Eloi Sanfelix · X (formerly Twitter)

user avatar

Security researcher with experience in embedded system security from chip design to software vulnerabilities and exploitation. #int3pids CTF player.

NL

Joined September 2009

  • user avatar

    For this year's r2con CTF I contributed a small update of last year's kernel pwnable. Congrats to

    @dialluvioso_

    for the only solve during the CTF! I've uploaded the challenge binaries + source here in case anyone wants to give it a go: github.com/esanfelix/r2co… .

  • user avatar

    I've just pushed a write-up describing the code, my original solution using modprobe_path and an alternative with a KASLR bypass and credential modification to github.com/esanfelix/r2co… . I'd love to hear if anyone used a different approach (or bugs!)

  • user avatar

    I added the challenge source code. There is at least 1 (intended) security bug and 2 unintended functional bugs in there. Can you find them all? Can you exploit the security issue? I know of at least 3 people who did after the CTF. Let me know if you do too!

  • user avatar

    I contributed a kernel pwnable challenge to the r2con 2019 CTF organized by

    @enovella_

    and

    @as0ler

    . Unfortunately it went unsolved... I've pushed it to github.com/esanfelix/r2co… , and will later update source code and [even later] exploit. Let me know if you give it a try!

  • user avatar

Read the original on x.com ↗