Karsten
@gr4yf0x.bsky.social
๐ค 113
๐ฅ 174
๐ 22
VR. Can cook a decent Cacio e Pepe. Physicist in a former life.
reposted by
Karsten
Nathan Hamiel
5 months ago
The next battleground is in sight, and things are going to move fast. Half-baked tech pitched as transformational will be quickly adopted and thrown in front of children without any validation, but the demos will be amazing!
0
6
2
reposted by
Karsten
Dan Veditz
5 months ago
We just published
@firefox.com
updates to fix the exploits used at the Pwn2Own contest yesterday and today. Both contestants achieved RCE in our content process but did not escape the sandbox.
blog.mozilla.org/security/202...
loading . . .
Firefox Security Response to pwn2own 2025 โ Mozilla Security Blog
At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature ...
https://blog.mozilla.org/security/2025/05/17/firefox-security-response-to-pwn2own-2025/
3
24
9
reposted by
Karsten
OffensiveCon
5 months ago
Itโs only Tuesday but the first night of Lobbycon has already started! ๐ป
0
7
1
reposted by
Karsten
OffensiveCon
5 months ago
the takeover has begun.. trainings start tomorrow morning!
0
12
2
reposted by
Karsten
Phrack Zine
5 months ago
RUMOURS are TRUE ๐คทโโ๏ธ PHRACK will be releasing a SPECIAL #71.5 ๐HARDCOVER๐ at
www.offensivecon.org
BERLIN ("The ๐ -Day Edition"). Main #72 release THIS SUMMER at MULTIPLE conferences (main release at WHY2025). โค๏ธ
1
13
5
reposted by
Karsten
OffensiveCon
5 months ago
2025 agenda is out!
www.offensivecon.org/agenda/2025....
0
9
8
reposted by
Karsten
myrmepropagandist
6 months ago
To prevent deer from being hit by cars Finland has tried using reflective paint. (
https://www.smithsonianmag.com/smart-news/avoid-deer-strikes-finland-painting-deer-antlers-reflective-paint-180949792/
) File this under "solutions to modern problems that summon the old gods."
52
4023
1268
reposted by
Karsten
dmnk
6 months ago
Still adding people as they wash up here
go.bsky.app/EhGFSVj
add a skeleton here at some point
1
12
1
reposted by
Karsten
6 months ago
The BlackHoodie training at OffensiveCon has a whole of 2 seats left, and we will have a special give-away with this edition :)
blackhoodie.re/Offensivecon...
loading . . .
Blackhoodie OffensiveCon 2025
Hackers around the globe, listen, BlackHoodie will be at OffensiveCon this year :) For the very first time weโre offering a 1-day free training, for women, by women, at the most prestigious offensive ...
https://blackhoodie.re/Offensivecon2025/
0
6
5
reposted by
Karsten
Phrack Zine
6 months ago
Don't forget, the CFP for the 40th anniversary issue of Phrack is open until June 15th 2025. You can be someone's favorite article in the future!!
bsky.app/profile/phra...
add a skeleton here at some point
0
7
10
reposted by
Karsten
6 months ago
Save the date -
@blackhoodie.bsky.social
is partnering with
@offensivecon.bsky.social
this year to bring a BlackHoodie training to Berlin! Students will learn how to place compiler backdoors in innocent code. Mark your calendars for May 15th! Registration opens tomorrow, space is very limited โบ๏ธ
0
7
7
reposted by
Karsten
jduck
6 months ago
Happy to share my slides from BOOTSTRAP25. Unfortunately the bug discussed is still not patched in Linux 6.14.0 despite it being reported explicitly. Slides are in markdown but there's a PDF in "releases" too
github.com/jduck/bs25-s...
loading . . .
GitHub - jduck/bs25-slides: Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25
Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25 - jduck/bs25-slides
https://github.com/jduck/bs25-slides
1
14
7
reposted by
Karsten
OffensiveCon
6 months ago
We are proud to announce our first keynote for Offensivecon 2025, Perri Adams!
@perrib.us
0
12
3
reposted by
Karsten
OffensiveCon
6 months ago
Our second keynote for Offensivecon 2025 will be Dino Dai Zovi!
@ddz.bsky.social
0
9
4
Must be
@argp.bsky.social
and karl's article on the FreeBSD kernel allocator. The first one I worked really through, introduced me to kernel exploitation, and finally helped me with my first real exploit for FreeBSD-SA-19:02.fd.
phrack.org/issues/66/8#...
add a skeleton here at some point
6 months ago
0
6
1
Good analysis by the syzkaller developer, how some of thr latest ITW vulns could have been found.
add a skeleton here at some point
7 months ago
0
1
0
Pumpkin (@u1f383 on X) does cool work. Here is another cool read about an interesting race condition involving signal handling
u1f383.github.io/linux/2025/0...
add a skeleton here at some point
7 months ago
0
4
4
Really great read by @h0mbre (on X) about his journey to exploit a Linux n-day on kCTF. Not only the exploit but the process to understand the bug including own failures, e.g. deal with CONFIG_DEBUG_LIST, is full of insights.
h0mbre.github.io/Patch_Gappin...
loading . . .
Patch-Gapping the Google Container-Optimized OS for $0
Background Iโm trying to really focus this year on developing technically in a few ways. Part of that is reviewing kCTF entries. This helps me get a sense of what subsystems are producing the most bug...
https://h0mbre.github.io/Patch_Gapping_Google_COS/
8 months ago
0
2
2
reposted by
Karsten
Phrack Zine
8 months ago
Hackers rejoice! We are releasing the Phrack 71 PDF for you today! Don't forget this year is Phrack's 40th anniversary release! Send in your contribution and be part of this historical issue! The CFP is still open, you can find it and the PDF link at
phrack.org
loading . . .
.:: Phrack Magazine ::.
Phrack staff website.
https://phrack.org
2
63
34
reposted by
Karsten
OffensiveCon
9 months ago
To all our Bluesky friends, feel free to follow us here as we will be posting regular updates as the conference gets closer. See you in May!
0
8
3
Thank you
@phrack.org
!
9 months ago
0
3
0
As of today I'm not longer with CrowdStrike. Looking forward to new challenges in VR :)
9 months ago
1
5
0
Can recommend Satoshi's training as well, rarely had a training that was such hands-on.
add a skeleton here at some point
10 months ago
0
1
1
reposted by
Karsten
buherator
10 months ago
[RSS] Linux Kernel: TOCTOU in Exec System
github.com ->
Original->
0
2
1
Creative vuln research by Eloi (@elvanderb on X) on XNU logic bugs
t.co/Z3ktOkj6Gi
loading . . .
https://www.synacktiv.com/sites/default/files/2024-11/finding_and_exploiting_an_old_xnu_logic_bug.pdf
https://t.co/Z3ktOkj6Gi
10 months ago
0
3
1
Cool idea. Artists under the Taylor Swift level usually get their money through album sales and merch, maybe concerts only.
add a skeleton here at some point
11 months ago
0
0
0
reposted by
Karsten
buherator
11 months ago
I really like the idea of Bandcamp Gift Cards! Get your friends and family hooked on supporting independent artists/small labels!
https://bandcamp.com/gift_cards
Original->
0
2
2
Interesting paper by Erin Avllazagaj to automatically find Linux kernel objects being potentially useful for privilege escalation, tool is called SCAVY.
www.usenix.org/system/files...
loading . . .
https://www.usenix.org/system/files/usenixsecurity24-avllazagaj.pdf
11 months ago
0
5
2
reposted by
Karsten
dmnk
11 months ago
Slides for my @ekoparty talk "Advanced Fuzzing With LibAFL" - >
docs.google.com/presentation...
loading . . .
Advanced Fuzzing With LibAFL @ Ekoparty 2024
Advanced Fuzzing With LibAFL Dominik Maier Ekoparty 2024-11-15 1
https://docs.google.com/presentation/d/1ILXdsBx6JJbsf3uq-_hSeYux-a0DRRPxebOY65EDE5o/edit?usp=sharing
0
44
22
reposted by
Karsten
Phil Stokes โซ๐ โซ
11 months ago
All the recordings from
#r2con2024
. ๐คฉ ๐
radare.org/con/2024/
loading . . .
https://radare.org/con/2024/
0
11
7
Custom Linux kernel fuzzing with libFuzzer by
@r00tkitsmm.bsky.social
r00tkitsmm.github.io/fuzzing/2024...
loading . . .
Structure-Aware linux kernel Fuzzing with libFuzzer
Hi everyone! Iโm really happy to tell you about my experimenting adventure today. I decided to experiment with KCOV and see how I can hook it into libfuzzer and boot the kernel without spending too mu...
https://r00tkitsmm.github.io/fuzzing/2024/03/27/libffuzzerkernel.html
11 months ago
0
5
2
Let's give this network a second chance and see if critical mass is hit.
11 months ago
0
1
0
you reached the end!!
feeds!
log in