<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Blackwing Intelligence</title><link>https://blackwinghq.com/</link><description>Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations</description><language>en</language><lastBuildDate>Tue, 15 Oct 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://blackwinghq.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Finding Vulnerability Variants at Scale</title><link>https://blackwinghq.com/blog/posts/finding-vulnerability-variants-at-scale/</link><pubDate>Tue, 15 Oct 2024 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/blog/posts/finding-vulnerability-variants-at-scale/</guid><description>From a JPEG file-format bug in jpeg-recompress to its variants across Chromium, Electron, WINE and more: a method for finding vulnerability variants at scale.</description></item><item><title>Playing with Libmalloc in 2024</title><link>https://blackwinghq.com/blog/posts/playing-with-libmalloc/</link><pubDate>Tue, 02 Jan 2024 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/blog/posts/playing-with-libmalloc/</guid><description>An introduction to macOS libmalloc in 2024 and heapster, a new tool for exploring the heap, plus a few strange things found along the way.</description></item><item><title>[tool] heapster</title><link>https://blackwinghq.com/research/tools/heapster/</link><pubDate>Tue, 02 Jan 2024 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/tools/heapster/</guid><description>A tool for exploring the macOS libmalloc heap from LLDB: zones, magazines, free lists and the state of individual allocations, introduced in our libmalloc post.</description></item><item><title>A Touch of Pwn - Part I</title><link>https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/</link><pubDate>Tue, 21 Nov 2023 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/</guid><description>How we bypassed Windows Hello fingerprint authentication on three laptops: reverse engineering the sensors, breaking a custom TLS, and defeating Microsoft's SDCP protocol.</description></item><item><title>[project] A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication</title><link>https://blackwinghq.com/research/projects/a-touch-of-pwn/</link><pubDate>Tue, 21 Nov 2023 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/projects/a-touch-of-pwn/</guid><description>Microsoft's Offensive Research and Security Engineering team asked us to evaluate the top three fingerprint sensors used for Windows Hello. We bypassed fingerprint authentication on all three laptops. The BlueHat talk and the write-up.</description></item><item><title>[talk] A Touch of Pwn: Attacking Windows Hello Fingerprint Authentication</title><link>https://blackwinghq.com/research/talks/a-touch-of-pwn/</link><pubDate>Wed, 11 Oct 2023 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/talks/a-touch-of-pwn/</guid><description>Microsoft engaged us to evaluate the security of the top fingerprint sensors used for Windows biometric authentication.
This presentation details our vulnerability research process, which entailed extensive reverse engineering of software and hardware, breaking cryptographic implementation flaws in a custom TLS, and deciphering and reimplementing proprietary protocols, to go from very little knowledge about biometric authentication to a full bypass of Windows Hello authentication on all three of our research targets.</description></item><item><title>[tool] iBoot64Binja</title><link>https://blackwinghq.com/research/tools/iboot64binja/</link><pubDate>Thu, 01 Oct 2020 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/tools/iboot64binja/</guid><description>A Binary Ninja binary view for iBoot, SecureROM and similar Apple boot firmware. Point it at a raw image and it identifies the firmware, finds the load address and rebases the binary so analysis is accurate, then restores a set of useful symbols from heuristics, so you start from a mapped, partly labelled image instead of a blob at address zero. Inspired by argp’s iBoot64helper loader for IDA Pro.</description></item><item><title>Dissecting CVE-2013-1899</title><link>https://blackwinghq.com/blog/posts/dissecting-cve-2013-1899/</link><pubDate>Sun, 04 Aug 2013 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/blog/posts/dissecting-cve-2013-1899/</guid><description>Turning PostgreSQL's CVE-2013-1899 command-line-flag injection from a denial of service into remote code execution.</description></item><item><title>[tool] NFCProxy</title><link>https://blackwinghq.com/research/tools/nfcproxy/</link><pubDate>Sat, 28 Jul 2012 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/tools/nfcproxy/</guid><description>An Android app that proxies NFC transactions between a contactless card and a reader, for demonstrating relay attacks and analysing NFC protocols. Presented at DEF CON 20.</description></item><item><title>[talk] NFC Hacking: The Easy Way</title><link>https://blackwinghq.com/research/talks/nfc-hacking-the-easy-way/</link><pubDate>Sat, 28 Jul 2012 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/talks/nfc-hacking-the-easy-way/</guid><description>Eddie Lee presents NFCProxy, a proof-of-concept tool that demonstrates insecurities in near field communication and contactless credit cards. The tool is also useful for NFC protocol analysis in further research.</description></item><item><title>[talk] IRK: Crafting OS X Kernel Rootkits</title><link>https://blackwinghq.com/research/talks/irk-osx-kernel-rootkits/</link><pubDate>Thu, 07 Aug 2008 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/talks/irk-osx-kernel-rootkits/</guid><description>Apple’s OS X operating system has been gaining in popularity. This presentation details how to manipulate the OS X kernel in order to hide an attacker’s activities and maintain access.</description></item><item><title>[talk] Mach Shellcodes and Injectable OS X Rootkits</title><link>https://blackwinghq.com/research/talks/mach-shellcode-osx-rootkits/</link><pubDate>Sat, 14 Jun 2008 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/talks/mach-shellcode-osx-rootkits/</guid><description>Using the Mach interfaces in the OS X kernel to manipulate the kernel from user space, i.e. from shellcode, to alter kernel structures. Example shellcodes are included.</description></item><item><title>[talk] Blackjacking: Owning the Enterprise via the BlackBerry</title><link>https://blackwinghq.com/research/talks/blackjacking/</link><pubDate>Sat, 05 Aug 2006 00:00:00 +0000</pubDate><guid>https://blackwinghq.com/research/talks/blackjacking/</guid><description>Jesse D’Aguanno demonstrated using the trust relationship between the BlackBerry Enterprise Server infrastructure and the handhelds to bypass perimeter controls and compromise an internal corporate network.</description></item></channel></rss>