Unmasking Spoofed Stagers: Header Forensics & Attribution
Blake De Garza Blake De Garza

Unmasking Spoofed Stagers: Header Forensics & Attribution

The paradox at the heart of email-based attacks is this: modern authentication systems—SPF, DKIM, DMARC, ARC—were designed to prevent exactly this kind of forgery, yet a sophisticated attacker can still spoof an email from someone's own address and have it pass every cryptographic check.

Read More
Info Leak Cisco ASA - v 9.18
Blake De Garza Blake De Garza

Info Leak Cisco ASA - v 9.18

he LINA `kprintf` function contains a use-after-free vulnerability when processing malformed SNMP queries. Error messages logged via `kprintf` reference freed memory structures, allowing:

1. Information disclosure via heap spray

2. ASLR bypass by leaking libc addresses

3. Selective overwrite of freed heap chunks

4. Arbitrary code execution via corrupted function pointers

Read More
      Case Study: Finding Real Concurrency Bugs with LLP Predicate Detection 
 Table of Contents 
 
  Overview  
  Case Study 1: Data Races in Boruvka's Minimum Spanning Tree  
 2.1  The Algorithm  
 2.2  The Bug  
 2.3  Detection Results  
 2.4  Roo
Blake De Garza Blake De Garza

Oh the places we go, Oh the lattices we Explore!

Read More