6 404
订阅者
+124 小时
+187 天
+20730 天
数据加载中...
吸引订阅者
十月 '2610月 '26
十月 '26
+18
在0个频道中
九月 '26
+262
在4个频道中
Get PRO
八月 '26
+200
在4个频道中
Get PRO
七月 '26
+346
在8个频道中
Get PRO
六月 '26
+154
在0个频道中
Get PRO
五月 '26
+181
在4个频道中
Get PRO
四月 '26
+224
在5个频道中
Get PRO
三月 '26
+612
在6个频道中
Get PRO
二月 '26
+205
在2个频道中
Get PRO
一月 '26
+502
在0个频道中
Get PRO
十二月 '25
+322
在1个频道中
Get PRO
十一月 '25
+652
在2个频道中
Get PRO
十月 '25
+653
在5个频道中
Get PRO
九月 '25
+523
在1个频道中
Get PRO
八月 '25
+788
在9个频道中
Get PRO
七月 '25
+1 458
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 05 十月 | 0 | |||
| 04 十月 | +4 | |||
| 03 十月 | +2 | |||
| 02 十月 | +5 | |||
| 01 十月 | +7 |
频道帖子
| 2 | I managed to internally use HeapSnitch (modified) vulnerability in QSEE to extract UDS
As you may know Google has previously revoked this, but they reincarnated it again, and during my experiments, i figured that BCC it had did NOT involve TME or CE, and was self signed, and placed directly for S-EL0 signing.
This is critical, we expected at least that it's a leaf derivation from TME.
I am sorry but MediaTek claims spot 2 now that NSW-EL0 can do this on QSEE.
.
This came as a challenge because I've been rumored that some managed to do the same and even for StrongBox. | 1 809 |
| 3 | 没有文字... | 2 118 |
| 4 | Update:
-Adapted HeapSnitch to work on post-boot after vold CE storage decryption is completed.
Tradeoff:
- [IMPORTANT]: YOU temporarily lose access to your old blobs (symmetric/asymmetric) including RKP blobs hence the video. | 1 953 |
| 5 | 没有文字... | 2 442 |
| 6 | https://mia-ai.net/experiments/let-there-be.html | 2 354 |
| 7 | https://blog.nns.ee/2026/09/24/oneplus-root/ | 2 971 |
| 8 | Google revoked UDS, now emits 403 Perm denied
at least we know that it didn't go to 444 | 3 021 |
| 9 | Too late university starts next week, | 2 891 |
| 10 | https://x.com/Weixin_WeChat/status/2102725320646554000 | 2 824 |
| 11 | #69 breaks the hearts, rip your 248k$ sir | 2 731 |
| 12 | https://issues.chromium.org/issues/544163112 | 2 607 |
| 13 | upon checking, we can see 2 potential ways:
1- run at service.d but heap is unstable due to call swarm unlike post fs data which we can ensure proper run of HeapSnitch (3)
2- figure way to migrate keys between two slots or leak dec key of blobs & build MiniMint (OhMyKeymint like) to handle asym/sym ops with leaked key
3- figure how exp can prepare leaked known heap for post runtime to exec (note that after swapping, the apps & others won't be able to recognize old keys, causing temporarily loss of app creds & logins, teaching secondary slot on new data) | 3 095 |
| 14 | preview 🍖
exp was finished today, I am currently investigating an issue causing the change of locked status to swap slots which loses decryption of storage keys temporarily. | 3 042 |
| 15 | I got access to TypeSafe & Jev is crazy! | 4 109 |
| 16 | I mean more to that, there are some additional fields that were never described in docs | 3 913 |
| 17 | What? | 3 855 |
| 18 | (no comments) | 3 499 |
| 19 | https://issuetracker.google.com/u/7/issues/492218540
????? | 3 998 |
| 20 | you don't have to worry about me, I was already looking to get rid of my device, but everything should be safe as I pushed all my changes already, in fact I uploaded copy of the rkp db weeks ago in favor of this incident if it happens and it did | 3 484 |
