the_secret_club Profile Banner
secret club Profile
secret club

@the_secret_club

Followers
17K
Following
10
Media
9
Statuses
66

secret club is a not-for-profit reverse-engineering group; publishing new research on popular software. No ads, no cookies, just research.

Joined March 2020
Don't wanna be here? Send us removal request.
@the_secret_club
secret club
4 years
Two years ago, secret club member @floesen_ reported a remote code execution flaw affecting all source engine games. It can be triggered through a Steam invite. This has yet to be patched, and Valve is preventing us from publicly disclosing it.
69
678
2K
@the_secret_club
secret club
1 month
Hypervisors for Memory Introspection and Reverse Engineering by @memn0ps .
2
127
336
@the_secret_club
secret club
2 years
RISC-Y Business: Raging against the reduced machine by @mrexodia oopsmishap.
0
38
116
@the_secret_club
secret club
2 years
Abusing undocumented features to spoof PE section headers by @x86matthew
3
80
258
@the_secret_club
secret club
3 years
Bootkitting Windows Sandbox by @mrexodia @sdoogm .
0
64
137
@the_secret_club
secret club
3 years
Improving MBA Deobfuscation using Equality Saturation by @fvrmatteo and @mr_phrazer.
0
73
140
@the_secret_club
secret club
3 years
Earn $200K by fuzzing for a weekend: Part 2 by @addisoncrump_ko .
0
7
33
@the_secret_club
secret club
3 years
Earn $200K by fuzzing for a weekend: Part 1.by @addisoncrump_ko .
2
55
197
@the_secret_club
secret club
4 years
0
10
28
@the_secret_club
secret club
4 years
1
10
26
@the_secret_club
secret club
4 years
Tickling VMProtect with LLVM: Part 1-3 by @fvrmatteo .
1
89
212
@the_secret_club
secret club
4 years
Windows 11: TPMs and Digital Sovereignty by @daax_rynd @_can1357 @nickeverdox .
3
69
149
@the_secret_club
secret club
4 years
Preventing memory inspection on Windows by @JustasMasiulis
1
14
64
@the_secret_club
secret club
4 years
Counter-Strike Global Offsets: reliable remote code execution by @brymko @cffsmith @scannell_simon (Guest article).
2
85
246
@the_secret_club
secret club
4 years
We've launched a public discord, check it out!.
3
11
65
@the_secret_club
secret club
4 years
CVE-2021-30481: Source engine remote code execution via game invites by @floesen_ .
1
86
201
@the_secret_club
secret club
4 years
RT @chirun02: Many researchers (@bienpnn, @teapotddd, @the_secret_club and others) have demonstrated exploits for Source games that Valve d….
0
21
0
@the_secret_club
secret club
4 years
Here we see researcher teapotd demonstrate his remote code execution vulnerability in CS:GO that is yet to be patched by Valve!.
@teapotddd
teapotd
4 years
Here's a demonstration of one of the exploits that I have reported - an unconditional RCE that can be reliably triggered by entering a malicious server.
0
14
53
@the_secret_club
secret club
4 years
After two years, Valve has patched the critical remote code execution exploit disclosed by @floesen_.
@floesen_
🤷‍♂️
4 years
Good news! Valve fixed my recent exploit and gave me permissions to disclose details. That being said, I am working on a detailed technical write-up which I am going to release soon. Stay tuned!.
2
23
139
@the_secret_club
secret club
4 years
Here we see researcher teapotd with multiple CRITICAL 0days in Source Engine games that have been known by Valve for years.
@teapotddd
teapotd
4 years
I've seen some people recently shared their *negative* experience with Valve bug bounty program. I have decided to share my frustration as well. @the_secret_club @floesen_
Tweet media one
4
10
54
@the_secret_club
secret club
4 years
You can read about our work in the latest VICE article .
6
16
84