Congratulations to Carl Smith from v8 Security team and join Blackhat USA review board as guest reviewer. He is willing to share, open-minded, and a hardcore researcher and developer.
@rwx.page
20.02.2025 14:12 β π 2 π 1 π¬ 0 π 0
Unfortunately not, we are planning on sharing more details in form of talks in the future though.
05.02.2025 15:53 β π 1 π 0 π¬ 0 π 0
And make sure to update to the latest swift version too!
04.02.2025 19:35 β π 1 π 0 π¬ 0 π 0
Some slides discussing some of this work can be found here:
https://powerofcommunity.net/poc2024/Carl%20Smith,%20Fuzzing%20for%20complex%20bugs%20across%20languages%20in%20JavaScript%20Engines.pdf
04.02.2025 19:35 β π 3 π 0 π¬ 2 π 0
Iβm very excited to announce that we at V8 Security have finally published our first version of Fuzzilli that understands Wasm!
Go check it out at https://github.com/googleprojectzero/fuzzilli.
While we still have a way to go in improving it, we think it shows a promising approach!
04.02.2025 19:34 β π 31 π 16 π¬ 1 π 1
Chrome Vulnerability Reward Program Rules | Google Bug Hunters
ATTENTION As of 4 February 2024, Chromium has migrated to a new issue tracker, please report security bugs to the new issue tracker using this form . Please see the Chrome VRP News and FAQ page for mo...
Another big step towards becoming a security boundary: today weβre expanding the VRP for the V8 Sandbox
* No longer limited to d8
* Rewards for controlled writes increased to $20k
* Any memory corruption outside the sandbox is now in scope
bughunters.google.com/about/rules/...
Happy hacking!
13.11.2024 18:05 β π 27 π 10 π¬ 1 π 0
Finally got around to publishing the slides of my talk @offensivecon.bsky.social from ~two weeks ago. Sorry for the delay!
The V8 Heap Sandbox: saelo.github.io/presentation...
Fantastic conference, as usual! :)
22.05.2024 19:01 β π 4 π 5 π¬ 0 π 1
V8 Sandbox - Trusted Space
V8 Sandbox - Trusted Space Author: saelo@ First Published: October 2023 Last Updated: October 2023 Status: Living Doc Visibility: PUBLIC This document is part of the V8 Sandbox Project and discusses...
Here's another V8 sandbox design document, this time discussing how sensitive ("trusted") V8-internal objects (such as BytecodeArrays) can be protected: docs.google.com/document/d/1...
This should be one of the last pieces of infrastructure required for the sandbox.
20.10.2023 13:34 β π 7 π 2 π¬ 1 π 0
One day, @rwx.page and me got bored and built a tiny command line game with 0 deps in π¦.
`cargo install quarto`
It's not much but it's honest work :)
https://github.com/domenukk/quarto_rs
12.08.2023 00:34 β π 1 π 1 π¬ 0 π 0
Co-director of the Nuclear Policy Program at the Carnegie Endowment For International Peace. I spend a lot of time thinking about nuclear weapons, advanced nonnuclear technology, and escalation.
Retired DEFCON CTF org.
Shellphish Captain Emeritus.
ASU Prof.
angr hacker.
pwn.college sensei.
Looking for students/interns!
https://yancomm.net
https://github.com/zardus
https://defcon.social/@Zardus
Security Engineer @ XTX. MSc in eng. physics & CompSci, dev & gamer. β€οΈ music & long distance running. Wanna do a PhD sometime. Same U/N on all other sites
high-frequency transsexual (@mxemilymode on twitter)
union square greenmarket enjoyer
nyc she/her
A programming language empowering everyone to build reliable and efficient software.
Website: https://rust-lang.org/
Blog: https://blog.rust-lang.org/
Mastodon: https://social.rust-lang.org/@rust
Offizieller Kanal des SV #Werder Bremen
Englisch: @en.werder.de | Spanisch: @es.werder.de
Senior Lecturer in Cyber Secutity at @UniMelb & ARC DECRA Fellow. Prev @MonashInfotech & @NUSComputing . (Fuzz) Testing enthusiast.
Security @ Google - cpu bugz
Nova JavaScript engine developer and OSS contributor by day and night. Avid choir singer. He/him.
Give me data-oriented design or else (I will cry).
https://trynova.dev/
Working on WebAssembly / wasm in V8 | Opinions are my own
π§βπ» finding flags @fluxfingers.net
π finding bugs @ Cure53
he/him
https://realansgar.dev
I work on manager/security things for a non-profit software company. I love my family, my bike and reading books.
You can also find me on Mastodon as @freddy@security.plumbing, which I consider my primary account.
Homepage: https://frederikbraun.de/
CTF Player with FluxFingers | Ph.D. Student
CTF @FluxFingers.net, Infosec @Ruhr-Uni-Bochum.de
Participating in Capture the Flag security competitions representing @ruhr-uni-bochum.de since 2007. Also, organizers of annual Hack.lu CTF.
Web: https://FluxFingers.net