Joe Bialek's Avatar

Joe Bialek

@josephbialek.bsky.social

Windows security person

81 Followers  |  48 Following  |  9 Posts  |  Joined: 14.11.2024  |  1.9316

Latest posts by josephbialek.bsky.social on Bluesky

Post image

I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at #BHUSA! This is going to be epic, check out the abstract for a teaser ↓

14.05.2025 13:31 β€” πŸ‘ 39    πŸ” 18    πŸ’¬ 2    πŸ“Œ 1

I do! Easier to make a local copy of.

29.05.2025 16:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Are the slides published?

29.05.2025 04:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I actually was not super optimistic this would work due to compatibility but it ended up being pretty easy to get through.

24.05.2025 00:44 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This was my team, sorry not sorry :-)

24.05.2025 00:43 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Bypassing kASLR via Cache Timing : r0keb.github.io/posts/Bypass...

kASLR Internals and Evolution : r0keb.github.io/posts/kASLR-... credits @r0keb

20.05.2025 06:40 β€” πŸ‘ 3    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
BlueHat 2024: S09: Pointer Problems – Why We’re Refactoring the Windows Kernel
YouTube video by Microsoft Security Response Center (MSRC) BlueHat 2024: S09: Pointer Problems – Why We’re Refactoring the Windows Kernel

Important news: Microsoft is working to bring SMAP into Windows

www.youtube.com/watch?v=-3jx...

Great talk by Joe Bialek from MORSE team

16.12.2024 04:29 β€” πŸ‘ 18    πŸ” 7    πŸ’¬ 1    πŸ“Œ 0

Very cool!

31.01.2025 04:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Windows Bug Class: Accessing Trapped COM Objects with IDispatch Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...

New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...

30.01.2025 18:37 β€” πŸ‘ 66    πŸ” 42    πŸ’¬ 2    πŸ“Œ 0

In the past 6 months we’ve ported over 2,000 usermode accesses in ntoskrnl and securekernel to usermode accessors and discovered and fixed a handful of vulnerabilities in the process. I never thought we’d see such large scale refactoring

31.01.2025 03:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
windows-arm64 VM using qemu-system - Windows On Arm (WOA) - Confluence

Simple 3 steps to boot Arm64 WinVOS in QEMU (emulation mode).
linaro.atlassian.net/wiki/spaces/...

Boots in under a minute.

26.11.2024 16:35 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 2    πŸ“Œ 0
Preview
Microsoft Validation OS Microsoft Validation OS

TIL we published WinVOS, a super lightweight Windows SKU. This is a great way to debug ultra hot system calls and other things that are just too noisy on a full version of Windows. I use it for development. learn.microsoft.com/en-us/window...

26.11.2024 17:13 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I didnt realize we publish WinVOS, that’s awesome

26.11.2024 17:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

More usermode accessor improvements are landing in Windows 😊

26.11.2024 01:41 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Work-around for long-term issue in Cygwin's fork() running on Arm64 resolved.
Really appreciate the energy and collaboration with the @msys2org.bsky.social folks!

14.11.2024 03:17 β€” πŸ‘ 12    πŸ” 6    πŸ’¬ 1    πŸ“Œ 0

@josephbialek is following 20 prominent accounts