OR’LYEH? The Shadow over Firefox (INFILTRATE 2015)

About two months ago (April 15th 2015) I visited Miami and presented at the INFILTRATE Security Conference a talk on Firefox heap exploitation, titled “OR’LYEH? The Shadow over Firefox”. The organization of the conference was flawless and the people I met there were amazing. A special thank you to the Immunity team for being great hosts and for their helpful feedback.

DTrace talk at CONFidence 2015

Hello, my name is Andrzej Dyjak and I’m part of the research team here at CENSUS.

A few weeks ago (on May 26th) I gave a talk titled “DTrace + OS X = Fun” at CONFidence 2015 in which I have described how DTrace can be used in order to ease various tasks within the realm of dynamic analysis on the OS X platform.

The slides from this talk are now also available here.

5th InfoCom Security Conference

CENSUS was one of the sponsors of the 5th InfoCom Security conference, that was held on April 1st, 2015 at the Divani Caravel hotel in Athens, Greece.

5th InfoCom Mobile World Conference

CENSUS will be sponsoring the 5th InfoCom Mobile World conference, that will be held on February 26th, 2015 at the Divani Caravel hotel in Athens, Greece.

Project Heapbleed

CENSUS researcher Patroklos Argyroudis has recently presented a talk on heap exploitation abstraction at two conferences, namely ZeroNights 2014 (Moscow, Russia) and BalCCon 2014 (Novi Sad, Serbia). In the talk titled “Project Heapbleed”, Patroklos has collected the experience of exploiting allocators in various different target applications and platforms. He focused on practical, reusable heap attack primitives that aim to reduce the exploit development time and effort.

PoS Attacking the traveling salesman — DEFCON 2014

CENSUS researchers Alex Zacharis and Nikos Tsagkarakis presented their Point-of-Sale exploitation work entitled “PoS Attacking the Traveling Salesman” at this year’s DEFCON conference in Las Vegas, USA.

The talk illustrated vulnerabilities of airport point-of-sale systems that could be used by adversaries to collect passenger data.

Material from this talk can be found here:

The presentation was a success and caught the attention of various technology blogs:

We would like to thank the organizers of DEFCON for hosting this great event and hope to meet everyone again next year!

4th InfoCom Mobiles and Apps conference slides

Here are the slides for our recent (albeit short) talk on “Secure Mobile App SDLC”, as presented at the 4th Infocom Mobiles and Apps conference.

4th InfoCom Mobiles and Apps conference

Census will be sponsoring the 4th InfoCom Mobiles and Apps conference, that will be held on February 12th, 2014 at the Divani Caravel hotel in Athens, Greece.

Firefox Exploitation — AthCon 2013

We are thrilled to be participating again, for the fourth time actually, at AthCon, the leading technical IT security conference in Greece. This year, our researchers Patroklos Argyroudis and Chariton Karamitas will be presenting novel exploitation techniques against the Mozilla Firefox browser.

3rd InfoCom Security conference

census will be sponsoring the 3rd InfoCom Security conference, that will be held on April 10th, 2013 at the Divani Caravel hotel in Athens, Greece.

