D_K Profile
D_K

@D_K_Dev

Followers
218
Following
100
Media
2
Statuses
42

IT-Security Student, @allesctf Member, Co-Founder and Security Researcher @neodyme

Joined July 2012
Don't wanna be here? Send us removal request.
@D_K_Dev
D_K
18 days
RT @DHM_ctf: Would you like to participate in the German Hacking Championship next year? 💻🎉Then, your next chance to qualify is this weeken….
0
1
0
@D_K_Dev
D_K
5 months
RT @C_S_C_G: The Cyber Security Challenge Germany 2025 has started! 🎉.The competition runs from March 1 - 18:00 CET to May 1 - 18:00 CEST.….
0
5
0
@D_K_Dev
D_K
7 months
RT @Neodyme: Following our #38c3 talk about exploiting security software for privilege escalation, we're excited to kick off a new blog ser….
0
22
0
@D_K_Dev
D_K
7 months
RT @Neodyme: ND people are @ #38c3 in Hamburg, Germany. Be sure to check out our two talks about LPEs in AV/EDR Products (Saturday, 4 PM YE….
0
4
0
@D_K_Dev
D_K
9 months
RT @Neodyme: Since we had used a different setup without any administrator account, our official attempt during #Pwn2Own failed. However, @….
0
2
0
@D_K_Dev
D_K
9 months
Now I could either reflash the emmc chip or use the nice USB-Boot mode of the custom U-Boot ;), though that required pulling Boot0 Pin high and a weird USB Flash drive config.
Tweet media one
2
0
8
@D_K_Dev
D_K
9 months
After some reversing and looking arround, I noticed the U-Boot version was 2017.11 . A quick search revealed CVE-2020-10648. A verified boot bypass for U-Boot. What was left was crafting a new fit image and using a custom initrd with the init command replaced, by a shell.
1
0
2
@D_K_Dev
D_K
9 months
Unfortunately everything else was encrypted with a key out of the tee. The U-Boot and everything after is also signed with keys, starting on the i.MX6 CPU. So patching the initrd was not possible.
1
0
3
@D_K_Dev
D_K
9 months
Disassembling the device, I quickly found UART pins. These were a great first find, but did not provide anything useful :/ Next, I tried to dump the firmware by desoldering the emmc chip. This got me lots of insights to the initrd.
Tweet media one
1
0
5
@D_K_Dev
D_K
9 months
After a great #Pwn2Own with @Neodyme , I would like to share some insights I gained when working with the AeoTec Smart Home Hub. We did not manage to find any bugs in time but dumping the firmware was a great lesson. So, let’s tell you the story of how I approached this target.
1
15
105
@D_K_Dev
D_K
9 months
RT @thezdi: Our final SOHO Smashup of Day 2 ends with a partial collision. Neodyme (@Neodyme) used 4 bugs, including a stack-based buffer o….
0
5
0
@D_K_Dev
D_K
9 months
RT @Neodyme: gg, this should fit nicely into our new office 🖨️. We'll be looking to complete the set tomorrow by attacking Lexmark CX331adw….
0
5
0
@D_K_Dev
D_K
9 months
RT @thezdi: Confirmed! Team Neodyme (@Neodyme) used a stack-based buffer overflow to exploit the HP Color LaserJet Pro MFP 3301fdw printer.….
0
7
0
@D_K_Dev
D_K
2 years
RT @allesctf: The cyber mimic defense starts soon thanks for the invitation. Good luck to all teams.
Tweet media one
0
2
0
@D_K_Dev
D_K
2 years
RT @redrocket_ctf: The @CyberSecRumble next year will be episch 🔥 :
Tweet media one
0
4
0
@D_K_Dev
D_K
2 years
RT @Neodyme: Introducing Riverguard 🏞️💂. A new security tool for Solana program deployers. 🧵. .
0
71
0
@D_K_Dev
D_K
2 years
RT @C_S_C_G: 1st place of the #ECSC2023: Team Germany 🎉 unexpected!! CYBER!!👏
Tweet media one
0
15
0
@D_K_Dev
D_K
2 years
RT @C_S_C_G: 🇩🇪 | Today, the @BSI_Bund hosted Germany's #ECSC team. These talented youngsters proved their skills during CSCG and will re….
0
4
0
@D_K_Dev
D_K
2 years
RT @allesctf: Are you also tired from teams stealing flags or organizers stealing 0days from organizers in CTFs?.Then you should play CCCam….
0
15
0
@D_K_Dev
D_K
2 years
RT @Neodyme: When CS:GO clients connected to our server, they got more than a game. We found 3 RCE vulnerabilities to give clients an unexp….
Tweet card summary image
neodyme.io
We identified three independent remote code execution (RCE) vulnerabilities in the popular Counter-Strike: Global Offensive game. Each vulnerability can be triggered when the game client connects to...
0
151
0