LiveOverflow
LiveOverflow
  • 420
  • 63 250 887
My Trip to DEF CON & Black Hat
My second time in Las Vegas for DEF CON and Black Hat. Lots has changed since I have been here 6 years ago. This trip was quite emotional for me and I am so grateful for the experience. Hope to meet you all again.
Learn hacking (ad): app.hextree.io/
Buy our Faultier (US): 1bitsquared.com/collections/embedded-hardware/products/faultier
Google x Hextree Android Courses: www.hextree.io/hextree-x-google
Raspberry Pi Hacking Challenge: www.hextree.io/rp2350
Embedded System Village: embeddedvillage.org/
My previous DEF CON 26 (6 years ago) Vlog:
- czcams.com/video/B8saYocsI-U/video.html
- czcams.com/video/RXgp4cDbiq4/video.html
=[ ❤️ Support ]=
→ per Video: www.patreon.com/join/liveoverflow
→ per Month: czcams.com/channels/lcE-kVhqyiHCcjYwcpfj9w.htmljoin
2nd Channel: czcams.com/users/LiveUnderflow
=[ 🐕 Social ]=
→ Twitter: LiveOverflow/
→ Streaming: twitch.tvLiveOverflow/
→ TikTok: www.tiktok.com/@liveoverflow_
→ Instagram: LiveOverflow
→ Blog: liveoverflow.com/
→ Subreddit: www.reddit.com/r/LiveOverflow/
→ Facebook: LiveOverflow/
zhlédnutí: 43 402

Video

Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)
zhlédnutí 59KPřed 7 měsíci
A guide on how to do fuzzing with AFL in an attempt to rediscover the libwebp vulnerability CVE-2023-4863 that was used to hack iPhones. Want to learn hacking? Signup to hextree.io (ad) Buy my shitty font: shop.liveoverflow.com/ (ad) Watch webp Part 1: czcams.com/video/lAyhKaclsPM/video.html Sudo Vulnerability Series: czcams.com/play/PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx.html Docker Video: czcams....
A Vulnerability to Hack The World - CVE-2023-4863
zhlédnutí 108KPřed 8 měsíci
Citizenlab discovered BLASTPASS, a 0day being actively exploited in the image format WebP. Known as CVE-2023-4863 and CVE-2023-41064, an issue in webp's build huffman table function can lead to a heap buffer overflow. This vulnerability is very interesting and I'm excited to share with you what I learned. Want to learn hacking? Signup to hextree.io (ad) Buy my shitty font: shop.liveoverflow.com...
Reinventing Web Security
zhlédnutí 39KPřed 9 měsíci
Follow me down the rabbit hole into the wonderful world of IT security. Buy my terrible font (ad): shop.liveoverflow.com Learn hacking (ad): hextree.io Related Videos: czcams.com/video/866olNIzbrk/video.html czcams.com/video/lKzsNp4AveY/video.html Tweets: LiveOverflow/status/1720734431659376995 LiveOverflow/status/1720799912181284864 LiveOverflow/status/17214...
The Circle of Unfixable Security Issues
zhlédnutí 114KPřed 10 měsíci
Not every security issues can be fixed. There exist (what I call) "unfixable" bugs, where you can always argue and shift the goal posts. The idea is to only report these kind of issues to create an endless stream of bug bounty money! Buy my terrible font (ad): shop.liveoverflow.com Learn hacking (ad): hextree.io What is a vulnerability? czcams.com/video/866olNIzbrk/video.html hackerone reports:...
Hacker Tweets Explained
zhlédnutí 159KPřed 11 měsíci
Let me explain to you what you can learn from these tweets. Did you know the name trick? Buy my terrible font (ad): shop.liveoverflow.com Learn hacking (ad): hextree.io Quote Tweet: avlidienbrunn/status/1697869590569582932 Original Tweet: Rhynorater/status/1696862832841916679 Critical Thinking Podcast: www.criticalthinkingpodcast.io/ XSS Origin Series: czcams.com/play/PL...
Zenbleed (CVE-2023-20593)
zhlédnutí 160KPřed 11 měsíci
Let's explore the "most exciting" CPU vulnerability affecting Zen2 CPUs from AMD. Watch part 1 about fuzzing: czcams.com/video/neWc0H1k2Lc/video.html buy my font (advertisement): shop.liveoverflow.com/ This video is sponsored by Google: security.googleblog.com/2023/08/downfall-and-zenbleed-googlers-helping.html Original Zenbleed Writeup: lock.cmpxchg8b.com/zenbleed.html Grab the code: github.co...
The Discovery of Zenbleed ft. Tavis Ormandy
zhlédnutí 62KPřed rokem
How did Tavis Ormandy fuzz CPUs to discover Zenbleed? In this video we learn about the techniques to make this work! Watch part 2: czcams.com/video/9EY_9KtxyPg/video.html buy my font (advertisement): shop.liveoverflow.com/ This video is sponsored by Google: security.googleblog.com/2023/08/downfall-and-zenbleed-googlers-helping.html Original Zenbleed Writeup: lock.cmpxchg8b.com/zenbleed.html AMD...
Asking Android Developers About Security at Droidcon Berlin
zhlédnutí 34KPřed rokem
I attended droidcon Berlin 2023 and interviewed some developers about what they know about Android security. Thanks again to everybody who answered my questions, and thanks Egidijus for the dcbln23 ticket. Buy the terrible font (advertisement): shop.liveoverflow.com/ Watch my security conference vlog: czcams.com/video/E9kz6RQu9Oc/video.html Egidijus on Twitter: AegisLil droidcon: ww...
Local Root Exploit in HospitalRun Software
zhlédnutí 68KPřed rokem
Let's talk about a "security flaw in hospital software that allows full access to medical devices". This issue was disclosed on LinkedIn and included a full exploit code. Let's use this app as an example on how to find a macOS privilege escalation and learn how local root exploits can work. Print BINGO sheet: liveoverflow/status/1682650394227351552 Sources: Original LinkedIn Post: w...
Android App Bug Bounty Secrets
zhlédnutí 100KPřed rokem
Sergey Toshin tells us the story of how he became a top Android bug hunter and how he finds critical vulnerabilities. He also shows us a really cool vulnerability found in the Google Android Snapseed app. I didn't know this crazy attack vector exists! Start Android Bug Hunting Here! Google App Scan Results: bughunters.google.com/report/targets/290590452 Google Mobile VRP: bughunters.google.com/...
Generic HTML Sanitizer Bypass Investigation
zhlédnutí 141KPřed rokem
I stumbled over a weird HTML behavior on Twitter and started to investigate it. Did I just stumble over a generic HTML Sanitizer bypass? Get my handwritten font shop.liveoverflow.com (advertisement) Checkout our courses on hextree.io (advertisement) The Tweet: MRCodedBrain/status/1662701541680136195 Google XSS: czcams.com/video/lG7U3fuNw3A/video.html HTML Spec: html.spec.whatwg.org/...
Hacking Google Cloud?
zhlédnutí 124KPřed rokem
Every year Google celebrates the best security issues found in Google Cloud. This year we take a look at the 7 winners to see if we could have found these issues too. Will I regret not having hacked Google last year? This video is sponsored by Google VRP: Follow GoogleVRP Twitter: GoogleVRP The GCP Prize Winners of 2022: security.googleblog.com/2023/06/google-cloud-awards-313337-in-...
Trying to Find a Bug in WordPress
zhlédnutí 91KPřed rokem
I stumbled over some WordPress code involving caching. Immediately I had this idea about MD5 collision and how this could affect the implemented logic. I started going down a rabbit hole exploring the feasibility and eventually setting up a PHP debug environment. Only to realize that the idea was flawed from the start. So while this ends up being failed security research, we still learn a lot a...
Authentication Bypass Using Root Array
zhlédnutí 126KPřed rokem
Authentication Bypass Using Root Array
My YouTube Financials - The Future of LiveOverflow
zhlédnutí 105KPřed rokem
My CZcams Financials - The Future of LiveOverflow
Defending LLM - Prompt Injection
zhlédnutí 50KPřed rokem
Defending LLM - Prompt Injection
Accidental LLM Backdoor - Prompt Tricks
zhlédnutí 143KPřed rokem
Accidental LLM Backdoor - Prompt Tricks
Attacking LLM - Prompt Injection
zhlédnutí 370KPřed rokem
Attacking LLM - Prompt Injection
Our Future As Hackers Is At Stake!
zhlédnutí 66KPřed rokem
Our Future As Hackers Is At Stake!
Cyber Security Challenge Germany (2023)
zhlédnutí 21KPřed rokem
Cyber Security Challenge Germany (2023)
Cybercrime is Not Hacking!
zhlédnutí 78KPřed rokem
Cybercrime is Not Hacking!
Attacking Language Server JSON RPC
zhlédnutí 56KPřed rokem
Attacking Language Server JSON RPC
Advanced Teleport Hack (stolen from cheaters)
zhlédnutí 46KPřed rokem
Advanced Teleport Hack (stolen from cheaters)
VPNs, Proxies and Secure Tunnels Explained (Deepdive)
zhlédnutí 81KPřed rokem
VPNs, Proxies and Secure Tunnels Explained (Deepdive)
Velocity Exploit on Paper?
zhlédnutí 79KPřed rokem
Velocity Exploit on Paper?
Computer Networking (Deepdive)
zhlédnutí 108KPřed rokem
Computer Networking (Deepdive)
Revisiting 2b2t Tamed Animal Coordinate Exploit
zhlédnutí 62KPřed rokem
Revisiting 2b2t Tamed Animal Coordinate Exploit
What is a Protocol? (Deepdive)
zhlédnutí 167KPřed rokem
What is a Protocol? (Deepdive)
Can AI Create a Minecraft Hack?
zhlédnutí 610KPřed rokem
Can AI Create a Minecraft Hack?

Komentáře

  • @matiassandacz9145
    @matiassandacz9145 Před 14 hodinami

    I think this is not working any more.

  • @rodrigomarros7353
    @rodrigomarros7353 Před 19 hodinami

    who is the guy streaming?

  • @kumarkumar-md7ee
    @kumarkumar-md7ee Před 21 hodinou

    awesome!!!!!

  • @drallersouldust3054
    @drallersouldust3054 Před 23 hodinami

    I kept receiving offers, reward and an invitation for help sometimes it's too attractive but No, I couldn't fall for that kind of phishing scam lol .. been like that for decades. but never

  • @kittoh_
    @kittoh_ Před dnem

    Awesome stuff boss!

  • @jacolansac
    @jacolansac Před dnem

    Dude. Your explanations are fantastic. Congrats and thanks.

  • @mjango3719
    @mjango3719 Před dnem

    18:01 The last time, I met Thomas in person was in 2019. I wouldn’t have recognized him with the beard. Doesn’t look like a 12 year old anymore

  • @maplessss
    @maplessss Před dnem

    keep hacking ❤

  • @sadasow2670
    @sadasow2670 Před 2 dny

    Ich verstehe nur Bahnhof

  • @Wren6991
    @Wren6991 Před 2 dny

    Can confirm LiveOverflow is exactly as nice in person as he seems on his channel

  • @Linuxe_d
    @Linuxe_d Před 2 dny

    I am cooked 😢, everytime I try reverse engineering something I get stuck 😞, maybe I was not made for it

  • @ravbhuva
    @ravbhuva Před 2 dny

    I always wanted to learn Android Security & Pentesting but I never found any authentic source to learn. Thank you so much for bringing this up and Yes I have signed up.😇😇😇😀🙂🙂😊

  • @mystiquegirl2023
    @mystiquegirl2023 Před 3 dny

    Just have to say I am proud of you, keep up the good work!!

  • @anasgharbi3801
    @anasgharbi3801 Před 3 dny

    why not use wait() instead of ready boolean to wait for the child process

  • @Infarlock
    @Infarlock Před 3 dny

    For me the video started at 18:00 because I understood nothing till then :D

  • @TheFreelancer131
    @TheFreelancer131 Před 3 dny

    Iv heard your server explanation having a d&d player gm relationship to 😆

  • @BEBETTER-1
    @BEBETTER-1 Před 3 dny

    dude i was literally 17 at the time of release of this video thanks

  • @Phoenix-e3c
    @Phoenix-e3c Před 4 dny

    gud game

  • @loganlopez1617
    @loganlopez1617 Před 4 dny

    I was so close to meeting you! I heard hextree but my brain refused to put 2 and 2 together until I saw the video. I was laser focused on the ESV CTF and I was on the J4v4C0d3C14n(); team that got #3 on the final scoreboard. I did stop by the raspberry pi booth and your booth was SWAMPED but at least I got a few RP2350s. I'll be sure to catch you next year.

  • @semitangent
    @semitangent Před 4 dny

    Not sure if you've been there, but Black Hat Europe in London is also amazing and super easy to reach by flying to Stansted. Been there last year and it was a blast, but definitely more polished than defcon ;)

  • @DSAhmed
    @DSAhmed Před 4 dny

    Yes it did rain in Vegas, i was as shocked as you.

  • @DSAhmed
    @DSAhmed Před 4 dny

    Dude, i was there at BlackHat this year for the first time in 12 years, and i missed you :(

  • @claytonguzman8598
    @claytonguzman8598 Před 4 dny

    Pleasure meeting you in person! Thanks again for hopping on camera for that DEFCON reel! :D

  • @pavelyankouski4913
    @pavelyankouski4913 Před 4 dny

    its seems to be I am different, because I am stuck in a time, avarage game designer in US is 20 years old and I am almost 40 ^^ We grow slower in Eastern Europe ^^

  • @nelioasousa
    @nelioasousa Před 4 dny

    This video was wild! Thanks

  • @ajinrenfire
    @ajinrenfire Před 4 dny

    You alive?

  • @NothingForThisWorld1692

    what is IRC channel ?!

  • @Ghandmann1
    @Ghandmann1 Před 5 dny

    Glückwunsch zu diesem Erfolg. Vom kleinen CZcamsr auf die große Bühne beim Who-is-Who der Defcon/BlackHat/Google. :) Grüße aus dem ZAK ;) Und: Stay humble!

  • @starchild_3693
    @starchild_3693 Před 5 dny

    Congratulations @LiveOvereflow

  • @lukor-tech
    @lukor-tech Před 5 dny

    Thanks for such a great video, I've been SUPER surprised you were updating real-time during the event and I hope you had lots of fun in the wilderness later on ;D Take a breather and h4x on

  • @saireddy9707
    @saireddy9707 Před 5 dny

    awesome happy to see hextree public .you always inspired many i am one of those and continue to do what do you overflow the scope kudos once again....

  • @patfre
    @patfre Před 5 dny

    I was in Las Vegas a couple of weeks ago when it was 47 Celsius and I am from Denmark where just getting 30 is unusual

  • @Agent_Orange_Peel
    @Agent_Orange_Peel Před 5 dny

    Damn, I missed you at the con. I’ll try to catch you next year and say hi.

  • @netanelkomm5636
    @netanelkomm5636 Před 5 dny

    It was so cool to meet you in person in DEFCON😄 Keep up the good work!

  • @notdavlu
    @notdavlu Před 5 dny

    Congrats on Hextree! 🥳

  • @aaronstone628
    @aaronstone628 Před 5 dny

    I went this year and couldn’t believe it. It was crowded beyond belief. I won’t be surprised if DEFCON builds their own convention center for hack spaces and talks. Good to go this year, lots of crowding thought.

  • @rickiwinner
    @rickiwinner Před 5 dny

    liking + comment to boost! glad to see you back, great vid

  • @sapperlott
    @sapperlott Před 5 dny

    Schön zu sehen, dass sich eure harte Arbeit auszahlt 👍

  • @omfikchannel92
    @omfikchannel92 Před 6 dny

    Saya perlu bantuan dan saya akan beri 100 juta

  • @makeaniiimpactYT
    @makeaniiimpactYT Před 6 dny

    The YT algorithm randomly pushed this video to me (probably because I live in vegas) but I'm not a hacker, in software design with my consulting company and YT channel. Watched the whole video and I've never had a booth at a conference and have been wanting to have one. Watched this entire video and loved the content!

  • @zfutox7224
    @zfutox7224 Před 6 dny

    Is some music AI generated? It has that vibe to it (especially at 4:35). I hope im not stepping on someone toes here 😅

  • @davidabba7663
    @davidabba7663 Před 6 dny

    Enjoyed Thank you 🎉

  • @ROBOTRIX_eu
    @ROBOTRIX_eu Před 6 dny

  • @Mortec593
    @Mortec593 Před 6 dny

    Waiting for next video 😊

  • @MustardShoe
    @MustardShoe Před 6 dny

    it was nice meeting you and your friends at the taco restaurant. Best of luck!

  • @31redorange08
    @31redorange08 Před 6 dny

    So, what vulnerabilities can an Android app have?

  • @Keksgesicht
    @Keksgesicht Před 6 dny

    09:45 simply found a real-life backdoor to a hacker conference xD

  • @Roter_Wolf
    @Roter_Wolf Před 6 dny

    Faultier is such a brilliant name xD