was born in '85, still alive...

Joined February 2010
40 Photos and videos
Alyosha Sintsov retweeted
14 Oct 2024
"we would look at xrefs to strcpy() and write a highly reliable exploit by the end of the day"
3
68
496
31,315
Hey, we are looking for an Incident Response Engineer in Mexico! #job social.icims.com/viewjob/pt1…

1
3
241
Alyosha Sintsov retweeted
Let me say that again... You store pointers at the _destination_ address of a memcpy. You glitch during memcpy (). You get that pointer into PC. No, it's not sci-fi. It's the "instruction corruption" fault model. And we pioneered that. See thread below 1/N.
5 Sep 2023
Replying to @raelizecom
This attack showed that the data at the destination of a copy can be abused just like the data at the source. We had to improve this attack quite a bit as it simply took too long to get a successful glitch. The details for this optimization will be explained during our training.
1
14
39
10,637
Alyosha Sintsov retweeted
Application Security and Vulnerability Assessment getting a significant advantage from GenAI (context-driven knowledgebase). That helps security teams understand the root cause of the problem faster and significantly reduces the latency in producing security fixes at scale.
1
10
32
6,941
Alyosha Sintsov retweeted
21 Jun 2023
"... detected several remotely exploitable bugs in AMI MegaRAC BMC" "... whole attack sequence: from having zero knowledge about a remote AMI BMC with enabled IPMI (yeah, right) to flashing a persistent firmware implant to the server SPI flash" Looking forward to this talk!
Check out the abstract of our upcoming DC talk :) CC: @Adam_pi3 forum.defcon.org/node/245714
14
30
10,851
Alyosha Sintsov retweeted
6 Jun 2023
Our lovely Red Team at @gitlab is looking for a Senior Red Teamer boards.greenhouse.io/gitlab/…
1
31
168
38,923
Also found interesting, that ChatGPT works much better if you ask to use LangSec approach: translate logic into grammar, and input as a language and try to find a Weird Machine, works more efficient at my example than just "check the pseudocode/logic for security issues"
1
298
1
242
1
243
Think lately about weird machines, and found myself that jokes and humor is an example of such for human beings.
1
353
And on other side: "fraud/propaganda" is also a language for creating "weird machines"...
225
Alyosha Sintsov retweeted
A Dark Side of UEFI: Cross-Silicon Exploitation by @matrosov and @flothrone now #OffensiveCon23
1
25
63
10,906
Alyosha Sintsov retweeted
My dear humans and non-humans, I present to you the speakers for #OffensiveCon23 offensivecon.org/speakers/

2
36
116
58,020
Alyosha Sintsov retweeted
8 Sep 2022
📝New research by @lmpact_l: "Fork Bomb for Flutter" There are more and more Flutter applications, and security analysis of these apps is in high demand. Our member Phil shares his knowledge and presents his reFlutter tool. Read the article: swarm.ptsecurity.com/fork-bo…
6
27
76
Future of hacking... ha ha, It is really fun, thx!
1
3
6