Vignesh Rao (@sherl0ck__) 's Twitter Profile
Vignesh Rao

@sherl0ck__

Cyber Security Enthusiast | ex Pwner @teambi0s

Mastodon: infosec.exchange/@sherl0ck

ID: 938088748310519809

linkhttp://vigneshsrao.github.io calendar_today05-12-2017 16:52:41

204 Tweet

1,1K Followers

454 Following

Alex Plaskett (@alexjplaskett) 's Twitter Profile Photo

Just posted a rare non-technical short blog aiming to demystify security research a bit alexplaskett.github.io/demystifying-sโ€ฆ Part 1 is focusing on choosing topics, approach, mindset. I feel like as industry we often see the output from research but less about the process of getting there.

Saar Amar (@amarsaar) 's Twitter Profile Photo

Last year, Apple shared a high-level overview of "Memory safe iBoot implementation". I thought it would be nice to reverse and write about it, hope you will find it interesting :) saaramar.github.io/iBoot_fireblooโ€ฆ

Ian Beer (@i41nbeer) 's Twitter Profile Photo

Excited to publish my writeup of a novel iOS in-the-wild exploit: The curious case of the fake Carrier .app: googleprojectzero.blogspot.com/2022/06/curiouโ€ฆ

Exodus Intelligence (@xi_research) 's Twitter Profile Photo

Exodus is experiencing record growth, so we are hiring multiple people for multiple roles! Join our team of l33t hackers and focus on what you love with very little bureaucracy exodusintel.com/careers.html

Brandon Azad (@_bazad) 's Twitter Profile Photo

Iโ€™m really excited for us to shed light on some really cool work weโ€™ve been doing to harden the XNU allocator! This has been a huge effort by so many people, and Iโ€™m very proud of the direction: security.apple.com/blog/towards-tโ€ฆ

Exodus Intelligence (@xi_research) 's Twitter Profile Photo

We are finally going to start doing public training again in 2023. Our first training will be in Austin TX in late March: blog.exodusintel.com/2023/02/17/vulโ€ฆ

Michele Campa (@s1ckb017) 's Twitter Profile Photo

I am really happy to announce that my research on adobe sandbox escape exploiting a windows CVE has been published on the Exodus Intelligence's blog blog.exodusintel.com/2023/04/06/escโ€ฆ

Ahn Ki Chan (@externalist) 's Twitter Profile Photo

Here are the slides for my keynote, 'Mobile Exploitation, the past, present, and the future' at #Zer0Con2023. Zer0con was a blast as always, thank you POC_Crew ๐Ÿ‘จโ€๐Ÿ‘ฉโ€๐Ÿ‘ฆโ€๐Ÿ‘ฆ!! ๐Ÿš€๐Ÿ’ซ github.com/externalist/prโ€ฆ

typeconfuser (@typeconfuser) 's Twitter Profile Photo

> we are having the CTF, and while checking traffic, I noticed that one of the team's exploits is not GLES 3.1 or compute shader specific. I checked that it's a 0day. > I eventually reported the issue to ensure that it actually is taken care of,

> we are having the CTF, and while checking traffic, I noticed that one of the team's exploits is not GLES 3.1 or compute shader specific. I checked that it's a 0day.
> I eventually reported the issue to ensure that it actually is taken care of,
Vignesh Rao (@sherl0ck__) 's Twitter Profile Photo

Blogged after a while on some research that me and typeconfuser did back in 2020 regarding the exploitation of a range mis-computation issue in WebKit!

Ian Beer (@i41nbeer) 's Twitter Profile Photo

If you like memory corruption, low-level internals and building custom decompilers to analyse novel exploits check out the write-up here: googleprojectzero.blogspot.com/2023/10/an-anaโ€ฆ

Vignesh Rao (@sherl0ck__) 's Twitter Profile Photo

We wrote about a Chrome bug that arose due to the manner in which V8's Maglev tried to optimize the number of allocations it made. Now, in the newer releases with Trusted Pointers, the v8 heap sandbox looking a bit more formidable ๐Ÿ‘€

ulisses (@foolisses) 's Twitter Profile Photo

Just published a post on exploiting CVE-2024-0582, a vulnerability in the Linux kernel that remained unpatched in Ubuntu for over two months. Hope you enjoy it! blog.exodusintel.com/2024/03/27/minโ€ฆ

Off-By-One Conference (@offbyoneconf) 's Twitter Profile Photo

Vignesh Rao delivering his l33t paper ๐„๐ฑ๐ฉ๐ฅ๐จ๐ซ๐ข๐ง๐  ๐–๐ž๐›๐Š๐ข๐ญ'๐ฌ ๐‰๐ฎ๐ฌ๐ญ-๐ˆ๐ง-๐“๐ข๐ฆ๐ž ๐‚๐จ๐ฆ๐ฉ๐ข๐ฅ๐š๐ญ๐ข๐จ๐ง in ๐Ÿ”ฅ style at Off-By-One Conference . Powering on Day 1 at our inaugural Off-By-One Conference !

<a href="/sherl0ck__/">Vignesh Rao</a> delivering his l33t paper ๐„๐ฑ๐ฉ๐ฅ๐จ๐ซ๐ข๐ง๐  ๐–๐ž๐›๐Š๐ข๐ญ'๐ฌ ๐‰๐ฎ๐ฌ๐ญ-๐ˆ๐ง-๐“๐ข๐ฆ๐ž ๐‚๐จ๐ฆ๐ฉ๐ข๐ฅ๐š๐ญ๐ข๐จ๐ง in ๐Ÿ”ฅ style at <a href="/offbyoneconf/">Off-By-One Conference</a> . Powering on Day 1 at our inaugural <a href="/offbyoneconf/">Off-By-One Conference</a> !