RSSAmplifier

Blog

YayWebsiteYay (I suck at titles)

Sometimes I want to publish stuff unfiltered.

/RSS feed ↗5 posts

Latest posts

Really Delayed Post OffensiveCon Talk Post

Slide Deck https://yogehi.github.io/assets/offensivecon25-talk-stuff/OffensiveCon 2024 Talk - Chainspotting 2.pdf Talk Video https://www.youtube.com/watch?v=LAIr2laU-So Write Up https://yogehi.github.io/published-research/pwn2own-ireland-2024-samsung-s24-attack-chain

Really Delayed Post Defcon Talk Post

Slide Deck DEFCON 32 Media Server / DEF CON 32 / DEF CON 32 presentations / Presentation.pdf Exploit Video DEFCON 32 Media Server / DEF CON 32 / DEF CON 32 presentations / Exploit.mp4 Talk Video DEFCON 32 Media Server / DEF CON 32 / DEF CON 32 video and slides / Talk.mp4 Write Up https://yogehi.github.io/cves/cve-2024-4406.html

10 CVEs! My Personal Thoughts On Research And CVEs

Samsung issued their January 2023 patch, which included 2 more CVEs assigned to me. That makes 10 CVEs so far in my security career.

CVE-2022-24002 - Samsung Link Sharing Start Any Activity

In 2021, as part of my research for Austin Pwn2Own 2021, I found a bug where the Link Sharing application could be abused to start either:

Sonew Bluetooth Lock-Scripts and “Internal F-Secure Pwn2Own”

In March 2020 (literally a week before the world shut down the first time), F-Secure held an “Internal F-Secure Pwn2Own” where each office competed to hack as many in-scope devices as possible. I volunteered to hack the Sonew Bluetooth Lock, aka this bastard: The competition took place in the UK, and I was allowed 3 attempts within 15 minutes to unlock the lock via Bluetooth or physical entry…