Maxime Rossi Bellom (@max_r_b) 's Twitter Profile
Maxime Rossi Bellom

@max_r_b

Android security geek @quarkslab. My tweets are all yours.
mastodon.social/@maxrb

ID: 139389485

calendar_today02-05-2010 13:11:57

826 Tweet

915 Followers

799 Following

quarkslab (@quarkslab) 's Twitter Profile Photo

Now at Pass the SALT Conference ThiƩbaud Fuchs presents Hydradancer, an open source project to improve USB hacking with Facedancer using HydraUSB3 hardware Sounds complicated? It is not! It's just good USB hacking fun Join the live stream at here: 2024.pass-the-salt.org

hydrabus.com (@hydrabus) 's Twitter Profile Photo

Great talk on HydraDancer by QuarksLab(quarkslab) / ThiĆ©baud Fuchs(github.com/kauwua) at Pass the SALT Conference #pts24 Check it out: cfp.pass-the-salt.org/pts2024/talk/E… HydraDancer Dongle V1 R1 coming soon! Ultra-small aluminum anodized + laser engraving enclosure: 53mm x 33mm x 15mm.

Great talk on HydraDancer by QuarksLab(<a href="/quarkslab/">quarkslab</a>) / ThiƩbaud Fuchs(github.com/kauwua) at <a href="/passthesaltcon/">Pass the SALT Conference</a> #pts24
Check it out: cfp.pass-the-salt.org/pts2024/talk/E…
HydraDancer Dongle V1 R1 coming soon!
Ultra-small aluminum anodized + laser engraving enclosure: 53mm x 33mm x 15mm.
quarkslab (@quarkslab) 's Twitter Profile Photo

Ready for part 3 of our travel into the dynamic instrumentation of #Golang during runtime? In this article, cryptonite and Damien Aumaitre will leverage CGO, Go's Foreign Function Interface (FFI), to improve the hooking scheme they defined in part 1 blog.quarkslab.com/lets-go-into-t…

Ready for part 3 of our travel into the dynamic instrumentation of #Golang during runtime? In this article, <a href="/cryptonitemmk/">cryptonite</a> and Damien Aumaitre will leverage CGO, Go's Foreign Function Interface (FFI), to improve the hooking scheme they defined in part 1
blog.quarkslab.com/lets-go-into-t…
stacksmashing (@ghidraninja) 's Twitter Profile Photo

Hello Black Hat! Catch my talk on using electro-magnetic side-channels + EMFI to hack into Apple’s ACE3 chip tomorrow at 10:20am! Send me a message if you want to meet up - or if you know what parties are worth attending šŸ˜€

Hello <a href="/BlackHatEvents/">Black Hat</a>!

Catch my talk on using electro-magnetic side-channels + EMFI to hack into Apple’s ACE3 chip tomorrow at 10:20am!

Send me a message if you want to meet up - or if you know what parties are worth attending šŸ˜€
quarkslab (@quarkslab) 's Twitter Profile Photo

Today at DEF CON 32 Damien Cauquil (@[email protected]) & Romain Cayre unveil WHAD: A Python framework for Wireless HAcking Devices Tired of building ad-hoc tools for wireless hacking? Sick of having to implement half-baked protocols? We've got you covered! At 5pm in LVCC - L1 - HW1-11-02 (Track 2)

Romain Cayre (@cayreromain) 's Twitter Profile Photo

After two years of hard work with Damien Cauquil (@[email protected]) , we are proud to release for DEFCON32 the first public version of WHAD, a whole new ecosystem of opensource libs, tools & firmwares for wireless security ! The main repo is here: github.com/whad-team/whad… . And now, demo time ! [1/n]

quarkslab (@quarkslab) 's Twitter Profile Photo

Are "MIFARE-compatible" contactless cards not playing fair? That's what you may wonder after Philippe Teuwen spotted some odd behavior. Curiosity led to experiments to devise a new attack technique that uncovered some backdoors. The RFID hacking spirit lives on! blog.quarkslab.com/mifare-classic…

Are "MIFARE-compatible" contactless cards not playing fair? That's what you may wonder after <a href="/doegox/">Philippe Teuwen</a> spotted some odd behavior. Curiosity led to experiments to devise a new attack technique that uncovered some backdoors.
The RFID hacking spirit lives on!
 blog.quarkslab.com/mifare-classic…
quarkslab (@quarkslab) 's Twitter Profile Photo

The Cryptodifference Engine: An in-depth look at differential fuzzing for harvesting crypto bugs, by CĆ©lian GlĆ©naz blog.quarkslab.com/differential-f…

The Cryptodifference Engine: An in-depth look at differential fuzzing for harvesting crypto bugs, by CƩlian GlƩnaz

blog.quarkslab.com/differential-f…
quarkslab (@quarkslab) 's Twitter Profile Photo

Finding and chaining 4 vulns to exfiltrate encryption keys from the Android Keystore on Samsung series A* devices. Did you miss the "Attacking the Samsung Galaxy A* Boot Chain" talk by Maxime Rossi Bellom and RaphaĆ«l Neveu earlier this year ? Talk && PoC || GTFO: blog.quarkslab.com/attacking-the-…

Finding and chaining 4 vulns to exfiltrate encryption keys from the Android Keystore on Samsung series A* devices.
Did you miss the  "Attacking the Samsung Galaxy A* Boot Chain" talk by <a href="/max_r_b/">Maxime Rossi Bellom</a> and Raphaƫl Neveu earlier this year ? 
Talk &amp;&amp; PoC  || GTFO:
blog.quarkslab.com/attacking-the-…
quarkslab (@quarkslab) 's Twitter Profile Photo

Linux kernel instrumentation from Qemu and gdb: A technique to analyze binaries or kernel modules that may try to monitor themselves. In this blog post Professor Forgette BenoĆ®t explains the trick blog.quarkslab.com/linux-kernel-i…

Linux kernel instrumentation from Qemu and gdb:
A technique to analyze binaries or kernel modules that may try to monitor themselves. 

In this blog post Professor <a href="/Mad5quirrel/">Forgette BenoƮt</a> explains the trick

blog.quarkslab.com/linux-kernel-i…
quarkslab (@quarkslab) 's Twitter Profile Photo

Our 2024-2025 internships season has started Check out the 3 new openings and apply for fun and knowledge! (paid internships, fur coats not included) blog.quarkslab.com/internship-off…

Our 2024-2025 internships season has started
Check out the 3 new openings and apply for fun and knowledge!
(paid internships, fur coats not included)

blog.quarkslab.com/internship-off…
hardwear.io (@hardwear_io) 's Twitter Profile Photo

šŸ”— #BluetoothLowEnergy (#BLE) has seen extensive research, but few studies have targeted the specification corner cases requiring high-level manipulation of the #GATT layer Baptiste at #hw_ioNL2024 proposes fuzzing approach to identify vulnerabilities šŸ‘‰ hardwear.io/netherlands-20…

šŸ”— #BluetoothLowEnergy (#BLE) has seen extensive research, but few studies have targeted the specification corner cases requiring high-level manipulation of the #GATT layer

Baptiste at #hw_ioNL2024 proposes fuzzing approach to identify vulnerabilities

šŸ‘‰ hardwear.io/netherlands-20…
Jiska (@naehrdine) 's Twitter Profile Photo

How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented. naehrdine.blogspot.com/2024/11/revers…

How does the new iOS inactivity reboot work? What does it protect from?

I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented.

naehrdine.blogspot.com/2024/11/revers…
ringzerĆø.training && @ringzer0@infosec.exchange (@_ringzer0) 's Twitter Profile Photo

Learn Reversing Cryptography in Black Box Binaries with Quarkslab's Dahmun Goudarzi and Robin David at BOOTSTRAP25, Austin, TX, March 18-21 ringzer0.training/bootstrap25-re…

quarkslab (@quarkslab) 's Twitter Profile Photo

こんにごは Tokyo! "Of all things, I liked bugs best." ― Nikola Tesla Quarkslab is happy to participate in Pwn2Own Automotive and tomorrow we will try to demonstrate a RCE on an Electric Vehicle Charger on stage. Nikola enlight us, Murphy stay home! zerodayinitiative.com/blog/2025/1/21…

quarkslab (@quarkslab) 's Twitter Profile Photo

Another audit finalized with OSTIF Official and CNCF! šŸ” Quarkslab reviewed Notary Project’s new cryptographic features — timestamping & certificate revocation — identifying 11 issues, including 2 CVEs! šŸ“– Read more in our blog post: blog.quarkslab.com/security-audit…

Another audit finalized with <a href="/OSTIFofficial/">OSTIF Official</a> and <a href="/CloudNativeFdn/">CNCF</a>! šŸ” Quarkslab reviewed Notary Project’s new cryptographic features — timestamping &amp; certificate revocation — identifying 11 issues, including 2 CVEs! šŸ“– Read more in our blog post: blog.quarkslab.com/security-audit…
quarkslab (@quarkslab) 's Twitter Profile Photo

Good tools are made of bugs: How to monitor your Steam Deck with one byte. Finding and exploiting two vulnerabilities in AMD's UEFI firmware for fun and gaming . A Christmas gift in February, brought to you by the amazing Gwaby 🫶 blog.quarkslab.com/being-overlord…

Good tools are made of bugs: How to monitor your Steam Deck with one byte.
Finding and exploiting two vulnerabilities in  AMD's UEFI firmware for fun and gaming . 
A Christmas gift in February, brought to you by the amazing <a href="/pwissenlit/">Gwaby</a>  🫶

blog.quarkslab.com/being-overlord…
Specter (@specterdev) 's Twitter Profile Photo

I've published a write-up on reversing and analyzing Samsung's H-Arx hypervisor architecture for Exynos devices, which has had a lot of changes in recent years and pretty interesting design. Hope you all enjoy :) dayzerosec.com/blog/2025/03/0…