Skip to content

Commit

Permalink
Updates
Browse files Browse the repository at this point in the history
  • Loading branch information
xairy committed Mar 1, 2024
1 parent d12bbf8 commit 2b8189d
Showing 1 changed file with 14 additions and 0 deletions.
14 changes: 14 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,15 @@ Follow [@andreyknvl](https://twitter.com/andreyknvl) on Twitter or [@xairy@infos

## Research

### 2023

- ["Rogue CDB: Escaping from VMware Workstation Through the Disk Controller" by Wenxu Yin](https://conference.hitb.org/hitbsecconf2023hkt/materials/D1T2%20-%20Rogue%20CDB%20Escaping%20from%20VMware%20Workstation%20Through%20the%20Disk%20Controller%20-%20Wenxu%20Yin.pdf) [slides] [[video](https://www.youtube.com/watch?v=_PfuJN-I8-8)]
- ["CVE-2023-20869/20870: Exploiting VMware Workstation at Pwn2Own Vancouver"](https://www.zerodayinitiative.com/blog/2023/5/17/cve-2023-2086920870-exploiting-vmware-workstation-at-pwn2own-vancouver)

### 2021

- ["From Binary Patch to Proof-of-concept: a VMware ESXi vmxnet3 Case Study" by Alisa Esage](https://zerodayengineering.com/research/vmware-esxi-vmxnet3-from-patch-to-poc.html) [article]

### 2020

- ["Detailing Two VMware Workstation TOCTOU Vulnerabilities" by Reno Robert](https://www.zerodayinitiative.com/blog/2020/10/22/detailing-two-vmware-workstation-toctou-vulnerabilities) [article]
Expand Down Expand Up @@ -69,6 +78,7 @@ Follow [@andreyknvl](https://twitter.com/andreyknvl) on Twitter or [@xairy@infos

- https://www.exploit-db.com/search?q=vmware
- https://github.com/unamer/vmware_escape
- https://github.com/s0duku/cve-2022-31705

## CTF tasks

Expand All @@ -89,3 +99,7 @@ Follow [@andreyknvl](https://twitter.com/andreyknvl) on Twitter or [@xairy@infos
- [Demonstration of Use-After-free Escalation in VMware](https://www.youtube.com/watch?v=XAV3JcizbwM)
- [CPython RPC Demonstration](https://www.youtube.com/watch?v=nrajtut6kEE)
- [Demonstrating the vmware_copy_pirate Metasploit Post-Exploitation Module](https://www.youtube.com/watch?v=4R-jJej_TKE)

## Other lists

- [WinMin/awesome-vm-exploit](https://github.com/WinMin/awesome-vm-exploit)

0 comments on commit 2b8189d

Please sign in to comment.