2OURC3
@2ourc3
Followers
2K
Following
11K
Media
31
Statuses
694
https://t.co/PhUNBKK4hn | @auditor_codes
Joined February 2021
I'm still looking for two (2) tickets for 39c3 for my friends, who otherwise would be forced to dress as service-dog to maybe have a chance to enter the conference. If any of you got a plug please hit me up!
12
0
11
Read my latest article: Introduction to root-cause analysis on Linux:
1
12
38
Hey fuzzer folks! Want to learn how to use LibAFL ? Check this super exercices made by @addisoncrump_vr
https://t.co/SvyjY84UzK
github.com
Learn to LibAFL with parking-game puzzles. Contribute to addisoncrump/parking-game-fuzzer development by creating an account on GitHub.
2
25
101
New bug I've reported: CVE-2025-52194 - IRCAM File Processing Buffer Overflow in LibSndfile Write-up:
0
3
13
I'm quite happy to share that Apple have published a vulnerability I have reported. This vulnerability affects multiple MacOS versions and affects the program `file`. First bug in Apple product 🥳
6
2
48
Introducing Havoc Professional: A Lethal Presence We’re excited to share a first look at Havoc Professional, a next-generation, highly modular Command and Control framework, and Kaine-kit our fully Position Independent Code agent engineered for stealth! https://t.co/0aPVihoFIU
infinitycurve.org
An introduction to Havoc Professional and Kaine-kit, exploring the advanced features and capabilities that make them lucrative for modern security professionals.
56
186
745
Joining @rektoff_xyz bootcamp about Solana Rust Security! Really thrilled and thankful to start this one :D
0
0
7
Releasing this fun tool Golem based on @0xdea, LLVM, LLM and @semgrep Golem automates C/C++ vulnerability discovery by combining Semgrep rule scans, LLVM call-graph & CFG slicing, and AI-driven context analysis. Tool: https://t.co/BX9a2nSZXi Article:
bushido-sec.com
Discover how combining SemGrep, LLVM, and local LLMs like Ollama can boost vulnerability research. From funny IKEA frustrations to slicing control-flow graphs, meet Golem—your new automated bug...
6
44
127
turns out running thing on server and locally are not the same, who would have guess???
0
0
2
Note: It's a BETA, it's vibe coded A LOT, it doesnt handle any sensitive info, please report bugs if you find some (you will) thanks kiss kiss
2
0
1
Just launched Code Auditor CTF — https://t.co/S87nvpjfht A web platform to practice finding real-world C/C++ vulnerabilities • 8000+ challenges • Progress tracking + leaderboard • Beginner-friendly • Fully open source (beta):
github.com
The most complete code auditing platform with thousands of real-world challenges - 20urc3/auditor.codes
12
145
580
Write-up of my v8 bug: Critical type confusion in V8's Turboshaft compiler allowed stale pointers to bypass GC, leading to exploitable memory corruption. Full details + PoC:
bushido-sec.com
V8 Turboshaft Load Elimination Type Confusion Vulnerability (CVE-2024-6773)Exploitable Memory Corruption via Garbage Collection Race Condition Executive Summary A critical type confusion vulnerabil...
2
61
245
I wrote a comprehensive guide on harnessing libraries for effective fuzzing with AFL++ ! Have a look =>
github.com
This repository contains the public work I produced, wheter it is research, post, slides, sometimes videos, and materials of my talks. - 20urc3/Publications
2
18
112
🥳CVE-2024-53589: I discovered a heap buffer-overflow vulnerability in objdump affecting version 2.43, during a fuzzing campaign with @aflplusplus More details:
bushido-sec.com
Security vulnerability in GNU Binutils 2.43 objdump allows buffer overflow via malformed tekhex files, potentially leading to information disclosure and ASLR bypass.
7
24
118
Following 7zip 24.08 release, @thezdi disclosed yesterday my vulnerability in 7zip 24.07: CopyCoder Infinite Loop Denial-of-Service Vulnerability - CVE-2024-11612 I found this vulnerability last summer during a fuzzing campaign with @aflplusplus
https://t.co/v4UVV7TOGt
bushido-sec.com
7zip vulnerability disclosure infinite loop results in DoS attack
11
12
81
My talk at lehack! Hacking satellites from SDR to RCE
🇫🇷 Hacking Satellites: From SDR to RCE - Salim LARGO - 2ourc3 https://t.co/QH0DtBYRtD
2
2
13