Ivan Fratric πŸ’™πŸ’› Profile
Ivan Fratric πŸ’™πŸ’›

@ifsecure

Followers
18K
Following
1K
Media
30
Statuses
1K

Security researcher at Google Project Zero. Author: Jackalope, TinyInst, WinAFL, Domato. PhD. Tweets are my own. Backup @[email protected]

Joined August 2011
Don't wanna be here? Send us removal request.
@ifsecure
Ivan Fratric πŸ’™πŸ’›
3 years
The slides for my Black Hat talk "XMPP Stanza Smuggling or How I Hacked Zoom" are now available at
3
66
277
@ifsecure
Ivan Fratric πŸ’™πŸ’›
8 days
RT @GoogleVRP: It is time to separate the vibe hackers πŸ€– from the hackers with vibe 😎. Google CTF June 27-29. Age….
0
90
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
21 days
In my recent conference talks on browser security, I showed a calc-popping exploit demo that targets Firefox 135.0. For educational purpuses, to try to demistify some of that calc popping magic, the demo code is now public
0
26
153
@ifsecure
Ivan Fratric πŸ’™πŸ’›
22 days
Some fun with a web browser without involving memory corruption.
@ProjectZeroBugs
Project Zero Bugs
22 days
Webkit: Cross-site CSS rule and redirect URL disclosure
0
6
40
@ifsecure
Ivan Fratric πŸ’™πŸ’›
23 days
This weekend, I gave a talk on web browser security research at a student-organized conference. I tried to make the talk reasonably beginner-friendly, so the slides (linked here) could hopefully be useful to someone as a learning resource.
3
133
524
@ifsecure
Ivan Fratric πŸ’™πŸ’›
1 month
RT @natashenka: The final part of @j00ru’s Windows Registry series is live! Contains all the hive memory corruption exploitation you’ve bee….
0
65
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
1 month
RT @ProjectZeroBugs: The Windows Registry Adventure #8: Practical exploitation of hive memory corruption
0
10
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
1 month
RT @ProjectZeroBugs: The Windows Registry Adventure #7: Attack surface analysis
0
23
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
1 month
RT @__sethJenkins: My OffensiveCon talk, Unexpectedly Excavating an ITW Exploit, is now available to watch!.
0
31
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
1 month
RT @_MatteoRizzo: The recording of our OffensiveCon presentation about EntrySign is live! Slides at .
0
21
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
1 month
RT @dillon_franke: Slides from my talk are here: And the recording is here!
0
18
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
1 month
And now the video is live too,
@ifsecure
Ivan Fratric πŸ’™πŸ’›
2 months
The slides for my OffensiveCon talk "Finding and Exploiting 20-year-old bugs in Web Browsers"
1
17
65
@ifsecure
Ivan Fratric πŸ’™πŸ’›
2 months
The slides for my OffensiveCon talk "Finding and Exploiting 20-year-old bugs in Web Browsers"
3
120
388
@ifsecure
Ivan Fratric πŸ’™πŸ’›
2 months
RT @dillon_franke: A bunch of new Apple patches just dropped, including another one found with my Mach message fuzzer πŸŽ‰ Fixed in Sequoia 15….
0
2
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
2 months
RT @dillon_franke: @offensive_con I've also open-sourced my fuzzing harness, custom instrumentation, and a PoC for CVE-2024-54529:. https:/….
0
20
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
2 months
RT @dillon_franke: Thrilled to announce my new Project Zero blog post is LIVE! πŸŽ‰ I detail my knowledge-driven fuzzing process to find sandb….
0
108
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
2 months
See you in Berlin!.
@offensive_con
offensivecon
2 months
2025 agenda is out!.
Tweet media one
0
0
25
@ifsecure
Ivan Fratric πŸ’™πŸ’›
3 months
RT @mattjay: 🧡 THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read. He's sayi….
0
30K
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
3 months
RT @R00tkitSMM: Pishi v-0.9 source code.
0
33
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
3 months
RT @itswillis: . and now, introducing Part 6 of @j00ru's work on the Windows Registry:. . πŸ“–πŸ‘€.
0
22
0
@ifsecure
Ivan Fratric πŸ’™πŸ’›
3 months
RT @R00tkitSMM: My new blog post, which I presented at #Zer0Con2025.binary level macOS KEXT kernel address sanitizer. .
0
84
0