HNHacker News
TopNewBestAskShowJobs

etenal

54 karma · joined September 29, 2023

Building Mythos-level cybersecurity code review at Nebula Security
submissionscomments
etenal··on GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
There is no if, it works, people have video proof, google confirmed, Linux patched and fixed. And you still believe this is AI gibberish
etenal··on GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
It's a browser to kernel full chain exploit, from url click to root your device.
etenal··on GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
We apologize for the confusion. We used AI to run final grammar pass and didn't noticed it changed some wording (shape is one of them). Will be more careful in the future
etenal··on GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
Thanks for testing, we currently only tested it on Pixel 10, but there are a few people on our repo creating PR to support other devices, you can take a look here https://github.com/NebuSec/CyberMeowfia
etenal··on We won $92,337 bug bounty using a single kernel 0-day
Read our technical walkthrough here to see how we won almost $10k bug bounty from a single Linux kernel 0-day -- GhostLock.

Chaining GhostLock with a Firefox 0-day, we managed to remote control any Android device (even the latest Android 17) from a simple URL click. We name this full-chain exploit "IonStack", because it's IonMonkey 0-day in Firefox and a StackOverflow in Linux kernel.

Our blog post -> https://nebusec.ai/research/ionstack-part-2/

Exploit Github -> https://github.com/NebuSec/CyberMeowfia