1 Visitor Messages

  1. View Conversation
    hey whats up brother! howz pune doing
Showing Visitor Messages 1 to 1 of 1
About fb1h2s

Basic Information


About fb1h2s
Biography:
http://packetstormsecurity.org/search/files/?q=fb1h2s
Location:
India
Interests:
Revrse Engineering, Researching , WebApp Security or anything related to Computers.
Occupation:
Information Security Researcher

Signature


Hacking Is a Matter of Time Knowledge and Patience

Statistics


Total Posts
Total Posts
600
Posts Per Day
0.56
Visitor Messages
Total Messages
1
Most Recent Message
12-01-2012 05:27 PM
Total Thanks
Total Thanks
279
  • Thanked 152 Times in 77 Posts
General Information
Last Activity
Yesterday 04:58 PM
Join Date
07-07-2010
Referrals
20

32 Friends

  1. 41.w4r10r 41.w4r10r is offline

    InfoSec Consultant

    41.w4r10r
  2. ajaysinghnegi ajaysinghnegi is offline

    Garage Member

    • Send a message via MSN to ajaysinghnegi
    • Send a message via Yahoo to ajaysinghnegi
    ajaysinghnegi
  3. akshaya0417 akshaya0417 is offline

    Garage Newcomer

    akshaya0417
  4. AnArKI AnArKI is offline

    Super Administrator

    AnArKI
  5. AP4CH3 AP4CH3 is offline

    Garage Newcomer

    AP4CH3
  6. b0nd b0nd is offline

    Garage Hyper Addict

    b0nd
  7. babloo babloo is offline

    Garage Newcomer

    • Send a message via Skype™ to babloo
    babloo
  8. br0wn_sug4r br0wn_sug4r is offline

    Garage Newcomer

    br0wn_sug4r
  9. D4rk357 D4rk357 is offline

    Garage Member

    D4rk357
  10. d4rkpyth0n d4rkpyth0n is offline

    Garage Newcomer

    d4rkpyth0n
Showing Friends 1 to 10 of 32
Page 1 of 4 123 ... LastLast
View fb1h2s's Blog

Recent Entries

DEP ASLR bypass without ROP JIT : CanSecWest2013 Slides and Analysis

by fb1h2s on 03-08-2013 at 05:03 AM
I have my own talk from CanSecwest to blog about but this one is more interesting and the most awaited one. So here are the slides, I will add my own analysis and test cases to this blog entry later. Interesting thing is we had this technique discussed on garage in november http://www.garage4hackers.com/f22/wi...innu-3080.html .

Yu Yang @tombkeeper did a demo of the technique on Ms013-08 and it does not ever need a heap spray for his ASLR/DEP bypass

Read More

Categories
Uncategorized

Beginners Guide to "Use after free Exploits #IE 6 0-day #Exploit Development"

by fb1h2s on 11-15-2012 at 05:09 AM

Yea right!

Last week a friend asked few queries regarding use after free vulnerabilities, . It's been a while I wrote a tutorial so taught of cooking a beginners guide this week end. I wanted a live target for the tutorial so my plans were to run my fuzzer on an old version of IE 6, since it is easy to find a bug in and it's not worth to blog out any new versions 0-day . Any way I picked up the first test case IE crashed on and

Read More

Categories
Uncategorized

Max OSX 64 bit ROP Payloads.

by fb1h2s on 10-27-2012 at 11:38 PM
6 Months back I did a presentation on Mac OSX 64 bit ROP shellcodes at Null Monthly meet, where I took two different session explaining 64 bit architecture in detail and Mac OSX 64 Rop Shellcode. Today I was browsing through some old stuffs and came across the PPT I used back then. The slides only contains the first day's presentation and I can't find the second days PPT .

Am sharing it over here. There is nothing new.

http://www.slideshare.net/RahulSasi2...sx-64ropchains

Read More

Categories
Uncategorized

Fuzzing DTMF Detection Algorithms .

by fb1h2s on 10-21-2012 at 01:55 AM
My ekoparty.org [Argentina] and NU[Delhi] talk and also Ruxcon [Australia] and BlackHat [Abhudabi] which I could't make it .



What is this paper about:

Input validation attacks and memory corruption attacks are common, and the
criticality of finding a DOS attack on a service like HTTP is consider a lot critical
considering the attack surface and easiness of attack. Even if we could trigger an
exception in an

Read More

Categories
Uncategorized

Web-App Remote Code Execution Via Scripting Engines Part -1: Local Exploits PHP 0-day

by fb1h2s on 08-20-2012 at 07:07 PM

This would be part-1 one of my C0C0n talk , where I demonstrated few PHP 0-days, Local and Remote . The entire concept of the talk was demonstrating attacks on WebApplications via scripting engines.

In a common Webapp test we manipulates Input , that a common end user controls and check for responses from the app. But since these data passed are processed by the PHP,ASP engines that are used to build these apps. We

Read More

Categories
Uncategorized