|
Andrea Fioraldi
@
andreafioraldi
Italy
|
|
Msc CE @ @SapienzaRoma CTF with @TheRomanXpl0it & @mhackeroni. malweisse on IRC. @cyberchallengIT @defcon11396 Binary stuffs, programming languages and fuzzing.
|
|
|
869
Tweetovi
|
387
Pratim
|
886
Osobe koje vas prate
|
| Tweetovi |
|
Andrea Fioraldi
@andreafioraldi
|
2 h |
|
Ok looking better at the implementation of QString is stack-use-after-scope for the same reason
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
3 h |
|
Here to see that midRef uses this: github.com/radekp/qt/blob…
Here to see how calls m_string->isNull() (where m_string is the freed Qstring ptr) code.woboq.org/qt5/qtbase/src…
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
3 h |
|
This triggers an heap-use-after-free ASan error.
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
3 h |
|
midRef creates a QStringRef using this (the QString instance). The QString instance is then freed cause its destructor is called and so in ref there is a QStringRef that maintains a ptr to freed memory. The ptr is not null, so it is dereferenced to call QString::isNull()
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
5 h |
|
The AFL++ website is up: aflplus.plus
Very naive ATM, I'm open to suggestions.
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
9 h |
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
10 h |
|
Electron apps should be banned by law. It is inammissibile that an XSS may lead to RCE w/ o exploiting any other bug. Js is not for desktop.
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
21 h |
|
Makes sense if incompatible with old GCCs.
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
22 h |
|
From a discussion with @MeBeiM , I noticed that this check in elixir.bootlin.com/linux/v4.20.17… was removed in the 5.x kernel. Does any kernel hacker know why?
Accessing the stack belop SP remains a bug IMO. pic.twitter.com/nbKf8LEHNf
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
4. velj |
|
Actually, the quote on the slide is wrong. It should be "Cryptography in CTF is about searching for the right paper" and it is 100% true.
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
4. velj |
|
Directly from the screens of the movie "hackers", we have a logo now twitter.com/domenuk/status…
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
3. velj |
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
2. velj |
|
This can't happen with Motherfucking CTF (github.com/andreafioraldi…) cause there isn't password recovery. If you lose a password while playing a CTF, you deserve to loose 😂 twitter.com/RiftWhiteHat/s…
|
||
|
|
||
| Andrea Fioraldi proslijedio/la je tweet | ||
|
CodeColorist
@CodeColorist
|
2. velj |
|
VSCode x @fridadotre
* VSCode based GUI
* Interactive terminal
* Remote file browser (Yes!)
* Open source
Not on market yet. But you can built it from the source:
github.com/chichou/vscode… pic.twitter.com/sG5UhDy2Wd
|
||
|
|
||
| Andrea Fioraldi proslijedio/la je tweet | ||
|
DC11396 • DEFCON Rome
@defcon11396
|
2. velj |
|
~~~~ Update ~~~~
The slides of this Friday's meeting are now online. Download them from the website or from GitHub (github.com/DefconRome/mee…)
/cc @defcon @defcongroups
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
31. sij |
|
This afternoon don't miss our talks about @fridadotre and the @gamozolabs recent work on MDS for CPU instrospection.
👉 defcon11396.it//meetings/meet… twitter.com/defcon11396/st…
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
30. sij |
|
Happy to announce a new LLVM instrumentation for AFL++ called CmpLog that feeds the fuzzer with comparisons operands extracted with SanCov.
github.com/vanhauser-thc/…
I used it to build the Redqueen mutator in AFL++!
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
30. sij |
|
So now we have also the power metal edition of mhackeroni/sourcloud. twitter.com/HackingForSoju…
|
||
|
|
||
|
Andrea Fioraldi
@andreafioraldi
|
30. sij |
|
Nice write-up! Note that the AFL++ laf-intel module can also split floating-point comparisons using AFL_LLVM_LAF_SPLIT_FLOATS.
This is available also in QEMU mode for x86/arm.
|
||
|
|
||
| Andrea Fioraldi proslijedio/la je tweet | ||
|
GitHub Security Lab
@GHSecurityLab
|
30. sij |
|
Do you know #aflplusplus? It brings interesting add-ons to AFL. @nosoynadiemas used it during his fuzzing research to create custom instrumentation whitelists, increasing AFL code coverage securitylab.github.com/research/fuzzi…
|
||
|
|
||