2 min read

exploits.club Weekly Newsletter 01

exploits.club Weekly Newsletter 01

Dec 24th, 2023 - Dec 31st, 2023

Hello and welcome to the first entry of our Vulnerability Research Newsletter. We intend this to be a weekly round-up of interesting blogs, talks, and jobs postings related to vulnerability research and
exploit development. Let's get into it:

The 37th Chaos Communication Congress (37c3):

If you have been anywhere near X this week, you've probably come across some chatter about the talks presented at 37c3 over the past few days. Kaspersky's breakdown of Operation Triangulation certainly stole the show, with it's details of a zero-click iOS attack chain. One of the slides in particular has been making the rounds, which details the level of sophistication (and, according to LiveOverflow, "bureaucracy") of the attack.

Other talks we enjoyed here at exploits.club:

  • Nintendo hacking 2023: 2008 - It wouldn't be a C3 without a console hacking talk, and this breakdown on jailbreaking the Nintendo DSi certainly fills that role. Lots of interesting tidbits in this talk, ranging from advanced hardware hacking to binary exploitation to self-rolled crypto (yikes).
  • Fuzz Everything, Everywhere, All at Once - This talk walks through how to fuzz binary-only targets with LibAFL and QEMU. It then introduces a new library for LibAFL which offers "APIs to hook the target using Rust". It includes a demo against an Android Library, as well as a demo showing off some built-in detections for non-memory corruption bugs, such as command injection and SQLi. If this talk sparks your interest in LibAFL like it did for us, Artedis released a LibAFL workshop earlier this month which can help bring you up to speed.

There are plenty of other talks in our backlog at the moment, including stacksmashing's iPhone USB-C antics and a breakdown of spyware discovered during the Predator Files investigation.

Other Resources We Have Been Enjoying This Week:

Interesting Job Postings:

Wrapping up...

We are in the process of setting up our closed Discord community for researchers. Interested in joining the club? Fill out our interest form here: https://forms.gle/2qYrq8w3TLgDDVQx5

Follow us on X!