Retired security engineer but still hacking when free+beer

Seoul, Korea
beist retweeted
It's BlackHat/DEF CON week so I'd like to interrupt your regularly scheduled chest drumming feed! Let's talk about a critical WiFi 7 memory corruption bug. The flaw was in Hostapd, the userland daemon which powers the world's WiFi on the majority of access points. I reported this in June and it's now patched upstream. My proof of concept shows that authenticated clients can bypass ASLR to leak pointers OTA and inject code execution. 802.1X Enterprise WiFi 7 is basically exploitable pre-auth because of the "outer tunnel". This bug was missed by LLM scans as well as human auditors, but found in the wifi gauntlet. If you're at BH/DC this week and interested in the memory safe wifi stack we're building please reach out
11
56
219
31,014
CODE BLUE, one of my favorite security conferences, is accepting talk proposals until July 31. If you have some interesting research or a fun topic to share, please submit it! And if you need another reason to come, Tokyo has plenty to offer: anime culture, great food with awesome beer, and an excellent environment for digital nomads. codeblue.jp/en/cfp/presentat…
3
12
976
SPR was designed specifically to eliminate these attacks. Almost all other WiFi deployments carry inherent disconnects between L2/L3 that enable MITM attacks and packet injection, whether EAP-TLS or WPA3.
1
4
3
1,130
Reminder we are looking for talented security researchers in all areas (iOS, Android, Browser, 0click, AI) 🚀🚀 DM me or shoot us an email at catalystsecurity.com 🦊
1
9
52
6,805
Anyone knows if there are any coworking spaces in Tokyo where the HotDesk (daily pass) seats come with chairs that have wheels and armrests? It would be even better if they also provide external monitors. At WeWork, I noticed HotDesk doesn’t have those kinds of chairs. Thank you!
1
4
892
Can’t believe it’s already been 6 months since I retired. Life after retirement hasn’t been about being “productive,” but about finally using my time however I want. Starting next month I’ll be in Japan, then heading over to Europe and Bangkok, I guess.
1
12
675
I keep up with security news, and I feel the itch to dive back into full-time research—but for now, I’m just enjoying the present. Haven’t really touched computers much, but lately I’ve been hacking about a few hour a week. Using AI to hunt for crashes is still a lot of fun.
8
489
beist retweeted
🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memo…
54
484
2,658
380,892
These days, when I see the results of bug hunting using AI, I truly feel glad that I retired early. Theori at aixcc: theori.io/blog/exploring-tra… Google big sleep: issuetracker.google.com/issu… Xbow: xbow.com/blog/top-1-how-xbow…
3
9
61
7,972
As a New Year resolution, consider applying to Project Zero :)
It doesn't happen very often, but Project Zero is hiring! goo.gle/41DBQBY Please share with anyone you think would be awesome for the role 🎉 Looking for at least one person. DMs open if you want to reach out about the role. The team: piped.video/My_13FXODdU
3
6
46
7,305
The Parallels VM escape bug reminds me of a bug I reported to VMware about two years ago. I was waiting until a patch was released before posting, but I ended up forgetting. Just an LPE bug on the host side, feel free to check it out if you're curious. (A colleague of mine forgot his MacBook password, so I discovered the bug in order to read the admin hash and crack it. He made a 'guest' account luckily before.) The diagram might look ugly, tho. PoC is available if you want, but it's a simple logic bug, so easy to exploit.
2
4
50
5,254
For a new setup (Mac mini and LG Dual-up display), I spent some hours and it’s pretty nice! Cursor so much helped me out crash prl_vm_app on the host side (Parallels VM escape). Have not finished the exploit yet but it’s likely exploitable. (Sorry, the cables are still messy.)
2
1
9
2,359
This is an older feature, but it's still one of my favorites in Parallels. Using the prlctl command, you can easily load snapshots right from the Terminal. (If you’re curious about any commands, ChatGPT provides great explanations!) Especially during kernel-level fuzzing, when the system tends to slow down significantly, it’s often more efficient to restore a snapshot than to perform a clean-up. The same applies to user-level fuzzing as well.
4
1,259
Google Tokyo office was amazing! Great food and view. And the location is golden. Thanks for feeding me! @kapitanpetko Probably I need another chance to visit there again for the party.
9
1,267
Who comes to PoC conference this year? Speaker list is here - powerofcommunity.net/speaker…
1
1
3,245
Tokyo is a paradise for hackers who love booze and bar bites. See you at CODEBLUE! codeblue.jp/2024/en/time_tab…
8
1,180