Here you will be presented with the latest and most exciting security research activities undertaken by the Blue Frost Security research team. You will find whitepapers, tools, advisories and blog posts.
LG PC Suite Insecure Update Mechanism
A vulnerability inside the update mechanism was identified which allows an attacker to remotely execute arbitrary code on the target system.
FireEye Detection Evasion and Whitelisting of Arbitrary Malware
An analysis engine evasion was identified which allows an attacker to completely bypass FireEye's virtualization-based dynamic analysis on Windows and whitelist arbitrary malicious binaries.
IE11 CObjectElement Use-After-Free Vulnerability
A use-after-free vulnerability was identified which allows the execution of arbitrary code on vulnerable installations of Microsoft Internet Explorer.
OpenSSH PAM Privilege Separation Vulnerabilities
Multiple vulnerabilities in OpenSSH were identified that could allow successful authentication as an arbitrary user and thus impersonation of other users.
Exploiting Trusted Apps on Samsung’s TEE
Abusing GDI for Ring0 Exploit Primitives: Evolution
Windows 10 kernel exploitation techniques based on the latest Windows 10 RS3 insider preview
Look Mom! I Don’t Use Shellcode
A Browser Exploitation Case Study for Internet Explorer 11
Exploiting CVE-2014-4113 on Windows 8.1
Analysis of the Windows kernel vulnerability CVE-2014-4113, demonstrating how it can successfully be exploited on Windows 8.1.
BFS Ekoparty 2019 Exploitation Challenge - Override Banking Restrictions to get US Dollars
Show us your skills, get invites to the BFS-IOACTIVE party and an opportunity to join BFS!
Escaping the Chrome Sandbox via an IndexedDB Race Condition
Exploitation of a race condition in the IndexedDB implementation of Chrome, demonstrating a full sandbox escape.
TEE Exploitation on Samsung Exynos devices (I/IV) : Introduction
Part 1 of a series of posts on exploiting Trusted Applications on the Samsung Galaxy S9 TEE.
Analysis of CVE-2019-5790 and how the search for unexplored attack surface in V8 led to its discovery.
BFS Ekoparty 2018 Exploitation Challenge: Stop the Capital Flight
Win entry tickets to Ekoparty as well as an invitation to the official speaker dinner by stopping capital flight and solving the Argentinean currency crisis!
19 hours, 7 minutes ago
19 hours, 7 minutes ago
19 hours, 8 minutes ago
The 2019 Ekoparty challenge is closed! Thanks for all your amazing submissions! Details will be send out to all winners end of next week.
6 days, 4 hours ago
Take our 2019 Ekoparty challenge for a chance to win a ticket for the BFS-IOACTIVE party and the opportunity to joi… https://t.co/prw67mZ8Kk
1 week, 4 days ago