Vulnerability Researcher

Seoul
KISA recently released decryptor tool for victims of #rhysida #ransomware. @CISACyber @CISAgov @FBI seed.kisa.or.kr/kisa/Board/1…
264
Figure out that AFL use the branch hit count for calculating coverage. It’s really novel idea.
Windows CVE-2020-1034 LPE Exploit
1
Made it. My #AFL can fuzz command-line arguments on binary mode. Let’s fuzz it.
This result in a single library file being split into more multiple memory region for the purpose.
1
Anyway, The mutation algorithm of AFL fuzzer is optimized for file input. This is because the first funtion is bitflip.
1
AFL_PRELOAD is useful environment value when fuzzing command-line binary on qemu mode.
If an error occurs while compiling qemu for #AFL, Check it out this. mail-archive.com/debian-bugs…
1
Enforcing Type confusion in memory also uses ie vbscript #exploitation case. Depending on what target memory can be manipulated, the reliability of the exploit increases. good blog post for iOS example. googleprojectzero.blogspot.c…
1
Some Linux binary has a extra space at the end of function. #radare2 is rarely unable to identify the end of function when processing disassembly.
Memory allocator of android 11 fully moved over to scudo. heap is getting hardening.
1
If a file viewer/editor program adds an exploit mitigation(aslr,dep), the attempts to find memory corruption are significantly lower. Even through it is exploited, exploit is typically less reliable. There are few elements that can make a memory leak.
Broken phishing email accidentally reveal 0-day as well. isc.sans.edu/forums/diary/Br…
Sometimes pin tool can't find end of routine during static analysis as rtn callback. So They suggest analysing rtn at runtime.
When intel #pintool disassemble xor ax, ax it returns weird value. The result is data16 nop.
1
Arbitrary R/W comes from not only vulnerability ifself but also exploit primitives.
Webkit added auditStructureID in FunctionPrototype.cpp to prevent structureID leak. github.com/WebKit/webkit/com…
3