
2OURC3
@2ourc3
Followers
2K
Following
11K
Media
31
Statuses
677
building things - breaking others | @auditor_codes
Joined February 2021
New bug I've reported: CVE-2025-52194 - IRCAM File Processing Buffer Overflow in LibSndfile. Write-up:
bushido-sec.com
A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header...
0
3
12
RT @C5pider: Introducing Havoc Professional: A Lethal Presence. We’re excited to share a first look at Havoc Professional, a next-generatio….
infinitycurve.org
An introduction to Havoc Professional and Kaine-kit, exploring the advanced features and capabilities that make them lucrative for modern security professionals.
0
184
0
Joining @rektoff_xyz bootcamp about Solana Rust Security! Really thrilled and thankful to start this one :D
0
0
6
Releasing this fun tool Golem based on @0xdea, LLVM, LLM and @semgrep . Golem automates C/C++ vulnerability discovery by combining Semgrep rule scans, LLVM call-graph & CFG slicing, and AI-driven context analysis. Tool: Article:
bushido-sec.com
Discover how combining SemGrep, LLVM, and local LLMs like Ollama can boost vulnerability research. From funny IKEA frustrations to slicing control-flow graphs, meet Golem—your new automated bug...
6
44
125
Just launched Code Auditor CTF — A web platform to practice finding real-world C/C++ vulnerabilities.• 8000+ challenges.• Progress tracking + leaderboard.• Beginner-friendly.• Fully open source (beta):
github.com
The most complete code auditing platform with thousands of real-world challenges - 20urc3/auditor.codes
12
146
586
Write-up of my v8 bug: Critical type confusion in V8's Turboshaft compiler allowed stale pointers to bypass GC, leading to exploitable memory corruption. Full details + PoC:
bushido-sec.com
V8 Turboshaft Load Elimination Type Confusion Vulnerability (CVE-2024-6773)Exploitable Memory Corruption via Garbage Collection Race Condition Executive Summary A critical type confusion vulnerabil...
3
64
248
I wrote a comprehensive guide on harnessing libraries for effective fuzzing with AFL++ ! . Have a look =>
github.com
This repository contains the public work I produced, wheter it is research, post, slides, sometimes videos, and materials of my talks. - 20urc3/Publications
2
19
112
🥳CVE-2024-53589: I discovered a heap buffer-overflow vulnerability in objdump affecting version 2.43, during a fuzzing campaign with.@aflplusplus. More details:
bushido-sec.com
Security vulnerability in GNU Binutils 2.43 objdump allows buffer overflow via malformed tekhex files, potentially leading to information disclosure and ASLR bypass.
7
25
119
Following 7zip 24.08 release, @thezdi disclosed yesterday my vulnerability in 7zip 24.07: CopyCoder Infinite Loop Denial-of-Service Vulnerability - CVE-2024-11612. I found this vulnerability last summer during a fuzzing campaign with @aflplusplus .
bushido-sec.com
7zip vulnerability disclosure infinite loop results in DoS attack
11
12
82