Sign in

Meysam

@r00tkitsmm.bsky.social
490 followers 421 following 33 posts

Security Researcher.

PostsRepliesMedia
Meysam @r00tkitsmm.bsky.social · 31/07/2025
Come learn how to hack the XNU kernel, like a pro 🍎 with beautiful diagrams to guide every step. :) 📅 Nov 10-12 (3 days) 📍 Four Seasons Hotel Seoul, South Korea 🔗 More info powerofcommunity.net/#training
050
Meysam @r00tkitsmm.bsky.social · 17/04/2025
Here is the source code of my fuzzer ai development for macOS. github.com/R00tkitSMM/P...
github.com
GitHub - R00tkitSMM/Pishi: Pishi is a code coverage tool like kcov for macOS.
Pishi is a code coverage tool like kcov for macOS. - R00tkitSMM/Pishi
170
Meysam @r00tkitsmm.bsky.social · 16/04/2025
Oh, We have a long weekend ahead in Germany/Berlin. Maybe I can finish my unpublished blog posts. Share blogs or papers that I can read and enjoy.
000
Meysam @r00tkitsmm.bsky.social · 10/04/2025
My new blog post, which I presented at #Zer0Con2025 A binary level macOS KEXT kernel address sanitizer r00tkitsmm.github.io/fuzzing/2025...
r00tkitsmm.github.io
Pishi Reloaded: Binary only address sanitizer for macOS KEXT.
In the part 1 of my tutorial style blog post about fuzzing, I discussed how we can instrument the macOS KEXTs to collect code coverage at the basic block or edge level.
0134
Meysam @r00tkitsmm.bsky.social · 03/04/2025
Will be in Korea next week for Zer0Con. Ping me and let’s chat about software security.
120
Meysam @r00tkitsmm.bsky.social · 29/03/2025
blog.slowerzs.net/posts/keyjum...
blog.slowerzs.net
Code reuse in the age of kCET and HVCI
051
Reposted by Meysam
Paged Out! @pagedout.bsky.social · 29/03/2025
Paged Out! #6 has arrived! And it's jam-packed with content! You can download it here: pagedout.institute?page=issues....
02227
Reposted by Meysam
jduck @jduck.me · 25/03/2025
Happy to share my slides from BOOTSTRAP25. Unfortunately the bug discussed is still not patched in Linux 6.14.0 despite it being reported explicitly. Slides are in markdown but there's a PDF in "releases" too github.com/jduck/bs25-s...
github.com
GitHub - jduck/bs25-slides: Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25
Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25 - jduck/bs25-slides
1147
Reposted by Meysam
buherator @buherator.bsky.social · 27/03/2025
[RSS] The Evolution of Dirty COW (1) u1f383.github.io -> Original->
042
Reposted by Meysam
dmnk @dmnk.bsky.social · 24/03/2025
Neat, #riscv emu with #LibAFL support github.com/fkie-cad/squid
github.com
GitHub - fkie-cad/squid: RISC-V emulator for high-performance fuzzing with AOT instead of JIT compilation 🦑
RISC-V emulator for high-performance fuzzing with AOT instead of JIT compilation 🦑 - fkie-cad/squid
072
Reposted by Meysam
Gynvael Coldwind @gynvael.bsky.social · 11/03/2025
Did you know that pressing CTRL+D in linux terminal is like pressing ENTER? (to some extent, of course) Well, I didn't, so after randomly investigating what CTRL+D actually does, I've decided it's a fun topic to write about: hackarcana.com/article/ctrl...
hackarcana.com
3102
Reposted by Meysam
dmnk @dmnk.bsky.social · 10/03/2025
This is so cool: The LibAFL_QEMU ASan implementation was ported to rust github.com/AFLplusplus/... #LibAFL #QEMU #ASan #Rust
github.com
Librasan by WorksButNotTested · Pull Request #3023 · AFLplusplus/LibAFL
Implementation of ASAN target side components in rust. The implementation sits alongside the existing libqasan (although that could be withdrawn in future if we are happy with it). It is selected ...
0114
Meysam @r00tkitsmm.bsky.social · 10/03/2025
I will talk about macOS Kernel fuzzing at the zer0con.org#schedule-sec... conference.
zer0con.org
Zer0Con
Zer0Con is POC’s NEW ‘CLOSED’ international security conference. It focuses on finding, analyzing, and exploiting vulnerabilities. Zer0Con aims to have high-level technical presentations.
040
Meysam @r00tkitsmm.bsky.social · 08/01/2025
I usually dig into a topic I research by googling and reading blogs, manuals, sources,… and have not read a technical book for a year. What would you recommend for low level software/CPU/OS security/exploit topics?
110
Reposted by Meysam
Alexandre Borges @alexandreborges.bsky.social · 31/12/2024
All videos from The 38th Chaos Communication Congress (38C3) 2024: media.ccc.de/b/congress/2... #cybersecurity #informationsecurity #hacking #exploitation #iOS #android #apple #exploitation #reverseengineering #vulnerability
02917
Meysam @r00tkitsmm.bsky.social · 29/12/2024
Doing Apple Silicon’s security research for days non stop. Hope it becomes a blogpost at some point.
020
Reposted by Meysam
Meysam @r00tkitsmm.bsky.social · 25/05/2023
Steve Glass, talks about potential vulnerabilities in TLV parser of AWDL in jun 2019, And some months later ian beer reported that famous vulnerability in exactly TLV parser of AWDL. Conferences are sources of ideas.
061
Meysam @r00tkitsmm.bsky.social · 28/12/2024
Where do you read papers? I have kindle and it’s the best option.
300
Meysam @r00tkitsmm.bsky.social · 27/12/2024
I’m in Hamburg, but wouldn’t attend #38c3 due to ticket issue :)
120
Reposted by Meysam
dmnk @dmnk.bsky.social · 24/12/2024
Re-sharing to keep bluesky rolling go.bsky.app/EhGFSVj
04513
Meysam @r00tkitsmm.bsky.social · 06/12/2024
I have read and watched a lot of papers and presentations this week about Compiler 🤝 OS 🤝SoC security. www.youtube.com/watch?v=bytW... www.youtube.com/watch?v=C1nZ... These two are about PAC
youtube.com
2024 LLVM Dev Mtg - Adding Pointer Authentication ABI support for your ELF platform
YouTube video by LLVM
040
Meysam @r00tkitsmm.bsky.social · 05/12/2024
Pishi2 needed more compiler/LLVM Knowledge. This is very good reference. llsoftsec.github.io/llsoftsecbook/
llsoftsec.github.io
Low-Level Software Security for Compiler Developers
041
Meysam @r00tkitsmm.bsky.social · 03/12/2024
Have written new macOS binary level fuzzing blog post. Second part of r00tkitsmm.github.io/fuzzing/2024... Don’t know when to publish it
r00tkitsmm.github.io
Pishi: Coverage guided macOS KEXT fuzzing.
This blog post is the result of some weekend research, where I delved into Pishi, a static macOS kernel binary rewriting tool, which I presented at POC2024. During the weekdays, I focus on Linux kerne...
092
Meysam @r00tkitsmm.bsky.social · 29/11/2024
Took 3 weeks off, bought a new MacBook. It’s to to fuzz the kernel.
070
Meysam @r00tkitsmm.bsky.social · 20/11/2024
I’m bad with telling jokes, In my POC2024(Seoul) talk about kernel fuzzing I joked that KAFL is Korean Wave of AFL. And nobody laughed.
060
Reposted by Meysam
dmnk @dmnk.bsky.social · 15/11/2024
Slides for my @ekoparty talk "Advanced Fuzzing With LibAFL" - > docs.google.com/presentation...
docs.google.com
Advanced Fuzzing With LibAFL @ Ekoparty 2024
Advanced Fuzzing With LibAFL Dominik Maier Ekoparty 2024-11-15 1
04420
Meysam @r00tkitsmm.bsky.social · 18/11/2024
Got back home after POC conference, now I have lots of fuzzing paper to read. 🥳
020
Reposted by Meysam
Karsten @gr4yf0x.bsky.social · 16/11/2024
Custom Linux kernel fuzzing with libFuzzer by @r00tkitsmm.bsky.social r00tkitsmm.github.io/fuzzing/2024...
r00tkitsmm.github.io
Structure-Aware linux kernel Fuzzing with libFuzzer
Hi everyone! I’m really happy to tell you about my experimenting adventure today. I decided to experiment with KCOV and see how I can hook it into libfuzzer and boot the kernel without spending too mu...
052
Meysam @r00tkitsmm.bsky.social · 15/11/2024
Can’t wait to get back to Berlin to work on my second part of my blog post about macOS kernel fuzzing.
130
Reposted by Meysam
John Scott-Railton @jsrailton.bsky.social · 15/11/2024
Whoa: NSO Group allegedly rolled a #WhatsApp exploit to implant #Pegasus spyware even after WhatsApp sued them. This previously-unrevealed "Erised" vector was later disabled by WhatsApp. These un-redacted filings are quite the read. Even some footnotes have scoops. 1/
Image from lawsuit filing mentioning the new exploit
5193108
Reposted by Meysam
Richard Johnson @richinseattle.bsky.social · 10/11/2024
This awesome fuzzing blog post by @r00tkitsmm.bsky.social covers a super reliable macOS kernel binary rewriting to instrument any KEXT or XNU at BB or edge level. Mandatory reading for anyone interested in fuzzing whether you use MacOS or not. So many good system internals and fuzzing references!
r00tkitsmm.github.io
Pishi: Coverage guided macOS KEXT fuzzing.
This blog post is the result of some weekend research, where I delved into Pishi, a static macOS kernel binary rewriting tool. During the weekdays, I focus on Linux kernel security at my job and would...
23715
Meysam @r00tkitsmm.bsky.social · 02/08/2023
googleprojectzero.blogspot.com/2023… A 3 parts blogpost from Google Project Zero after a long time.
000
Meysam @r00tkitsmm.bsky.social · 25/05/2023
Steve Glass, talks about potential vulnerabilities in TLV parser of AWDL in jun 2019, And some months later ian beer reported that famous vulnerability in exactly TLV parser of AWDL. Conferences are sources of ideas.
061
Meysam @r00tkitsmm.bsky.social · 18/05/2023
got 3 CVEs in recent Apple's Update CVE-2023-32384 CVE-2023-32372 CVE-2023-27929( last month i didn’t know :) ) support.apple.com/en-gb/HT213757
020
Meysam @r00tkitsmm.bsky.social · 16/05/2023
Hey @mdowd.bsky.social could you kindly let me know if you have any tickets to offensiveCon?
100
Meysam @r00tkitsmm.bsky.social · 13/05/2023
Introducing a new way to buzz for eBPF vulnerabilities security.googleblog.com/2023/05/int…
000
Meysam @r00tkitsmm.bsky.social · 12/05/2023
blog.thalium.re/posts/ksmbd-trailer
000
Meysam @r00tkitsmm.bsky.social · 11/05/2023
Lightweight fuzzing of a memory snapshot using KVM github.com/awslabs/snapchange
000
Meysam @r00tkitsmm.bsky.social · 11/05/2023
Two dead in shooting at Mercedes-Benz plant in Germany amp.cnn.com/cnn/2023/05/11/business…
000