Sign in

Alex Plaskett

@alexplaskett.bsky.social
407 followers 122 following 52 posts

Security Researcher | Pwn2Own 2018, 2021, 2022, 2024 | Posts about 0day, OS, mobile and embedded security.

PostsRepliesMedia
Reposted by Alex Plaskett
Catalin Cimpanu @campuscodi.risky.biz · 11/05/2025
Chinese robot maker Unitree has removed a problematic component from the firmware of its Go1 robot dog that could have allowed remote attackers to take over the robot www.scmp.com/tech/tech-tr...
scmp.com
China’s Unitree fixes flaw that gives hackers remote control of robots
The start-up has downplayed the impact of the vulnerability, noting that the affected model has been discontinued.
2116
Reposted by Alex Plaskett
OffensiveCon @offensivecon.bsky.social · 11/05/2025
the takeover has begun.. trainings start tomorrow morning!
0122
Reposted by Alex Plaskett
jduck @jduck.me · 25/03/2025
Happy to share my slides from BOOTSTRAP25. Unfortunately the bug discussed is still not patched in Linux 6.14.0 despite it being reported explicitly. Slides are in markdown but there's a PDF in "releases" too github.com/jduck/bs25-s...
github.com
GitHub - jduck/bs25-slides: Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25
Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25 - jduck/bs25-slides
1147
Reposted by Alex Plaskett
afd-icl.bsky.social @afd-icl.bsky.social · 14/01/2025
Delighted that our paper on "Grammar mutation for testing input parsers" - led by Bachir Bendrissou and joint with @ccadar.bsky.social - is now published in ACM TOSEM! This came from a registered report at FUZZING. Check it out! doc.ic.ac.uk/~afd/papers/...
doc.ic.ac.uk
1146
Reposted by Alex Plaskett
Phrack Zine @phrack.org · 13/03/2025
Reminder that the Phrack 72 CFP closes APRIL 1ST 2025. Get your papers in and come be a part of our fabulous 40th anniversary issue! See phrack.org for more info
Phrack Graffiti Logo
02717
Reposted by Alex Plaskett
tmp0ut @tmpout.sh · 21/03/2025
Would you look at that, it's tmp.0ut Volume 4! Happy Friday, hope you enjoy this latest issue! tmpout.sh/4/
table of contents for tmp.0ut volume 4
212163
Reposted by Alex Plaskett
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 28/02/2025
Only a week and a half left for USENIX WOOT '25 conference submissions - deadline March 11 AoE. We’re looking forward to seeing even more of your amazing offensive security papers this year! And still a few days for up-and-coming track (March 4). CfP at www.usenix.org/conference/w...
0510
Reposted by Alex Plaskett
Renaud Lifchitz ⠵ @nono2357.bsky.social · 20/02/2025
We discover 119 vulnerabilities in LTE/5G core infrastructure, each of which can result in persistent denial of cell service to an entire metropolitan area or city and some of which can be used to remotely compromise and access the cellular core. cellularsecurity.org/ransacked
02210
Reposted by Alex Plaskett
Daniel Cuthbert @dcuthbert.bsky.social · 16/02/2025
I watch and read and I’ve seen a manner research. But this research into visualising Wi-Fi signals using an array of ESP32 chips is something else. www.youtube.com/watch?v=sXwD... It is that good. That deep and frankly so out there and he calls himself a mediocre engineer too. WTF? Blown away.
youtube.com
This ESP32 Antenna Array Can See WiFi
YouTube video by Jeija
6309
Reposted by Alex Plaskett
Phrack Zine @phrack.org · 15/02/2025
Hackers rejoice! We are releasing the Phrack 71 PDF for you today! Don't forget this year is Phrack's 40th anniversary release! Send in your contribution and be part of this historical issue! The CFP is still open, you can find it and the PDF link at phrack.org
phrack.org
.:: Phrack Magazine ::.
Phrack staff website.
26232
Reposted by Alex Plaskett
dragosr @dragostech.bsky.social · 05/02/2025
Update your AMD Zen processor's BIOS: www.amd.com/en/resources... Check with your OEM for BIOS updates with the new microcode patches, they have had some time to address this high importance item.
amd.com
035
Reposted by Alex Plaskett
Zion Leonahenahe Basque @mahal0z.bsky.social · 29/01/2025
2024 was a significant year for decompilation, constituting a possible resurgence in the field. Major talks, the thirty-year anniversary of research, movements in AI, and an all-time high for top publications in decompilation. Join me for a retrospective: mahaloz.re/dec-progr...
mahaloz.re
Decompiling 2024: A Year of Resurgance in Decompilation Research
The year 2024 was a resurgant year for decompilation. Academic publications from that year made up nearly 30% of all top publications ever made in decompilat...
0229
Reposted by Alex Plaskett
Natalie Silvanovich @natashenka.bsky.social · 10/01/2025
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click project-zero.issues.chromium.org/issues/36869...
project-zero.issues.chromium.org
Project Zero
13816
Reposted by Alex Plaskett
Nicolas Grégoire @agarri.fr · 10/01/2025
OMG, Orange Tsai released his latest new research 🤯 💣 blog.orange.tw/posts/2025-0...
blog.orange.tw
WorstFit: Unveiling Hidden Transformers in Windows ANSI!
📌 This is a cross-post from DEVCORE. The research was first published at Black Hat Europe 2024. Personally, I would like to thank splitline, the co-author of this research & article, whose help
33420
Alex Plaskett @alexplaskett.bsky.social · 26/12/2024
Looking through the schedule of #38c3 which starts tomorrow. Some talks I’ll be watching the streams for this year: ACE up the sleeve: Hacking into Apple's new USB-C Controller fahrplan.events.ccc.de/congress/202... Liberating Wi-Fi on the ESP32 fahrplan.events.ccc.de/congress/202...
fahrplan.events.ccc.de
ACE up the sleeve: Hacking into Apple's new USB-C Controller 38C3
With the iPhone 15 & iPhone 15 Pro, Apple switched their iPhone to USB-C and introduced a new USB-C controller: The ACE3, a powerful, very custom, TI manufactured chip. But the ACE3 does more than ju...
2133
Alex Plaskett @alexplaskett.bsky.social · 23/12/2024
vacation reading material acquired!
050
Alex Plaskett @alexplaskett.bsky.social · 23/12/2024
Pretty interesting technique used by _mccaulay here to understand the heap better and aid exploitation of a TP-Link vulnerability! www.nccgroup.com/uk/research-...
031
Reposted by Alex Plaskett
Phrack Zine @phrack.org · 16/12/2024
We updated our CFP for Phrack 72! The deadline is now April 1st 2025. Check the site for specifics on how to contribute, as well as some inspiration! We also posted a link to purchase physical copies of Phrack 71, and a donation link too. Enjoy! phrack.org
screenshot of the CFP on phrack.org
411658
Reposted by Alex Plaskett
Ken Shirriff @righto.com · 06/12/2024
Intel launched the Pentium processor in 1993. Unfortunately, dividing sometimes gave a slightly wrong answer, the famous FDIV bug. Replacing the faulty chips cost Intel $475 million. I reverse-engineered the circuitry and can explain the bug. 1/9
A die photo of the Pentium processor with the main functional blocks labeled including the caches, instruction fetch and decode, integer execution, and floating point. The image consists of complex patterns of rectangular regions in reddish and brownish colors. The image zooms in on a small part of the floating point unit giving a detail of an adder and PLA circuit.
16708236
Reposted by Alex Plaskett
Piotr Bazydło @chudypb.bsky.social · 12/12/2024
I wrote a fun, little blog post. Remote pre-auth file deletion in SolarWinds ARM allowed to achieve LPE on AD machines 🙃
196
Reposted by Alex Plaskett
Catalin Cimpanu @campuscodi.risky.biz · 12/12/2024
A PoC for that Cleo zero-day is now live: labs.watchtowr.com/cleo-cve-202...
labs.watchtowr.com
Cleo Harmony, VLTrader, and LexiCom - RCE via Arbitrary File Write (CVE-2024-50623)
Note: this is a rapidly-drafted post on an evolving topic - we'll update the post with more details as we discover more about the situation. Hit that F5 key regularly for updates! We were having a ...
0128
Reposted by Alex Plaskett
dragosr @dragostech.bsky.social · 12/12/2024
New DCOM lateral movement technique discovered that bypasses traditional defenses. Unlike previous attacks relying on IDispatch interfaces, this method exploits undocumented COM interfaces within MSI, specifically targeting IMsiServer and IMsiCustomAction interfaces. 1/7
deepinstinct.com
Forget PSEXEC: DCOM Upload & Execute Backdoor
Join Deep Instinct Security Researcher Eliran Nissan as he exposes a powerful new DCOM lateral movement attack that remotely writes custom payloads to create an embedded backdoor.
22117
Reposted by Alex Plaskett
Laurent Clévy @lorenzo2472.bsky.social · 10/12/2024
Course materials for Modern Binary Exploitation by RPISEC github.com/RPISEC/MBE?s... via @alexplaskett.bsky.social
github.com
GitHub - RPISEC/MBE: Course materials for Modern Binary Exploitation by RPISEC
Course materials for Modern Binary Exploitation by RPISEC - RPISEC/MBE
011
Reposted by Alex Plaskett
Ken Shirriff @righto.com · 25/11/2024
I recently saw an amazing Navajo rug at the National Gallery of Art. It looks abstract at first, but it is a detailed representation of the Intel Pentium processor. Called "Replica of a Chip", it was created in 1994 by Marilou Schultz, a Navajo/Diné weaver and math teacher. 1/n
A Navajo rug with a complex pattern with muted reds, pinks and blues. The pattern consists of various vertical and horizontal rectangles with stripes. Around the border are small alternating black and colored rectangles. The weaving is mounted in a wooden frame and hanging on the museum wall.
352913911
Reposted by Alex Plaskett
RyotaK @ryotak.net · 07/12/2024
If you're interested in the technical details, I wrote the blog post here: flatt.tech/research/pos... For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)
flatt.tech
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
0178
Reposted by Alex Plaskett
Stephen Fewer @stephenfewer.bsky.social · 04/12/2024
Rapid7 has disclosed the vulns from our exploit chain targeting the Lorex 2K Indoor Wi-Fi Security Camera, which we entered at this year's Pwn2Own Ireland. A 2 phase exploit, built upon 5 vulns - phase 1 is an auth bypass, whilst phase 2 is RCE. Disclosure, analysis and exploit here: t.co/J9VDwMDRsI
t.co
https://www.rapid7.com/blog/post/2024/12/03/lorex-2k-indoor-wi-fi-security-camera-multiple-vulnerabilities-fixed/
1158
Reposted by Alex Plaskett
Linux Kernel Security @linkersec.bsky.social · 27/11/2024
Novel approach to exploit a limited OOB on Ubuntu at Pwn2Own Vancouver 2024 Slides from a talk by Pumpkin Chang about exploiting a stack out-of-bounds write bug in the traffic control subsystem. u1f383.github.io/slides/talks...
185
Reposted by Alex Plaskett
Mark @offlinemark.bsky.social · 01/12/2024
week 44, streaming kernel dev topic: userspace page fault handling prequel to week 43, worked on the kernel-mode syscall support behind userspace PF handling (incl. recursive page fault support) (pre-recorded since I'm away this week ✌️) www.youtube.com/watch?v=5fv6Pjx3in8
youtube.com
chill kernel hacking for fun (week 44, user page fault + assembly)
(detailed timestamps in comments)#livecoding #softwareengineering #operatingsystem discord: https://discord.gg/XsgpqpVxNuWelcome! This is my chill Operating ...
061
Alex Plaskett @alexplaskett.bsky.social · 01/12/2024
A port of DOOM for a quantum computer! github.com/Lumorti/Quan...
150
Alex Plaskett @alexplaskett.bsky.social · 30/11/2024
23712
Reposted by Alex Plaskett
Gynvael Coldwind @gynvael.bsky.social · 30/11/2024
If you enjoy programming and lower levels of the stack, this is a talk you want to watch: www.youtube.com/watch?v=WDfr...
youtube.com
Eon: An Amiga 500 Demo - Andreas Fredriksson
YouTube video by Handmade Cities
0206
Alex Plaskett @alexplaskett.bsky.social · 30/11/2024
QwQ: Reflect Deeply on the Boundaries of the Unknown QwQ-32B-Preview is an experimental research model developed by the Qwen Team, focused on advancing AI reasoning capabilities. qwenlm.github.io/blog/qwq-32b...
050
Alex Plaskett @alexplaskett.bsky.social · 30/11/2024
This a really cool talk by DonjonLedger about using a laser fault injection attack to extract the second share of the seed from a Microchip ATECC secure element hardwear.io/netherlands-... www.youtube.com/embed/Hd_K2y...
hardwear.io
010
Reposted by Alex Plaskett
Catalin Cimpanu @campuscodi.risky.biz · 29/11/2024
Podcast: risky.biz/RBNEWS367/ Newsletter: news.risky.biz/risky-biz-ne... -Microsoft’s thanksgiving treat: an FTC investigation -Tor needs 200 new bridges to avoid Russian censorship -US court overturns Tornado Cash sanctions -ESET finds first Ubuntu UEFI bootkit -Unpatched Windows LPE
news.risky.biz
Tor Project urgently needs 200 new bridges to avoid Russian censorship
In other news: FTC opens Microsoft antitrust probe; US court overturns Tornado Cash sanctions; ESET finds first Ubuntu UEFI bootkit.
13613
Reposted by Alex Plaskett
Nicolas Grégoire @agarri.fr · 29/11/2024
"The networks are still compromised, and booting the hackers out could involve physically replacing “literally thousands and thousands and thousands of pieces of equipment across the country,” specifically outdated routers and switches" 🕵️‍♂️
washingtonpost.com
Top senator calls Salt Typhoon ‘worst telecom hack in our nation’s history’
The severity of the Chinese breach highlights the need for more telecommunications regulation, lawmakers say.
14437
Reposted by Alex Plaskett
lukas seidel @pr0me.bsky.social · 29/11/2024
"SoK: Prudent Evaluation Practices for Fuzzing" paper link: arxiv.org/pdf/2405.10220
arxiv.org
032
Alex Plaskett @alexplaskett.bsky.social · 29/11/2024
Finding Bugs in Chrome with CodeQL by Google bughunters.google.com/blog/5085111...
bughunters.google.com
Blog: Finding Bugs in Chrome with CodeQL
Want to learn about using a static analysis tool called CodeQL to search for vulnerabilities in Google Chrome? Then this blog post is for you!
091
Alex Plaskett @alexplaskett.bsky.social · 29/11/2024
How to develop n-day chrome exploits for electron applications by p3rr0 github.com/p3rr0x/Blog/...
github.com
Blog/Electron N-Day exploit at main · p3rr0x/Blog
Contribute to p3rr0x/Blog development by creating an account on GitHub.
031
Reposted by Alex Plaskett
Taggart @taggart-tech.com · 27/11/2024
Firefox, Thunderbird, Tor Browser RCE: www.welivesecurity.c...
welivesecurity.com
RomCom exploits Firefox and Windows zero days in the wild
ESET Research details the analysis of a previously unknown vulnerability in Mozilla products exploited in the wild and another previously unknown Microsoft Windows vulnerability, combined in a zero-click exploit.
088
Reposted by Alex Plaskett
0xTen @0xten.bsky.social · 28/11/2024
Earlier this year, I used a 1day to exploit the kernelCTF VRP LTS instance. I then used the same bug to write a universal exploit that worked against up-to-date mainstream distros for approximately 2 months. osec.io/blog/2024-11...
03210
Reposted by Alex Plaskett
Marcel Böhme @mboehme.bsky.social · 28/11/2024
🔥 No fuzz drivers needed. Our paper on injecting greybox fuzzers into running systems at user-defined amplifier points (in-vivo fuzzing) was accepted at #ICSE25! 📝 mboehme.github.io/paper/ICSE25... 🧑‍💻 github.com/OctavioGalla... (subject to AE) //Lead by Octavio Galland (former #MPI_SP intern).
14011
Reposted by Alex Plaskett
Axel 👨‍💻 Developer @axelgarciak.bsky.social · 28/11/2024
Linux Kernel 6.12 is here! 🐧 It includes mainline support for PREEMPT_RT, improving the performance of real-time apps by making kernel processes pre-emptible. ⏱️ Plus, enhanced hardware support for AMD, Intel, NVIDIA, new schedulers, file systems, and QR code kernel panics for easier debugging.
0235
Alex Plaskett @alexplaskett.bsky.social · 28/11/2024
Exxon lobbyist investigated over hack-and-leak of environmentalist emails, sources say by Reuters www.reuters.com/business/ene...
reuters.com
Exclusive: Exxon lobbyist investigated over hack-and-leak of environmentalist emails, sources say
The FBI has been investigating a longtime Exxon Mobil consultant over the contractor's alleged role in a hack-and-leak operation that targeted hundreds of the oil company’s biggest critics, according to three people familiar with the matter.
000
Reposted by Alex Plaskett
Quentin Kaiser @qkaiser.bsky.social · 27/11/2024
Anyone experienced with fscrypt forensics/reversing ? I got a firmware with a kernel and UBIFS. Both are encrypted. Kernel self-decrypt just before self-decompression, I managed to recover the key and decrypt it. I see it mounts the UBIFS using fscrypt. It’s embedded so the key must be somewhere…
011
Alex Plaskett @alexplaskett.bsky.social · 28/11/2024
Do you brine your turkey for thanksgiving / Xmas?
000
Alex Plaskett @alexplaskett.bsky.social · 28/11/2024
Everyday Ghidra: Ghidra Data Types — Creating Custom GDTs From Windows Headers — Part 2 by clearbluejar medium.com/@clearblueja...
medium.com
Everyday Ghidra: Ghidra Data Types — Creating Custom GDTs From Windows Headers — Part 2
Ghidra, developed by the NSA, is a powerful reverse engineering tool known for its versatility. One standout feature is its ability to…
080
Reposted by Alex Plaskett
Michal Špaček @spazef0rze.bsky.social · 27/11/2024
nginx 1.27.3 released yesterday disabled TLS 1.0 and TLS 1.1 protocols by default, nice nginx.org/en/CHANGES
nginx.org
https://nginx.org/en/CHANGES
Changes with nginx 1.27.3 26 Nov 2024 *) Feature: the "server" directive in the "upstream" block supports the "resolve" parameter. *) Feature: ...
0199
Alex Plaskett @alexplaskett.bsky.social · 28/11/2024
Lights Out: Covertly turning off the ThinkPad webcam LED indicator by Andrey Konovalov powerofcommunity.net/poc2024/Andr...
040
Reposted by Alex Plaskett
434b @434b.bsky.social · 28/11/2024
Small QoL feature release to my Shellcoder @binary.ninja plugin. Now every time you run it the architecture is automatically set based on the currently selected binary/database github.com/0xricksanche...
github.com
GitHub - 0xricksanchez/Shellcoder: BinjaryNinja plugin for a ShellStorm like assembly/disassembly experience
BinjaryNinja plugin for a ShellStorm like assembly/disassembly experience - 0xricksanchez/Shellcoder
043
Alex Plaskett @alexplaskett.bsky.social · 28/11/2024
Bypassing Luks full disk encryption by Remy remyhax.xyz/posts/luks-v...
remyhax.xyz
GRUB LUKS Bypass and Dump
Recently I needed to get the data off of a LUKS encrypted partition on a Virtual Machine that “wasn’t mine” and I’d never done it before.
030