Resources(82)

  • Hitting the Gym: The Anatomy of a Killer Workout (TROOPERS 2019)

    Ioannis Stais

    On March 18th 2019 myself and Dimitrios Valsamaras delivered a presentation on cybersecurity vulnerabilities of "smart" fitness equipment, entitled "Hitting the Gym: The Anatomy of a Killer Workout" at the TROOPERS 2019 conference (NGI track).

  • Windows 10 RS2/RS3 GDI data-only exploitation tales (OffensiveCon 2018)

    Nikos Sampanis

    Hello, I'm Nikos Sampanis, a security researcher working at CENSUS. On February 16th, 2018 I presented at OffensiveCon a talk with the title "Windows 10 RS2/RS3 GDI data-only exploitation tales". The presentation focused on a mitigation introduced in the Win32k component of Microsoft Windows to prevent the...

  • iOS kernel exploitation archaeology (34th Chaos Communication Congress)

    Patroklos Argyroudis

    On December 27th 2017 I presented at the 34th Chaos Communication Congress (34C3) a talk on the technical details and the process of reverse engineering and re-implementation of the evasi0n7 jailbreak's main kernel exploit, titled "iOS kernel exploitation archaeology". Actually, I gave the same talk at the WarCon...

  • Shadow v2 public release

    Patroklos Argyroudis

    About four months ago (April 2017), Vasilis Tsaousoglou and myself presented our work on exploiting Android's libc allocator at the 2017 INFILTRATE conference (Miami, Florida). Since version 5.0, Android has adopted the jemalloc allocator as its default libc malloc(3) implementation. For our talk we extended our...

  • Lure10: Exploiting Windows Automatic Association Algorithm

    George Chatzisofroniou

    Lure10 is a novel technique presented at the Hack-in-the-Box 2017 conference in Amsterdam that enables an attacker to automatically achieve a man-in-the-middle position against wireless devices running the Windows operating system. The attack requires no user interaction and exploits the "Wi-Fi Sense" feature found in...

  • Introducing Choronzon: an approach at knowledge-based evolutionary fuzzing

    Nikolaos Naziridis

    CENSUS researchers Nikolaos Naziridis and Zisis Sialveras have recently presented their research on knowledge-based evolutionary fuzzing, at ZeroNights 2015 in Moscow, Russia. The talk introduced a cross-platform evolutionary fuzzing framework, that will be released as a free and open-source tool.

  • Introducing wifiphisher - BSides London 2015

    George Chatzisofroniou

    Hello. My name is George Chatzisofroniou (@_sophron) and I work as a security engineer at CENSUS. This summer I gave a talk at BSides London. The talk was called 'Introducing wifiphisher, a tool for automated WiFi phishing attacks' and revolved around the recently published tool.

  • OR'LYEH? The Shadow over Firefox (INFILTRATE 2015)

    Patroklos Argyroudis

    About two months ago (April 15th 2015) I visited Miami and presented at the INFILTRATE Security Conference a talk on Firefox heap exploitation, titled "OR'LYEH? The Shadow over Firefox". The organization of the conference was flawless and the people I met there were amazing. A special thank you to the Immunity team...

  • Project Heapbleed

    Patroklos Argyroudis

    I recently presented a talk on heap exploitation abstraction at two conferences, namely ZeroNights 2014 (Moscow, Russia) and BalCCon 2014 (Novi Sad, Serbia). The talk titled "Project Heapbleed", collected the experience of exploiting allocators in various different target applications and platforms. The talk focused...

  • How to enhance penetration testing through vulnerability research

    Patroklos Argyroudis

    The slides from my short presentation on "How to enhance penetration testing through vulnerability research" from the 3rd Infocom Security conference, are now available here (in Greek).

  • Heap Exploitation Abstraction by Example - OWASP AppSec Research 2012

    Patroklos Argyroudis

    This year's OWASP AppSec Research conference took place in Athens, Greece and we were planning to be there as participants. However, the day before the conference, Konstantinos Papapanagiotou (General Chair) asked if we could do a presentation to replace a cancelled talk. Myself and Chariton Karamitas agreed to help...

  • Black Hat USA 2012 update

    Patroklos Argyroudis

    This year we have presented our jemalloc exploitation research work at Black Hat USA 2012, the leading information security conference. Our researchers Patroklos Argyroudis and Chariton Karamitas visited Caesar's Palace at Las Vegas, Nevada and delivered the talk.

  • AthCon 2011 update

    Nikolaos Tsagkarakis

    CENSUS has participated once again at AthCon, the leading technical IT security conference in Greece. Our work entitled "Introducing the Parasite" presented a small device that is capable of creating a physical backdoor in an otherwise protected network.

  • Black Hat Europe 2011 update

    Patroklos Argyroudis

    Black Hat Europe 2011 is now over and we are very happy to have participated once again in the best European IT security conference!

  • Black Hat Europe 2010 update

    Patroklos Argyroudis

    Black Hat Europe 2010 is now over and after a brief ash cloud caused delay I am back in Greece. It has been a great conference, flawlessly organised and with many outstanding presentations. I would like to thank everyone that attended my presentation but also all the kind people that spoke to me before and afterwards....

  • FreeBSD kernel stack overflows

    Patroklos Argyroudis

    Last May (2008-05-30) I presented my research on FreeBSD kernel stack overflows at the University of Piraeus Software Libre Society, Event #16: Computer Security. The slides from the talk are now available in our research section.