Damian Pfammatter
@dp__pd
Followers
35
Following
47
Media
2
Statuses
13
Joined January 2018
First two unauthenticated RCE CVEs published - Discovered with the help of our #Binja plugin #Mole! 🔗 Advisory: https://t.co/tgb42PVnyx 🔗 Mole: https://t.co/J3NwT2iWkK More vulnerabilities have been reported - stay tuned for upcoming advisories.
github.com
A Binary Ninja plugin to identify interesting paths using static backward slicing - cyber-defence-campus/mole
0
2
5
Static pointer tracking is tricky. Just shipped some improvements to my #BinaryNinja plugin #Mole: it now tracks array and struct members more precisely. An example on how Mole does this: https://t.co/4FQOPA1l1F Binja's multiple ILs make precise analysis so much more powerful!
0
0
1
#Morion has been accepted for @BlackHatEvents #BHEU and will be presented at #BlackHatArsenal this December in London! https://t.co/M6HcumYu1Y
0
0
0
I've written a detailed showcase to highlight some of the tool's features (and current limitations). The showcase illustrates how the tool can, for example, help assess if a bug is exploitable and if so, assist in crafting a functional exploit: https://t.co/zPviKloeiW
github.com
Demonstrate some functionalities of Morion by generating an exploit for CVE-2022-27646 (stack buffer overflow on Netgear R6700v3 routers). - cyber-defence-campus/netgear_r6700v3_circled
1
0
1
A while back, I wanted to learn about @qb_triton and symbolic execution in general, and to research its challenges when it comes to real-world binaries. What began with a few simple scripts evolved into PoC tool called Morion, which I've just released. #symbex #libtriton #morion
1
4
9
If you are attending #EuroSP22 and are interrested in our work or the @cydcampus in general, let us know. We are happy to discuss!
0
0
3
How to setup network monitoring for your home IP in 4 easy steps using the Shodan CLI: https://t.co/d4Srj5nxfA
3
176
428
Great audience at my talk and a nice @swisscyberstorm coference in general. Leaving with plenty of new ideas to extend my research...
You missed the interesting @swisscyberstorm talk "Hidden Inbox Rules in Microsoft Exchange" by @dp__pd? All infos about his research and the attack can be found here: https://t.co/M7zfbRiUZu
#SCS18
0
0
2
Compass Security Blog: Hidden inbox rules in Microsoft Exchange… or how to secretly steal your messages. Topic presented at this year’s @swisscyberstorm. #DFIR
https://t.co/iG3oHgOs39
0
8
12