George Hughey Profile
George Hughey

@ecthr0s

Followers
558
Following
151
Media
3
Statuses
62

MSRC Engineering - previously CS @ University of Maryland working on Geneva (https://t.co/dMYqBnn2oA)

Seattle, WA
Joined June 2018
Don't wanna be here? Send us removal request.
@ecthr0s
George Hughey
6 months
We're super proud of this work - it took a lot of poking around in Windows Internals and a huge effort from Engineering to fix all these issues. Many thanks to all who worked on these :).
2
0
3
@ecthr0s
George Hughey
6 months
As many of these exploit differences in CreateFile and MUTZ, we've duplicated some of the behavior in CreateFile. This should help prevent similar bypasses in the future. We're planning on releasing more info about this research over the coming months, so stay tuned!.
2
0
1
@ecthr0s
George Hughey
6 months
This week's Patch Tuesday included 8 CVEs that @rohitwas and I found! . We've been focusing on findings ways to bypass MapUrlToZone and found several very interesting ways to confuse it. This is an API we've seen a lot of interest in lately, so good to have it locked down!
Tweet media one
3
3
44
@ecthr0s
George Hughey
7 months
RT @msftsecresponse: To help protect against NTLM relay attacks, we’ve enabled Extended Protection for Authentication (EPA) by default in W….
0
44
0
@ecthr0s
George Hughey
10 months
When I started I honestly didn't think I would ever find a CVE, so it's cool to get all the way up to 50!.
1
0
9
@ecthr0s
George Hughey
10 months
My 50th CVE came out in today's Patch Tuesday! CVE-2024-38240 is the last of some hardening we've been doing in a Windows service, and CVE-2024-38252/CVE-2024-38253 are two proactive efforts we worked on with some static analysis friends :).
3
1
44
@ecthr0s
George Hughey
1 year
RT @dragosr: CanSecWest Presentation:. Rolling in the Dough: How Microsoft Identified and Remediated a Baker’s Dozen of Security Threats in….
0
1
0
@ecthr0s
George Hughey
2 years
I'm hoping to give a conference talk/blog post on the DNS Admin research, methodology, and fix process we've been doing soon(ish), so stay tuned!.
2
2
15
@ecthr0s
George Hughey
2 years
Yesterday's Patch Tuesday saw the release of 10 CVEs I found in DNS! These could potentially allow an authenticated attacker to gain remote code execution. A huge thank you to the DNS team who worked through and fixed these.
Tweet media one
5
28
113
@ecthr0s
George Hughey
2 years
Forget buffaloes, the longest grammatically correct sentence using one repeating word is "sudo sudo sudo sudo sudo sudo sudo sudo sudo".
1
0
5
@ecthr0s
George Hughey
3 years
Yesterday, a vulnerability in DNS I found was patched: Thanks to the DNS team for working through this one!.
2
6
34
@ecthr0s
George Hughey
3 years
Tuesday saw the release of fixes for four vulnerabilities I discovered (CVE-2022-26801, CVE-2022-26802, CVE-2022-26803, CVE-2022-24536). Go check them out!
2
7
18
@ecthr0s
George Hughey
5 years
RT @DistributedDave: It's long been assumed that there are no nontrivial reflected amplification attacks using TCP—prior attacks are UDP or….
0
61
0
@ecthr0s
George Hughey
5 years
Talk from #BlueHatIL is live! Had such an awesome experience
0
2
7
@ecthr0s
George Hughey
5 years
RT @n0x08: - I should point out that many of the #BlueHatIL talks are up online here including my personal favorite….
0
2
0
@ecthr0s
George Hughey
5 years
Just posted our slides from BlueHat IL 2020 at Huge thank you to @tom41sh and the rest of the BlueHat team, we were really honored to be there :).
0
0
8
@ecthr0s
George Hughey
5 years
RT @OhadMZ: Very interesting session at #bluehatil about evading nation-state #censorship with AI methods (#Geneva project). Implanted alre….
0
7
0
@ecthr0s
George Hughey
5 years
RT @n0x08: Groundbreaking research being presented today at #BlueHatIL. TheMentor comes to mind: “We seek.after knowledge and you call us….
0
3
0
@ecthr0s
George Hughey
5 years
RT @BlueHatIL: The wait is finally over! Registration & schedule for #BlueHatIL 2020 are live. Places are limited so register NOW: https://….
0
55
0
@ecthr0s
George Hughey
5 years
Can't wait to present Geneva in a couple weeks at @BlueHatIL! .
0
0
10