Articles by Jordan Bouyat
2 articles
Date
Thu 11 May 2017
Authors Jean-Baptiste Bédrune, Jordan Bouyat, Gabriel Campana
Category Vulnerability
Authors Jean-Baptiste Bédrune, Jordan Bouyat, Gabriel Campana
Category Vulnerability
Quarkslab was hired by OSTIF to perform a security assessment of OpenVPN 2.4.0. We focused on code and cryptography assessment. Results are briefly described in this blog post, and full report is available at its end.
We recently begun to search bugs in USB host stacks using one of our tool based on the Facedancer. This article first presents our fuzzing approach followed by a practical example of a bug in Windows 8.1 x64 full-updated. The goal of this article is not to redefine state-of-the-art USB fuzzing, nor to give a full description of our fuzzing architecture, but rather to narrate a scenario which starts from fuzzing and ends up with a bug report.