Jesse D'Aguanno 

640 Followers
369 Following
248 Posts
Hacker, Vuln Research, 2x winner DEF CON CTF, Founder & CEO Blackwing Intelligence - not a CISSP
Twitterhttps://twitter.com/0x30n
Workhttps://blackwinghq.com
Personalhttps://c0nfusion.org
Curious about macOS’s default memory allocator? My new post introduces heapster, a tool to play and learn about libmalloc’s inner workings. 👉 https://blackwinghq.com/blog/posts/playing-with-libmalloc/
Playing with Libmalloc in 2024

Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations

@regehr My answer used to be Linkers and Loaders, too, but lately I've been pointing students at https://www.toolchains.net/ !
Toolchains.net - Compiler toolchains resources

GNU toolchain and LLVM toolchain resources

If you enjoy PCalc or Dice, a repost on the Black Friday deal linked below would be very helpful in getting the word out on the 50% off sale. I absolutely hate doing marketing, and always just feel like saying “buy my stuff, it's okay I guess!”, but this is not exactly conducive to selling copies.

https://mastodon.social/@jamesthomson/111460746988545560

Windows Hello fingerprint security failures! Great work from
Blackwing!

"We initially implemented this attack on a Raspberry Pi 4, but reimplemented it in TamaGo on the USB armory since the RPi4 takes too long to boot and we wanted a quicker demo. 😜"

https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/

A Touch of Pwn - Part I

Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations

Introducing the PCalc “More Than 42% Off Super Sale” for #blackfriday!

PCalc iOS: $4.99 down from $9.99
https://apps.apple.com/us/app/pcalc/id284666222

PCalc Mac: $4.99 down from $9.99
https://apps.apple.com/us/app/pcalc/id403504866

Dice by PCalc iOS: $0.99 down from $1.99
https://apps.apple.com/us/app/dice-by-pcalc/id1468680083

Dice by PCalc Mac: $0.99 down from $1.99
https://apps.apple.com/us/app/dice-by-pcalc/id1479250666

Everything is roughly 50% off until the end of Monday 27th November. It's extremely rare for PCalc to go on sale like this, so act now!

PCalc App - App Store

Download PCalc by TLA Systems Ltd. on the App Store. See screenshots, ratings and reviews, user tips, and more games like PCalc.

App Store
I guess Twitter isn't exactly dead for technical content

A Touch of Pwn - multiple vulnerabilities in the top three fingerprint sensors embedded in laptops successfully exploited, allowing complete bypass of Windows Hello authentication

https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/

A Touch of Pwn - Part I

Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations

Boom!
Windows Hello fingerprint authentication bypassed on top three devices:
- Dell Inspiron
- Lenovo ThinkPad
- Microsoft Surface Pro
Still waiting for recordings from our BlueHat talk to drop, but here's our writeup: https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/
#infosec #security #vulnresearch @Blackwing
A Touch of Pwn - Part I

Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations

*yells into the megaphone*
The "remote" in remote code execution refers to where the attack originates. Any type of vulnerability which requires local execution to exploit may be referred to as an arbitrary code execution vulnerability, a local code execution, or in special cases a local privilege escalation vulnerability.

Do not fall for the corporate propaganda!

Some thoughts on security “solutions”: https://c0nfusion.org/posts/2023/11/its-not-better-than-nothing/
It's not better than nothing

“It’s better than nothing” These words are the enabler of so many worthless security “solutions”. From phishing testing, to SAST, to “threat intel feeds”, to well, look around the floor of RSA… Instead of identifying real problems and finding or engineering solutions that fix those problems, “security” continues to bolt on the cheapest “solution”, masking the real problem and kicking it down the road, claiming “it’s better than nothing”. Unfortunately, it’s really not better than nothing.