2ourc3 Profile Banner
2OURC3 Profile
2OURC3

@2ourc3

Followers
2K
Following
11K
Media
31
Statuses
677

building things - breaking others | @auditor_codes

Joined February 2021
Don't wanna be here? Send us removal request.
@2ourc3
2OURC3
29 days
I'm quite happy to share that Apple have published a vulnerability I have reported. This vulnerability affects multiple MacOS versions and affects the program `file`. First bug in Apple product 🥳
Tweet media one
5
2
47
@grok
Grok
13 hours
Join millions who have switched to Grok.
51
83
744
@2ourc3
2OURC3
2 months
RT @C5pider: Introducing Havoc Professional: A Lethal Presence. We’re excited to share a first look at Havoc Professional, a next-generatio….
Tweet card summary image
infinitycurve.org
An introduction to Havoc Professional and Kaine-kit, exploring the advanced features and capabilities that make them lucrative for modern security professionals.
0
184
0
@2ourc3
2OURC3
2 months
Joining @rektoff_xyz bootcamp about Solana Rust Security! Really thrilled and thankful to start this one :D
Tweet media one
0
0
6
@2ourc3
2OURC3
2 months
Releasing this fun tool Golem based on @0xdea, LLVM, LLM and @semgrep . Golem automates C/C++ vulnerability discovery by combining Semgrep rule scans, LLVM call-graph & CFG slicing, and AI-driven context analysis. Tool: Article:
Tweet card summary image
bushido-sec.com
Discover how combining SemGrep, LLVM, and local LLMs like Ollama can boost vulnerability research. From funny IKEA frustrations to slicing control-flow graphs, meet Golem—your new automated bug...
6
44
125
@2ourc3
2OURC3
3 months
turns out running thing on server and locally are not the same, who would have guess???.
0
0
2
@2ourc3
2OURC3
3 months
Note: It's a BETA, it's vibe coded A LOT, it doesnt handle any sensitive info, please report bugs if you find some (you will) thanks kiss kiss.
2
0
1
@2ourc3
2OURC3
3 months
Just launched Code Auditor CTF — A web platform to practice finding real-world C/C++ vulnerabilities.• 8000+ challenges.• Progress tracking + leaderboard.• Beginner-friendly.• Fully open source (beta):
Tweet card summary image
github.com
The most complete code auditing platform with thousands of real-world challenges - 20urc3/auditor.codes
12
146
586
@2ourc3
2OURC3
7 months
Write-up of my v8 bug: Critical type confusion in V8's Turboshaft compiler allowed stale pointers to bypass GC, leading to exploitable memory corruption. Full details + PoC:
Tweet card summary image
bushido-sec.com
V8 Turboshaft Load Elimination Type Confusion Vulnerability (CVE-2024-6773)Exploitable Memory Corruption via Garbage Collection Race Condition Executive Summary A critical type confusion vulnerabil...
3
64
248
@2ourc3
2OURC3
8 months
I wrote a comprehensive guide on harnessing libraries for effective fuzzing with AFL++ ! . Have a look =>
Tweet card summary image
github.com
This repository contains the public work I produced, wheter it is research, post, slides, sometimes videos, and materials of my talks. - 20urc3/Publications
2
19
112
@2ourc3
2OURC3
8 months
✨️ Happy new year hackers! ✨️.
1
0
8
@2ourc3
2OURC3
8 months
Going to #38c3 was on my wishlist for MANY years. I am extremely happy to have been able to attend this super fun con for the first time, I've watch many great talks, met a bunch of really cool nerds and loved the hacking atmosphere! ✨️
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
1
10
@2ourc3
2OURC3
9 months
🥳CVE-2024-53589: I discovered a heap buffer-overflow vulnerability in objdump affecting version 2.43, during a fuzzing campaign with.@aflplusplus. More details:
Tweet card summary image
bushido-sec.com
Security vulnerability in GNU Binutils 2.43 objdump allows buffer overflow via malformed tekhex files, potentially leading to information disclosure and ASLR bypass.
7
25
119
@2ourc3
2OURC3
9 months
Following 7zip 24.08 release, @thezdi disclosed yesterday my vulnerability in 7zip 24.07: CopyCoder Infinite Loop Denial-of-Service Vulnerability - CVE-2024-11612. I found this vulnerability last summer during a fuzzing campaign with @aflplusplus .
Tweet card summary image
bushido-sec.com
7zip vulnerability disclosure infinite loop results in DoS attack
11
12
82
@2ourc3
2OURC3
11 months
My talk at lehack! Hacking satellites from SDR to RCE.
@_leHACK_
leHACK
11 months
🇫🇷 Hacking Satellites: From SDR to RCE - Salim LARGO - 2ourc3.
2
2
13
@2ourc3
2OURC3
1 year
It was a fantastic experience giving a talk about automated vulnerability research for SANS today. Grateful for this opportunity, very happy to meet all the other fantastic speakers there.
Tweet media one
Tweet media two
5
2
27
@2ourc3
2OURC3
1 year
Really proud! My vulnerability in Chrome v8 has been disclosed today! CVE-2024-6773 Type confusion in the v8 engine.
Tweet media one
13
16
172
@2ourc3
2OURC3
1 year
@_leHACK_ Thanks to all the persons that attended the conference, to leHack's team for putting this amazing event together, and to my friends for coming supporting me.
0
0
2
@2ourc3
2OURC3
1 year
It's a wrap! Yesterday I was presenting my first public talk at @_leHACK_ : Hacking Satellites from SDR to RCE. You can find the slides (and all the funny things) here:
Tweet media one
6
36
230
@2ourc3
2OURC3
1 year
Join meet at @_leHACK_ for my talk: Hacking satellites: From SDR to RCE. 👾.
@_leHACK_
leHACK
1 year
[🎙️ #Talk] Discover #leHACK 2024 talk: Hacking satellites: From SDR to RCE presented by @2ourc3 . 📅 Saturday, July 6th.⌚ 14:45.ℹ️ Details: .🎟️ Tickets:
4
1
15