then, it has become very well known for publishing offensive security rese...
1 comment:
Friday, May 19, 2017
*bleed, more powerful: dumping Yahoo! authentication secrets with an out-of-bounds read
›
Overview In my previous post on Yahoobleed #1 (YB1) , we saw how an uninitialized memory vulnerability could lead to disclosure of private...
1 comment:
Thursday, May 18, 2017
*bleed continues: 18 byte file, $14k bounty, for leaking private Yahoo! Mail images
›
Overview *bleed attacks are hot right now. Most notably, there's been Heartbleed and Cloudbleed . In both cases, out-of-bounds reads ...
2 comments:
Wednesday, May 17, 2017
Further hardening glibc malloc() against single byte overflows
›
Introduction Back in 2014, while at Project Zero, I exploited a buffer overflow of a single NUL byte in glibc . Tavis Ormandy had found th...
2 comments:
Monday, May 15, 2017
Are we doing memory corruption mitigations wrong?
›
Introduction Before we get into it, let's start by stating that the progression of memory corruption mitigations over the years has be...
4 comments:
Thursday, May 11, 2017
[0day] Proving Box.com fixed ASLR via ImageMagick uninitialized zlib stream buffer
›
Overview In my previous post, we explored using an ImageMagick 0day (now a 1day) in the RLE decoder to to determine missing ASLR in both...
Wednesday, May 10, 2017
Proving missing ASLR on dropbox.com and box.com over the web for a $343 bounty :D
›
Overview Cloud file storage providers such as Box and DropBox will typically thumbnail uploaded images for purposes of showing icons and p...
1 comment:
‹
›
Home
View web version