EXODUS BLOG


Exploit Techniques

Firefox Vulnerability Research Part 2

NOVEMBER 10, 2020
By Arthur Gerkis and David Barksdale This series of posts makes public some old Firefox research which our Zero-Day customers had access to before it was known publicly, and then our N-Day customers after...
Read More

Firefox Vulnerability Research

OCTOBER 20, 2020
By Arthur Gerkis and David Barksdale This series of posts makes public some old Firefox research which our Zero-Day customers had access to before it was known publicly, and then our N-Day customers after...
Read More

A EULOGY FOR PATCH-GAPPING CHROME

FEBRUARY 24, 2020
Authors: István Kurucsai and Vignesh S Rao In 2019 we looked at patch gapping Chrome on two separate occasions. The conclusion was that exploiting 1day vulnerabilities well before the fixes were distributed through the stable channel...
Read More

Patch-gapping Google Chrome

SEPTEMBER 9, 2019
Patch-gapping is the practice of exploiting vulnerabilities in open-source software that are already fixed (or are in the process of being fixed) by the developers before the actual patch is shipped to users. This...
Read More

To ../ or not to ../, that is the question

SEPTEMBER 13, 2018
Contributors: Grant Willcox and Gaurav Baruah Intro During our day-to-day research of N-day vulnerabilities at Exodus, we often come across public advisories containing incorrect root cause analysis of the core vulnerability. This blogpost details...
Read More

True Key: the not so uncommon story of a failed patch

SEPTEMBER 10, 2018
In this blog post, we examine the vendor-supplied patch addressing CVE-2018-6661.  The vulnerability was initially reported to Intel Security (McAfee) in June 2017 and disclosed publicly in April 2018.  Additionally, we contacted McAfee regarding the...
Read More