#Cup%C3%A1nTaeConf

2024-07-06

Video of talk "Path Dependence: History Matters" given by Laura Nolan at our #CupánTaeConf Virtual Series is up. Enjoy!

youtu.be/2lVu5_B7yUM?si=nn08g_

#TechTalks #IrishTechCommunity #TechCommunity

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

In 2010 Format String vuln relies on many features of printf

#CupanTaeConf

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

How to find it UB and integer Sanitizer

#CupanTaeConf

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07
roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

in 2002 we talked about buffer overflow and in 2017 ...

#CupanTaeConf

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

omg 😹 and oldie but a good one

#CupanTaeConf

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07
roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

We can see the pattern of the vulnerability explained before

#CupanTaeConf

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

ooof! root exploit 💥

#CupanTaeConf #

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

in 2019 Bad Binder vulnerability.!
Binder is Android's IPC mechanism

#CupanTaeConf #Android #BadBinder

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

... she showed us some code on how to fix the vuln and how to find them.

Some tools exist, like ASan but they replace malloc, so tricky

#CupanTaeConf #chocolateDoom

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

Showing when the Unlink happens... the shape of the vulnerability

#CupanTaeConf #ClassicVulnerabilities

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07
roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

Going over doubly-linked lists as the z_malloc is an implementation of malloc that has some extra metadata which uses a doubly linked list, and the vulnerability relies on this structure

#CupanTaeConf #ClassicVulnerabilities

roundcrisis (a.k.a Andrea ) 😹 🦙roundcrisis@types.pl
2024-05-07

@Patricia @cupantaeconf

We keep seeing the same pattern of something similar to what today call Unlink Vulnerability

#CupanTaeConf #patriciaRocks!

2024-05-06

Tea minus 1 Day till #CupánTaeConf with Patricia Aas who will be talking about "Classic Vulnerabilities". #CyberSecurity #TechTalk

🗓️ Tue May 7 (6PM IST/7PM)CEST followed by chats @ 7PM IST/8CEST

🎟️ Tickets (€5) & det: cupantaeconf.com/classic-vulne

Credit: Audio by @bandadeer

#Community #CupánTae #NeedACuppaTea #CodingGrace

2024-04-29

A sip of tea from Laura Nolan: youtube.com/shorts/Rk29vY-rYkE

🔜 Video will be out soon.

But if you want to join us live with our 3rd speaker, Patricia Aas, she will be talking about "Classic Vulnerabilities" on Tue May 7 @ 6PM.
🎟️ cupantaeconf.com/classic-vulne

#CupánTaeConf #TechTalks

whykay👩🏻‍💻🏳️‍🌈🐈(she/her)whykay@mastodon.ie
2024-04-25

I won't be there on the night because I'll be co-hosting @codinggrace's newest virtual talks called @cupantaeconf.

Our final speaker of our first series is Patricia Aas talking about "Classic Vulnerabilities".

You can still get tickets (€5) and join us virtually:
cupantaeconf.com/classic-vulne

#TechTalks #CupanTae #CupanTaeConf #Community

2024-04-04

John Looney's livestreamed (unplugged) talk on "Second System Effect - not a new problem" is now available.

youtube.com/live/DC397Cbi3Hc?f

Note: When we upload the polished video, we will remove the live-stream.

#CupanTaeConf #CupánTae #TechTalks #Community

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst