Garfield (@lanleft_) 's Twitter Profile
Garfield

@lanleft_

she/her | Qrious Secure @qriousec
I made my own cover photo

ID: 1178231491689512960

linkhttps://github.com/lanleft calendar_today29-09-2019 08:54:34

92 Tweet

1,1K Followers

360 Following

starlabs (@starlabs_sg) 's Twitter Profile Photo

"Breaking the Code - Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability" is by our former intern, Lan Vu before she graduated from Uni. We would also like this opportunity to wish her all the best in her future endeavors. starlabs.sg/blog/2023/06-bโ€ฆ

starlabs (@starlabs_sg) 's Twitter Profile Photo

In our latest blog post, we're proud of our intern, Kaligula Armblessed for delivering a quality post "prctl anon_vma_name: An Amusing Linux Kernel Heap Spray" starlabs.sg/blog/2023/07-pโ€ฆ

Lau (@notselwyn) 's Twitter Profile Photo

I wrote a new blogpost about adding ksmbd (SMB server in the Linux kernel) fuzzing functionality to Syzkaller. Feel free to send a DM if you have any questions :-) pwning.tech/ksmbd-syzkalleโ€ฆ #syzkaller #linux #ksmbd #vr #vulnres #fuzzing #zeroday #exploit

Physics In History (@physinhistory) 's Twitter Profile Photo

โ€œStudy the science of art and the art of science. Learn how to see. Realize that everything connects to everything else." - Leonardo da Vinci (1452 - 1519)

โ€œStudy the science of art and the art of science. Learn how to see. Realize that everything connects to everything else."

- Leonardo da Vinci (1452 - 1519)
Suto (@__suto) 's Twitter Profile Photo

Today, me, Lan Vu and Tri have submitted our latest report on Chromium detailed an information leak in ANGLE, which we discovered during our efforts to achieve a full-chain exploit. In total we reported 4 security issues for google and has been rewarded 56k usd.

Suto (@__suto) 's Twitter Profile Photo

Made a brief slide summarizing OTHERS โ€™ reports on V8 WebAssembly Engine. Hope you find it helpful! docs.google.com/presentation/dโ€ฆ

Off-By-One Conference (@offbyoneconf) 's Twitter Profile Photo

Singapore - shout it out for Yuki Chen ๐Ÿคฉ !!! Bringing Day 1 of Off-By-One Conference 2025 to a explosive end with ๐€ ๐‰๐จ๐ฎ๐ซ๐ง๐ž๐ฒ ๐ข๐ง๐ญ๐จ ๐–๐ข๐ง๐๐จ๐ฐ๐ฌ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐’๐ฎ๐ฉ๐ฉ๐จ๐ซ๐ญ ๐๐ซ๐จ๐ฏ๐ข๐๐ž๐ซ ๐ˆ๐ง๐ญ๐ž๐ซ๐Ÿ๐š๐œ๐ž. ๐Ÿ™‡๐Ÿ™‡๐Ÿ™‡

Singapore - shout it out for Yuki Chen ๐Ÿคฉ !!! Bringing Day 1 of <a href="/offbyoneconf/">Off-By-One Conference</a>  2025 to a explosive end with ๐€ ๐‰๐จ๐ฎ๐ซ๐ง๐ž๐ฒ ๐ข๐ง๐ญ๐จ ๐–๐ข๐ง๐๐จ๐ฐ๐ฌ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐’๐ฎ๐ฉ๐ฉ๐จ๐ซ๐ญ ๐๐ซ๐จ๐ฏ๐ข๐๐ž๐ซ ๐ˆ๐ง๐ญ๐ž๐ซ๐Ÿ๐š๐œ๐ž. 
๐Ÿ™‡๐Ÿ™‡๐Ÿ™‡
Samuel GroรŸ (@5aelo) 's Twitter Profile Photo

We released our Fuzzilli-based V8 Sandbox fuzzer: github.com/googleprojectzโ€ฆ It explores the heap to find interesting objects and corrupts them in a deterministic way using V8's memory corruption API. Happy fuzzing!

stephen (@_tsuro) 's Twitter Profile Photo

If you like Chrome IPC shenanigans like this, you might also enjoy my talk from black hat 25: youtu.be/qhhJCLy0YBA?siโ€ฆ

Garfield (@lanleft_) 's Twitter Profile Photo

Can not get a cve from this vulnerability, itโ€™s quite sad ๐Ÿ˜ž By the way, Iโ€™d like to give a huge thanks to my mentor Toan Pham ๐Ÿ˜Š

Suto (@__suto) 's Twitter Profile Photo

I've built a tool to perform AI automation decompilation vmware workstation binary to see how good it perform on realworld task based on the vulnerable version Thach mentioned in his PoC slides 2024.

I've built a tool to perform AI automation decompilation vmware workstation binary to see how good it perform on realworld task based on the vulnerable version Thach mentioned in his PoC slides 2024.