<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.1.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Electric Angel</title>
	<link>http://picix.sourceforge.net/electricangel</link>
	<description>picix project</description>
	<pubDate>Thu, 17 May 2007 04:27:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.1.3</generator>
	<language>en</language>
			<item>
		<title>Laura &#038; me</title>
		<link>http://picix.sourceforge.net/electricangel/?p=7</link>
		<comments>http://picix.sourceforge.net/electricangel/?p=7#comments</comments>
		<pubDate>Thu, 17 May 2007 04:27:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://picix.sourceforge.net/electricangel/?p=7</guid>
		<description><![CDATA[I meet Laura at work a few months ago, we got along pretty well, so she is my gf now! lol

Laura this is for you! *:-&#8221;*
(That is a ascii kiss)
]]></description>
			<content:encoded><![CDATA[<p>I meet Laura at work a few months ago, we got along pretty well, so she is my gf now! lol</p>
<p><a href="http://picix.sourceforge.net/electricangel/wp-content/uploads/2007/05/dsc09724.JPG" title="dsc09724.JPG"><img src="http://picix.sourceforge.net/electricangel/wp-content/uploads/2007/05/dsc09724.thumbnail.JPG" alt="dsc09724.JPG" /></a><br />
Laura this is for you! <strong>*:-&#8221;*</strong></p>
<p>(That is a ascii kiss)</p>
]]></content:encoded>
			<wfw:commentRss>http://picix.sourceforge.net/electricangel/?feed=rss2&amp;p=7</wfw:commentRss>
		</item>
		<item>
		<title>OpenBSD mbuf exploit</title>
		<link>http://picix.sourceforge.net/electricangel/?p=5</link>
		<comments>http://picix.sourceforge.net/electricangel/?p=5#comments</comments>
		<pubDate>Mon, 14 May 2007 06:52:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://picix.sourceforge.net/electricangel/?p=5</guid>
		<description><![CDATA[Some months ago, working for Core Security, I found a pretty severe bug on the IPV6 stack of the OpenBSD operative system.
I was investigating another bug, and because really didn&#8217;t have much info about it, I started to fuzz the IPv6 stack, and found this instead.
The history was something like this:

My boss assigned me the [...]]]></description>
			<content:encoded><![CDATA[<p>Some months ago, working for Core Security, I found a pretty severe bug on the IPV6 stack of the OpenBSD operative system.<br />
I was investigating another bug, and because really didn&#8217;t have much info about it, I started to fuzz the IPv6 stack, and found this instead.</p>
<p>The history was something like this:</p>
<ul>
<li>My boss assigned me the exploit, more like a curiosity to investigate. There were very few info about the bug, and no PoC.</li>
<li>A week later, testing  a primitive ipv6 &#8220;fuzzer&#8221; on a OpenBSD 4.0 box, a managed to get a crash similar to this:
<p align="center"><a href="http://picix.sourceforge.net/electricangel/wp-content/uploads/2007/05/openbsdcrash.png" title="Screenshot of the OpenBSD crash"></a></p>
<p style="text-align: center"><a href="http://picix.sourceforge.net/electricangel/wp-content/uploads/2007/05/openbsdcrash.png" title="Screenshot of the OpenBSD crash"><img src="http://picix.sourceforge.net/electricangel/wp-content/uploads/2007/05/openbsdcrash.thumbnail.png" alt="Screenshot of the OpenBSD crash" /></a></p>
</li>
<li>In the next few days, I made a impact module with the then-i-believe-to-be DoS, and others projects got my atention.</li>
<li>
<p align="left">Some days later, it occured to my to test the PoC with a OpenBSD 4.1 Box, supposedly patched, and oh surprise:The box also crashed! I was having a Zero-day on my hands.</p>
</li>
<li>
<p align="left">The OpenBSD team was immediately advised about this. They beleived that it was only a crash, and no code execution could be attained from this. They pretty much dismissed the bug, and label the patch a &#8220;Reliability fix&#8221;. My name wasn&#8217;t even on the bug report, and I became a little bitter about the subjet, but soon forget about it.</p>
</li>
<li>A couple of weeks later, boring on a Saturday Night (I was such a looser, haha!), decided to give it a try and make the exploit for the bug. I was getting a pretty reliable crash on the m_freem() kernel function, so should be a way to exploit that.</li>
<li>That day, working non-stop like 10 hours or so, I managed to get code execution on that bug. Sleep a couple of hours (I was very impacient) and back to work: This time i managed to execute code and get the kernel to continue with normal execution. It was great!</li>
<li>The next morning on the office, i silently modified the advisory, changing the &#8220;DoS&#8221; title, with a &#8220;Remote Exploit&#8221;. Woot!</li>
</ul>
<p>Then a bunch of very hilarious discussions were insued between Core and the OpenBSD team (Specially Theo), and is detailed on the advisory. Then the advisory was published, all went crazy for a couple of days. The manager of the Marketing team of Core was very thankfull of me and give me some words of support.</p>
<p>Thats all. I am not really a blog man, but is kind of required for blackhat, so here is. I will gladly respond any question, post a comment entering &#8220;comment&#8221;. bye!</p>
]]></content:encoded>
			<wfw:commentRss>http://picix.sourceforge.net/electricangel/?feed=rss2&amp;p=5</wfw:commentRss>
		</item>
		<item>
		<title>Pic30 OS project</title>
		<link>http://picix.sourceforge.net/electricangel/?p=4</link>
		<comments>http://picix.sourceforge.net/electricangel/?p=4#comments</comments>
		<pubDate>Sun, 25 Feb 2007 22:01:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Picix]]></category>

		<guid isPermaLink="false">http://picix.sourceforge.net/electricangel/?p=4</guid>
		<description><![CDATA[This one is not yet finished (mmm nor started) should i give it a try? we will see.
]]></description>
			<content:encoded><![CDATA[<p>This one is not yet finished (mmm nor started) should i give it a try? we will see.</p>
]]></content:encoded>
			<wfw:commentRss>http://picix.sourceforge.net/electricangel/?feed=rss2&amp;p=4</wfw:commentRss>
		</item>
		<item>
		<title>Pic18 OS project</title>
		<link>http://picix.sourceforge.net/electricangel/?p=3</link>
		<comments>http://picix.sourceforge.net/electricangel/?p=3#comments</comments>
		<pubDate>Sun, 25 Feb 2007 22:01:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Picix]]></category>

		<guid isPermaLink="false">http://picix.sourceforge.net/electricangel/?p=3</guid>
		<description><![CDATA[All coments about this project are under this thread.
]]></description>
			<content:encoded><![CDATA[<p>All coments about this project are under this thread.</p>
]]></content:encoded>
			<wfw:commentRss>http://picix.sourceforge.net/electricangel/?feed=rss2&amp;p=3</wfw:commentRss>
		</item>
	</channel>
</rss>
