Months of relentless work finally out: our Bitcoin Core security audit!
Both a bless by the code maturity, security culture -- and a curse by the challenge it represents!
Glad to have crossed paths with such a great dev team, @dergoegge@darosior@fanquake.
Keep up the great job!
The dragon has a VM. Of course it does. Our latest blog walks through the analysis of a complex C binary hiding behind a virtual machine, themed as a classic RPG fight. QBDI & TritonDSE are your weapons of choice. The dragon doesn't stand a chance. 🐉
blog.quarkslab.com/qbdi-vs-t…
Join us next Wednesday at 11AM CST for an OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".
Link in 🧵👇
#OSTIF#bitcoin
🎓 New PhD at Quarkslab on: "Analyzing binary programs and obfuscation with
graph-based representations and machine learning". I am overjoyed having supervised Roxane's PhD
and I have rarely seen such a committed, talented PhD researcher congrats 🎉!
Great talk by @JohnLaTwC on ways you can turn security data into graphs: youtube.com/watch?v=cXhX3sNh…. Especially the vector part is great: so many tools have built in support for embeddings (e.g. BigQuery ML.GENERATE_EMBEDDING and VECTOR_SEARCH), defenders should be using them more!
It has been a pleasure to be the 2nd talk of 20th Recon edition! Teaming up with Riccardo about EV charger security we show vulnerabilities found and a side step-by-step firmware cryptanalysis.
Outline: cfp.recon.cx/recon-2025/talk…
(slides published soon..)
i wrote a thing about all the different teams in north korea dedicated exclusively to fucking your shit up and how you can know exactly which one just ruined your entire month
paradigm.xyz/2025/03/demysti…
The recording of my talk is online: youtube.com/watch?v=LsDnrfZt…
"Streamlining firmware analysis with inter-image call graph and decompilation". Held in Orlando, Florida at @REverseConf!
We were slow with the last video update so we figured we'd do a two for one! Lukas talks about rehosting firmware for fuzzing (youtu.be/o_ckTnTQlfs) and Robin shows off a fantastic new tool for exploring code relationships beyond single binaries (youtube.com/watch?v=LsDnrfZt…)
There are so many great reasons to be on Signal.
Now including the opportunity for the vice president of the United States of America to randomly add you to a group chat for coordination of sensitive military operations.
Don’t sleep on this opportunity…
Attending and speaking at the inaugural edition of @REverseConf was fantastic. Great crowd, great organization by @vector35 folks, great discussions and great vibes! Slides of my talk on firmware analysis is available here:
github.com/quarkslab/conf-pr…
Oh hey! My last R&D project at @quarkslab is finally out. :D
tl.dr. playing with the Steam Deck is fun <3 (i.e. UEFI exploit w/ super limited primitives)
blog.quarkslab.com/being-ove…
Registration for #Pwn2Own Automotive is now closed! We have over 50 entries from over 20 teams - including a lot of first timers! The drawing for order will be next Tuesday, January 21, at 1400 Tokyo time (GMT 9). Watch it live at youtube.com/live/doaUXuz7udQ…
Nice blog post! We never documented it, but one can take a look at python-binexport github.com/quarkslab/python-… to see how we recreate a whole program structure from a BinExport file! Cc @AdmVonSchneider