Profile

Cover photo
Ange Albertini
121,602 views
AboutPosts

Stream

Ange Albertini

Shared publicly  - 
 
Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen. Sign upLog in. You won't see these kinds of Tweets next time you're here. You'll see more of these kinds of Tweets every time you're here. You won't see these kinds of Tweets next time you're here.
1
Add a comment...

Ange Albertini

Shared publicly  - 
1
Add a comment...

Ange Albertini

Shared publicly  - 
 
The video of my talk mixing file formats creating, hacking and preserving is out.
1
1
Ange Albertini's profile photo
Add a comment...

Ange Albertini

Shared publicly  - 
 
Peeks, Pokes and Pirates, with 4am.
1
Add a comment...

Ange Albertini

Shared publicly  - 
 
To turn PoC||GTFO 10 in a standard (non-polyglot) and smaller PDF,
run "mutools clean -ggg" on it.
http://mupdf.com/downloads/
1
Add a comment...

Ange Albertini

Shared publicly  - 
 
An easy way to turn formatted text files into PDFs https://gist.github.com/anonymous/2f0b993190fd95e9749454903fc89931 … Embedded image. 1:28 p.m. - 23 May 2016. 3 Retweets8 likes. Reply to @angealbertini. Home · Sign up · Log in · Search · About. More like this; Less like this ...
1
Add a comment...

Ange Albertini

Shared publicly  - 
 
When Infosec and Digipres share interests...

TL;DR 
- Attack surface with file formats is too big. 
- Specs are useless (just a nice ‘guide’), not representing reality. 
- We can’t deprecate formats because we can’t preserve and we can’t define how they really work

- We need open good libraries to simplify landscape, and create a corpus to express the reality of file format, which gives us real “documentation”. 
- Then we can preserve and deprecate older format, which reduces attack surface. 
- From then on, we can focus on making the present more secure.

- We don't need new formats: reality will diverge from the specs anyway - we need 'alive' (up to date, traceable) specs.
Presented at Troopers 2016. When Infosec and Digipres share interests... TL;DR - Attack surface with file formats is too big. - Specs are useless (just a nice ‘guide’), not representing reality. - We can’t deprecate formats because we can’t preserve and we can’t define how they really work - We need open good libraries to simplify landscape, and create a corpus to express the reality of file format, which gives us real “documentation”. ...
1
Add a comment...

Ange Albertini

Shared publicly  - 
 
Like free posters for your reverse engineering needs?
Support my patreon!
2
2
Add a comment...

Ange Albertini

Shared publicly  - 
 
PoC||GTFO 10 is a [polyglot] PoC-ception:
It's a PDF with several articles, and the first one explains how to exploit Pokemon Red via pure controller input (and reset), running on a Super Game Boy plugged in a Super Nintendo. It takes over the Super Game Boy, then takes over the Super Nintendo.

The same file is also an exploit that can be used on the real hardware or an emulator, and the payload displays the content of the article.

It's also a ZIP, containing many extra materials of interest.
a [polyglot] PoC-ception: exploit hardware^emulator to display the article explaining the exploit. Embedded image. 8:08 AM - 16 Jan 2016. 23 Retweets16 Likes. Reply to @angealbertini. Home · Sign up · Log in · Search · About. Not on Twitter? Sign up, tune into the things you care about, ...
1
1
Add a comment...

Ange Albertini

Shared publicly  - 
 
PoC||GTFO 10 is out!
2
Sebastian Porst's profile photo
 
Great pic!
Add a comment...
Story
Tagline
Reverse engineer - author of Corkami.com
Introduction
puzzles, crêpes, singing
reverse-engineering, graphics