sobota, 24 kwietnia 2021

Returning root to userland

Since last few days I was reading a little bit more about kernel exploitation. One of the resources I found[1,2,3] was "good enough" (for me ;)) to follow it and recreate the steps on my own VM machine. Vulnerable challenge - described here by Midas - was a one presented on hxpCTF 2020 - 'kernel-rop'. Below you'll find a "quick autopsy" (but I like to think about it like a note for the 'future me' ;)). Here we go...

sobota, 10 kwietnia 2021

FuzzLabs vs Acme CAD Converter

Hi ;) since last week I tried to prepare another article for the upcomoing 'Notes Magazine' (#07) - this time related to the fuzzing. My goal was to prepare a sample fuzzer and grab few new bugs. Below you'll find few of the "very first results". Here we go...