SpecterDev Profile Banner
Specter Profile
Specter

@SpecterDev

Followers
38K
Following
2K
Media
59
Statuses
1K

Interested in Security and Exploit Development. Nano is the one true text editor.

🇨🇦 Ontario
Joined August 2015
Don't wanna be here? Send us removal request.
@SpecterDev
Specter
10 months
My @dayzerosec co-host zi and I are giving our 1st training @ https://t.co/Na25TGbLQE with a focus on attacking security hypervisors! Trainings are something we've wanted to do for a while. Take a look and share to those who would be interested :) https://t.co/zM6QJjPcrk
7
36
211
@theflow0
Andy Nguyen
1 month
RIP, my PlayStation exploit died. https://t.co/gRmjKcqKFJ Works upto PS4 13.00 and PS5 12.00. Patched on PS4 13.02 and PS5 12.02.
168
313
3K
@SpecterDev
Specter
5 months
Some people already know this, but thought I'd mention here too... unfortunately basically all of my low fw PS5s got stolen recently, so I'm not sure what my future in console research will look like. Replacing this stuff might be too be difficult & expensive to be worth it :(
43
26
321
@dayzerosec
DAY[0]
8 months
We have a special episode this week, where we interview @JohnCarse of @getsquarex. We talk about John's industry experience, history of browser security, and the work SquareX is doing on detecting and mitigating browser-based attacks. Check it out:
0
1
30
@SpecterDev
Specter
10 months
My @dayzerosec co-host zi and I are giving our 1st training @ https://t.co/Na25TGbLQE with a focus on attacking security hypervisors! Trainings are something we've wanted to do for a while. Take a look and share to those who would be interested :) https://t.co/zM6QJjPcrk
7
36
211
@hardwear_io
hardwear.io
9 months
We have a training by @SpecterDev & Zi on Attacking Hypervisors From KVM to Mobile Security Platforms
@SpecterDev
Specter
9 months
I've published a write-up on reversing and analyzing Samsung's H-Arx hypervisor architecture for Exynos devices, which has had a lot of changes in recent years and pretty interesting design. Hope you all enjoy :) https://t.co/KTJ5IKfSfP
0
8
41
@SpecterDev
Specter
9 months
I've published a write-up on reversing and analyzing Samsung's H-Arx hypervisor architecture for Exynos devices, which has had a lot of changes in recent years and pretty interesting design. Hope you all enjoy :) https://t.co/KTJ5IKfSfP
Tweet card summary image
dayzerosec.com
In many ways, mobile devices lead the security industry when it comes to defense-in-depth and mitigation. Over the years, it has been proven time and again that the kernel cannot be trusted to be...
3
113
504
@reconmtl
REcon
10 months
Recon Training 23-26 June 2025: KVM to Mobile Security Platforms - Attacking Hypervisors with @SpecterDev and zi from @dayzerosec (4 days) For more details https://t.co/3MM2tIkcyS
0
8
36
@SpecterDev
Specter
1 year
RE: byepervisor do people care enough about not wanting to use rest mode and resume to switch the primary exploit for byepervisor to the jump table one? its higher maintenance and possibly slightly less stable but would be slightly more convenient to run I guess
21
13
107
@SpecterDev
Specter
1 year
Slides
Tweet card summary image
github.com
A PS5 hypervisor exploit for 1.xx-2xx firmwares. Contribute to PS5Dev/Byepervisor development by creating an account on GitHub.
@SpecterDev
Specter
1 year
I've published the repo for Byepervisor (we love named vulns out here). Contains exploit implementation for two PS5 hypervisor bugs for 2.xx and lower. Slides from the talk + vod should hopefully be published soon. https://t.co/YBrHXOpzQA
9
50
285
@SpecterDev
Specter
1 year
I've published the repo for Byepervisor (we love named vulns out here). Contains exploit implementation for two PS5 hypervisor bugs for 2.xx and lower. Slides from the talk + vod should hopefully be published soon. https://t.co/YBrHXOpzQA
Tweet card summary image
github.com
A PS5 hypervisor exploit for 1.xx-2xx firmwares. Contribute to PS5Dev/Byepervisor development by creating an account on GitHub.
42
123
655
@hardwear_io
hardwear.io
1 year
The PS5's hypervisor has kept the system secure for years—now, vulnerabilities are being revealed. What does this mean for gamers? 🕵️‍♂️🚨 Join @SpecterDev at #hw_ioNL2024 Know More: https://t.co/DeEfBFw7gi #ps5 #exploit #hardware
8
36
230
@flat_z
Aleksei Kulaev
1 year
There are a few ways on PS5 to defeat HV. One of methods that I've found was related to APIC: struct apic_ops is located in RW segment of kernel data. With KRW you can overwrite a function pointer inside it like xapic_mode and get into ROP, for example (just need to bypass CFI).
31
64
593
@SpecterDev
Specter
1 year
Feels great when an idea can finally be tested and works out after like a year :) Shouts to ChendoChap for working out the ROP chain. Protip: staying < 3.00 is a good idea.
53
94
777
@SpecterDev
Specter
1 year
Pushed v1.2, exploit's been updated with an implementation that works on 3.xx-5.xx (heap spray go brrr), also some support for other misc low fw. ELF loader and payloads will not work on 5.00+ for a while due to dlsym changes. Payload SDK needs changes. https://t.co/UBqga8fA5U
Tweet card summary image
github.com
Add support for 5.00, 5.02, 5.10, and 5.50FW Add support for 4.00, 4.02, 4.03, 4.50FW Add support for 3.00 and 3.20FW Add support for 2.70 factory FW Add support for 1.00 and 1.02 FW Added code to ...
64
79
532
@SpecterDev
Specter
1 year
Added 1.xx firmware support to UMTX exploit chain.
Tweet card summary image
github.com
Add support for 1.05, 1.10, 1.11, 1.12, 1.13, 1.14 firmwares Various minor fixes
28
42
400
@SpecterDev
Specter
1 year
I've published a webkit implementation of UMTX exploit for PS5 on 2.xx firmwares. Hoping to add support for 1.xx firmwares soon, higher firmwares will take some changes to make it work. See README for details as always. https://t.co/g1kk14IVby
Tweet card summary image
github.com
A webkit-based kernel exploit and jailbreak for PS5 - PS5Dev/PS5-UMTX-Jailbreak
67
119
635
@SpecterDev
Specter
1 year
70
101
798