home.social

#offensivecon — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #offensivecon, aggregated by home.social.

  1. Pwn2Own Berlin concludes with Singapore's STAR Labs claiming the "Master of Pwn" title and $320,000! Ethical hackers uncovered 28 zero-day vulnerabilities across AI platforms, virtualization software, and operating systems, demonstrating how security competitions drive industry improvement.

    #SecurityLand #News #Cybersecurity #Event #Pwn2Own #ZeroDay #Vulnerability #Research #OffensiveCon

    Read More: security.land/pwn2own-berlin-s

  2. CW: selfie ec

    Today was going for some don't-fuck-with-me outfit for #LobbyCon at #OffensiveCon :3

  3. CW: selfie ec

    Today was going for some don't-fuck-with-me outfit for #LobbyCon at #OffensiveCon :3

  4. While Zi Gan Tan walks the #OffensiveCon crowd through his Binder exploit, I’ve identified no less than 7 independent features in #grsecurity that break it:

    1/ slab merging is disabled by default and
    2/ AUTOSLAB makes it impossible to move any allocation into a kmalloc slab cache.
    3/ DYNORDER breaks moving free’d slab pages to a different cache easily as well as
    4/ our modifications to the free page buddy handling make it even harder to reallocate recently freed pages.
    5/ Type canaries detect the file related type confusion, breaking the leak primitive.
    6/ KERNSEAL will prevent messing with cred objects (they’re r/o), so does
    7/ CONSTIFY for selinux_state.

    #sad-state-of-android-security