ESultanik Profile Banner
Evan Sultanik Profile
Evan Sultanik

@ESultanik

Followers
1K
Following
4K
Media
235
Statuses
3K

Ph.D. computer security researcher @TrailOfBits. Editor of and frequent contributor to #pocorgtfo. My CV is a PDF that’s also an NES ROM https://t.co/lDrC4Hz6AI

Philadelphia, PA, USA
Joined December 2008
Don't wanna be here? Send us removal request.
@ESultanik
Evan Sultanik
5 years
After 6 months and over 5k new lines of 6502 assembly, the Kaizo-style platforming section of the NES game in my résumé is finally done! Yes, among other things, the PDF of my résumé is also an NES ROM. You can download it here for your emulating pleasure: https://t.co/NBbr5kVhqN
Tweet media one
Tweet media two
Tweet media three
4
49
185
@trailofbits
Trail of Bits
17 days
Solving the Traveling Salesman Problem for NYC's 474-station subway network, obviously! @ESultanik used Christofides algorithm to find a 20h 42min route through all 474 stations, which would beat the world record by 45 minutes.
Tweet card summary image
blog.trailofbits.com
We optimized the route for visiting every NYC subway station using algorithms from combinatorial optimization, creating a 20-hour tour that beats the existing world record by 45 minutes.
1
7
28
@suhackerr
Suha
21 days
New post and tool! Attackers can break production AI systems by using image scaling to hide multi-modal prompt injections from users. 🧵for more info on what broke, how this works, and our new tool to try this out yourself
@trailofbits
Trail of Bits
21 days
We hacked Gemini CLI, Vertex AI, Assistant, and other AI systems by embedding prompts into images that are not visible to users.
Tweet media one
4
52
202
@trailofbits
Trail of Bits
1 month
A wild Buttercup appears! Our @DARPA AI Cyber Challenge CRS is in the @BSidesLV Silent Auction. Bid on this encrypted limited edition!
Tweet media one
0
3
14
@trailofbits
Trail of Bits
7 months
Our new whitepaper covers secure-by-design steps that CEXes can take to keep users' accounts (and funds) safe from account takeover (ATO) in 2025. (Read more 👇)
Tweet media one
2
11
60
@ESultanik
Evan Sultanik
8 months
“It came to me in a dream.” Olivier salad roll.
Tweet media one
1
0
3
@angealbertini
Ange
10 months
When working on Magika (Google's AI-powered content-type detection), I checked other file formats KBs and detection engines to create filesets to train the model on. I gave a talk at HackLu to share an overview of the existing engines. https://t.co/arOmJNOgh6
Tweet card summary image
speakerdeck.com
Yara, LibMagic (file, binwalk, polyfile), TrID, Yara, Magika, PeID, Pronom, FDD, ShareMime, DiE... How do they work? What are their pros and cons, th…
5
27
83
@ESultanik
Evan Sultanik
11 months
Any idea why AA’s website is offering itineraries with legs operated by Lufthansa Group? 🤯 @thenonstopdan @AlexInAir
Tweet media one
2
0
2
@sergeybratus
sergey bratus
1 year
It's great to see Multiplier by @trailofbits being open-sourced! https://t.co/9r1WfebMIv I believe it exemplifies the kind of foundational, next-generation tools we need for proper software understanding, maintenance, and sustainment.
Tweet card summary image
github.com
Code auditing productivity multiplier. Contribute to trailofbits/multiplier development by creating an account on GitHub.
1
34
130
@ESultanik
Evan Sultanik
1 year
Even Telegram “secret chats” can be subverted by the server.
@paulmillr
Paul Miller
1 year
This is your regular reminder that “secret chats” in telegram rely on server-provided prime numbers (messages.getDhConfig). The server could send “bad” prime numbers to clients and decrypt conversations later. Section 1.2.1 of tel-03245433
0
0
0
@ESultanik
Evan Sultanik
1 year
I hate to be “reviewer #2”, but I’m a bit disappointed that my prior work was not cited
sultanik.com
Might the Ballmer Peak be an actual phenomena? posted Thursday September 1st, 2011
@d_feldman
Daniel 🦋
1 year
The Ballmer Peak is real !
Tweet media one
Tweet media two
0
0
2
@cerias
CERIAS at Purdue U.
1 year
This Wednesday, April 10th, 4:30pm ET: "In Pursuit of Silent Flaws: Dataflow Analysis for Bugfinding and Triage" Evan Sultanik @ESultanik - Trail of Bits @trailofbits https://t.co/OD379DZvkS Live on Zoom.
Tweet media one
0
1
3
@ESultanik
Evan Sultanik
2 years
Tweet media one
Tweet media two
0
0
0
@ESultanik
Evan Sultanik
2 years
I had to try this myself. @trailofbits was apparently founded by @DanielMiessler and Elijah Savage, not @dguido and @alexsotirov. It is known for having created the fastest open-source password cracker in the world, @shellphish.
Tweet media one
7
3
9
@travisgoodspeed
Travis Goodspeed
2 years
MD5 4d37c6712a2239962005eda3be6367b4
Tweet media one
4
89
277
@trailofbits
Trail of Bits
2 years
Today, we are disclosing LeftoverLocals, a vulnerability that allows listening to LLM responses through leaked GPU local memory created by another process on Apple, Qualcomm, AMD, and Imagination GPUs (CVE-2023-4969) https://t.co/rIqfClarLJ
11
225
935
@trailofbits
Trail of Bits
2 years
We assessed the YOLOv7 vision model and identified 11 security vulnerabilities that could enable RCE, DoS, and model differentials. We do not recommend using the codebase for mission-critical applications or applications that require high availability. https://t.co/FXmg314Uib
3
28
88
@ESultanik
Evan Sultanik
2 years
Paged Out! is such a great zine, I can’t wait for issue 3!
@gynvael
Gynvael Coldwind
2 years
I'm looking at the old @pagedout_zine articles and I realized it always hits me how amazing these are. Having to fit one's idea on a single fully-controlled page brings out A LOT of creativity in folks :) https://t.co/O2QRpYfKAI https://t.co/2C79XfPyJW
0
0
2