Zardus@DEFCON.social Profile Banner
Zardus@DEFCON.social Profile

@Zardus

6,681
Followers
90
Following
56
Media
903
Statuses

Retired @DEFCON CTF org, @Shellphish Captain Emeritus, @ASU Prof, @angrdothorse hacker, @CISAGov Tech Advisory Council, Now at

Joined October 2008
Don't wanna be here? Send us removal request.
📢 ASPIRING HACKERS! Want to learn to hack? Since it's virtual anyways, we're opening our Fall 2020 ASU Computer Systems Security / CTF course to the WHOLE WORLD! More info, including lecture times, youtube/twitch/presentation links, and practice problems:
9
331
792
Hello hackers! Wanted to try @pwncollege but never got past the expectation of x86 Assembly knowledge? Now you can! We just launched a new Assembly Crash Course lecture series to complement last year's Assembly Refresher challenges! Check it out:
6
125
487
Today, we launched this year's Kernel Security module, at ! Interested in getting into kernel exploitation? Want to know what we changed this year? Stay a while, and listen...
2
143
455
@DEFCON 29 was my 20th year at DEFCON, 13th year in the CTF room, and 4th (and final!) year on the organizer stage. I am so thankful to the community for giving me the chance to host DEFCON CTF, and to my amazing team, @oooverflow , for making this lifelong dream a reality!
1
19
230
Hello hackers! This thread is about a tricky but important issue: getting people into Cybersecurity, and one (of many!) things we're doing about it. Read on below! 🧵
5
42
208
Small tab completion fail live on stream today...
Tweet media one
9
14
194
Hello hackers! Finished all the awesome challenges on ? Ready for more? It's your lucky day! Today, we're launching a new feature: Community Dojos full of new and exciting challenges to tackle and learn from! Read on! 🧵
5
42
164
Hello aspiring hackers! @ASU 's fall semester starts today (2021/9/19), and that means that @TheConnorNelson and I are bringing you all another iteration of ! Interested in what this year will bring? Let me spin you a thread.
7
41
159
All five levels of the Kernel module of () are now released! Go hack them! As a reminder, this module is an *intro* to working with the kernel; we'll be exploiting actual bugs in the kernel a few modules from now!
0
44
157
Sorry for the late notice, but if you're looking for something to do this weekend, we've launched a few extra heap challenges while we get Race Conditions ready for next week!
1
31
116
Hello hackers! @ASU 's Fall semester starts in one week, and that means so does this year's refresh of ! Interested in learning to hack, want to look back at the evolution of the platform that taught you to hack, or just like reading me ramble? Read on! 🧵
1
44
117
We're back! Super proud of @shellphish for pulling this off!
Tweet media one
@DARPA
DARPA
3 months
Congrats to the 7 companies that will receive $1 million each to develop AI-enabled cyber reasoning systems that automatically find and fix software vulnerabilities as part of the #AIxCC Small Business Track! Full announcement: .
Tweet media one
14
89
279
3
9
117
Today is @DEFCON Quals... and for the first time in 15 years, I am not involved in any capacity! After 9 years playing, 4 years hosting, and 2 years playing again, this weekend is going to be a family event rather than a caffeine-fueled hacking extravaganza... Complex emotions!
3
6
114
A photo of my license plate, to honor @aleph_one 's Smashing the Stack for Fun and Profit turning 25 years old!
Tweet media one
5
1
111
All 13 levels of practice problems for the sandboxing module are up! More info at . Can you escape the sandbox?
0
27
111
Hello hackers! just passed a massive milestone: 1 MILLION flags have been captured by hackers across the platform! The millionth flag was from level 84 of the Program Interaction module! What a wild journey from humble beginnings.
Tweet media one
1
21
110
Wondering what we've been up to since last semester's ? This semester, I ran a course to give @ASU students real-world Vulnerability Research experience. Thread here. TLDR: we'll have a summary stream on Apr 27 at 12:00pm AZ time at !
2
24
101
This year's iteration of is well on its way, with today's launch of a streamlined Program Interaction module! But, in BIGGER NEWS, the first stream by @TheConnorNelson for the new intro "White Belt" material (aka ASU CSE 365) is TODAY at 4:30pm AZ time!
2
16
99
Amazing to see CTF-style education spreading beyond security!
@FetchDEX
FeDEX
5 months
Just finished my first teaching experience. Had a blast discussing computer architecture with the freshmen of @uvtromania this semester. We experimented with a new concept of turning the entire course into a CTF, computer architecture-themed.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
4
9
78
0
8
87
We're live with the semester summary of ASU's Applied Vulnerability Research class NOW on !
2
15
80
Hello academics! Arizona State University is hiring tenure-track cybersecurity professors! Areas of interest include security of distributed systems, consensus (/blockchain!), distributed ML, MPC, IoT, and much much more! Deadline Jan 15th. More info at
1
29
78
It was an honor hosting @DEFCON CTF quals again! Thanks for playing! And a special thank you to my amazing teammates on @oooverflow ! You rock. Team work makes the dream work.
@oooverflow
Overflow
4 years
And that's a wrap on @defcon #CTF ! Congratulations A*0*E for the dominating win! Also congratulations to Samurai for the 2nd place finish and to Shellphish for 3rd place!
Tweet media one
1
57
205
1
15
76
Super honored to be part of the @CISAgov TAC! With the possible exception of this @Zardus fella, this is one of the most competent (and coolest) government committee compositions I’ve seen. I have no doubt we’ll help make @CISAgov ’s mission a success!
@CISAJen
Jen Easterly🛡️
2 years
👉THIS! Super psyched & grateful to announce that @dinodaizovi , @effffn , @kurtopsahl , @runasand , @Zardus , @RachelTobac , @dwizzzleMSFT , @woodyatpch , @bcrypt & Isiah Jones will be part of our @CISAgov Technical Advisory Council led by @thedarktangent .
13
53
263
11
6
75
Hello hackers! Sorry to overwhelm you with @pwncollege news, but we just launched the first new module of the new White Belt material: Talking Web ()! A few more details below 🧵
1
10
73
Hello (aspiring) hackers! I am (mostly) recovered and going on stream RIGHT NOW for the launch of this year’s Assembly Refresher (new!) and Shellcoding modules! See you at !
0
11
70
Congrats @mmm_ctf_team for their inaugural @defcon CTF victory! Great job to everyone that played and to the organizers! Onwards to next year.
1
8
68
Good luck to everyone playing @defcon CTF quals! But most of all, good luck and smooth sailing to @Nautilus_CTF ! Glad you’re running it and not us :-)
0
5
66
Join us for the first stream of the year in 10 minutes at (although we’ll likely be a bit late due to setting up in a new room and so forth)!
1
9
66
BAR2018 paper PDFs are available at !
1
41
63
Videos for Module 4 of , Reverse Engineering, are UP! Check them out at , or join us Wednesday at 2:30pm AZ time for a prerecorded stream on . The extended Q&A and collaboration is right after, at 4:30pm!
1
16
60
The @oooverflow is trickling into Vegas and ALREADY PICKING FAVORITES! #ctfgate #bbq
Tweet media one
2
2
58
My daughter brought me a mean cold (not COVID, according to MANY tests) from preschool and left me sick and miserable for 3 weeks now! Out of caution (and misery), I moved classes online for now, which resulted in this thread of reflection on online vs in-person teaching...
2
13
58
Just happened to check the stats of our youtube channel. Check out that view count!
Tweet media one
Tweet media two
0
0
57
Hello Hackers! The inaugural #pwncollege Quarterly Quiz is LIVE at ! It’s a series of tough kernel pwning chals from the one and only @ky1ebot , kernel hacker extraordinaire, and will lead you on a journey through Linux kernel pwning and the VFS subsystem!
1
15
53
Just emerged up from the post-CTF coma. It was an honor for me and my incredible colleagues on @oooverflow to host @DEFCON #CTF quals for the second time! Thanks to all the amazing teams for playing, and keep those pistachios coming!
0
4
53
#defconquals2018 is over! Congrats to the qualifying teams, and than you all for playing. Hosting @DEFCON CTF with @oooverflow is a dream come true, despite the lack of sleep and other associated insanity!
0
4
51
At the rate the students have been blowing through this semester, sometime in the next day or two, we'll surpass 31337 total flag captures on the new instance!
0
3
49
Great writeup of a great kernel exploit by a great hacker!
@ky1ebot
kylebot
2 years
Finally, here is the blog documenting the crazy 7 days that I spent on CVE-2022-1786 to pwn kCTF (and won a lot of cash)! Let me know what you think of the blog!
5
228
773
0
1
49
I'm sure everyone's attention's elsewhere right now, but if you want to learn about (intro) heap exploitation, lectures for our next module () are up! We'll restream them at 2:30pm AZ time at , do a Q&A at 4:30, and launch challenges!
1
6
49
@zoaedk @oooverflow The personal impact is even worse. My daughter was born four months ago, and I spent most the time since in my office working on the CTF. I missed her first laugh and her first time rolling over to help bring you DEF CON. Others made similar sacrifices.
2
1
48
The discord is on the verse of becoming the most popular @ASU discord server! One step closer to Arizona (cyber)Security University! :-)
Tweet media one
1
2
47
😢☎️📞☎️📞☎️📞☎️📞☎️📞
@zommiommy
Tommaso Fontana
3 years
Everybody is asking "what's the flag @Zardus ?" but no one is asking "how are you Zardus?".
1
1
29
2
5
46
With DEFCON over and the thankyous sent, you, the twitter reader, might ask, "what's next"? There's a lot we're working on, from academic research, to and other education concepts, to @ctfradiooo . We'll stay busy. But let me ask, what is next for YOU?
1
9
45
20 years ago, high school me wandered the halls of the @AlexisPark at @DEFCON 9, absolutely in awe of the giants throwing exploits in the CTF room, the legends speaking in the tracks, and the titans giving and getting black badges. I never imagined I could occupy the same ranks.
2
4
43
Are you an undergrad or recent graduate interested in a summer internship doing awesome research and playing CTF at our lab at ASU? Our summer internship applications are now open! Apply at and choose my project :-)
0
12
42
Hello hackers! Tomorrow, April 1st, at 5pm Arizona time (8pm Eastern), we’ll launch the inaugural #pwncollege Quarterly Quiz! It’ll be a tough set of challenges written by one of the top hackers in the world! Drop by tomorrow, or read on for more details!
1
12
43
Belated announcement! I'm starting as an @ASU asst professor in August! Interested in a PhD or internship doing sec research & CTF? Ping me!
6
10
43
Reviewing writeups. My favorite ones are @mhackeroni 's adamtune writeup () and this AMAZING unintended LFI-to-speech-to-text from #KRAUTSTRIKE .
Tweet media one
1
18
41
The first 7 levels of the sandbox escape challenges from are live, with more launching in over the next day! Check them out at . Can @ASU students hack out of sandboxes faster than students around the world? We'll find out!
2
9
41
The best part of hosting (and playing!) CTFs is being forced to learn amazing, little-known tech to an absurd depth. This DEFCON, @JakeCorina forced me to learn VMX to write this part of the OOOWS challenge series with him and @michaeljpizza .
@oooverflow
Overflow
3 years
@adamdoupe @intel Finally, on the last day (after an all-nighter by @Zardus to set everything up), was ooows-hyper-o! This time we replaced that pesky KVM with our OOOWN hypervisor, to see how teams could successfully execute a hypervisor exploit to steal the flag
1
2
7
2
5
41
Back from a crazy week of travel, culminating in a visit to @RPISEC ! Their shirts are almost as good as their CTF skillz :-)
Tweet media one
0
8
39
Yo! Hopping back on to spread the word that @TheConnorNelson , of @pwncollege fame, is making moves toward becoming Dr. Nelson! Join us for his PhD proposal, which will be live streamed on at 3pm AZ time today (in just over an hour)!!!
4
6
40
It is happening!
@angrdothorse
angr
5 years
Recently, with the support of @DARPA 's CHESS program, I grew a decompiler! If you're interested, grab an **alpha** release of my GUI, and get decompiling! My *alpha-quality* decompilation's optimized for one amd64 binary, but may work on other stuff!
Tweet media one
4
125
289
0
4
39
Hello hackers! The rest of the Race Condition challenges (and videos) are up! Check them out at !
0
5
37
Thanks for joining our first #pwncollege stream! The recording is now live on YouTube ()! Stay tuned for our Shellcoding module next week!
1
5
36
Hello aspiring academics! I'm excited to spread the news that Arizona State University once again has open Assistant/Associate/Full Professor positions in Cybersecurity (job ad: )! Curious about ASU? Read this thread!
1
5
36
It was an honor to run #DC26CTF with my fellow @oooverflow overlords. Now, time to sleep for two weeks straight!
@oooverflow
Overflow
6 years
Order has been established! Thank you, cybercitizens, and congratulations to DEFKOR00T for winning @DEFCON #CTF ! Enjoy the black badges. Congrats to 2nd place PPP and 3rd place HITCON!
Tweet media one
10
173
402
1
11
35
Hello hackers! Quick reminder that in just under 6 hours, at 12:00pm AZ time, we'll be streaming about our experience running an Applied Vulnerability Research course this semester as a followup to . See you at noon at !
2
7
36
@zoaedk @oooverflow We make these sacrifices because we are passionate about the CTF community. Traditionally, those who dominated under an organizer took on the mantle to serve the community for the next phase. This held for 20 years of ghettohackers, kenshoto, ddtek, and legitbs.
2
2
36
So crashed under the load when we went to bed. Should be back up now! 💪
0
0
35
Read about our new research center: the @asu_gsi center for Cybersecurity and Trusted Foundations! @ASU has an awesome institutional design in which centers like the CTF (see what we did there?) enable us to do things that would normally be insane/impossible in academia.
@ASU
Arizona State University
2 years
. @asu_gsi 's new Center for Cybersecurity and Trusted Foundations aims to address the long-term cybersecurity challenges facing the nation. 🔐
1
7
17
0
2
35
. @trailofbits manticore solves magic from DEFCON quals. How about the whole crackme2000 category? angr does it! >:-)
1
14
35
Hello hackers! Last semester, you joined us for @TheConnorNelson ’s PhD proposal. Now, come to his PhD defense to see him present his accomplishments and (attempt to) become Dr. Nelson! See you in 30 minutes (5pm AZ) at !
1
0
35
I learn tech by hacking it, and I’d never actually dug deep into the underpinnings of virtualization before. Thanks to this challenge, I’ve learned so much about modern CPU architectures that I’m planning to run a “Dirty Secrets of Modern X86” course at @ASU next spring!
1
2
35
I just realized that this bash code is vulnerable: A=(1 2 3) read IDX echo "${A[$IDX]}" I've used the underlying weakness in other contexts, but realizing that it applied here was pretty terrifying. If you're interested, there's lots more like this at
0
1
34
Congrats to @Nautilus_CTF for running a successful quals! Now go get some good sleep before the crunch begins for DEFCON finals :-)
0
0
32
Super proud of the awesome @CIDSEASU , @ucsbcs , and @UCBerkeley students for winning the @CSAW_NYUTandon qualifying event!
2
2
32
Final pre-stream reminder! We're streaming the results of ASU's Applied Vulnerability Research class in 25 minutes at . See you there!
2
7
32
Attention hackers! We're starting in on the next module of : Shellcoding! More videos coming tonight, with an extended Q&A, knowledge solidification, and the launch of challenge problems on the Wednesday stream!
3
2
31
@zoaedk @oooverflow Hosting CTF does not help our careers. Example: the highest priority for me, career wise, is to submit a proposal for an NSF CAREER grant, a soft requirement for tenure. It is due tonight. For the third year in a row, I will miss it due to DEFCON.
1
1
31
Thanks for joining us for ASU's Applied Vulnerability Research end-of-the-semester stream! For those that missed it, you can read the livetweet summary in the linked thread, or watch it in all its glory on youtube!
We're live with the semester summary of ASU's Applied Vulnerability Research class NOW on !
2
15
80
0
5
31
Big day in infosec! Aside from its huge direct impact on the pwning community, without articles like @aleph_one ’s, resources like or would have never existed.
Today Smashing the Stack for Fun and Profit is 25 years old. Older than I was when I wrote it.
52
696
3K
0
5
31
Hello hackers! If you're following along live with this year's course, the Sandboxing module is over and the Reverse Engineering module is launching today! Join us at at 4:30 (in 10 mins)!
1
6
31
Hello aspiring hackers! Hope you’re digging into that Program Interaction module! We’ll do an extended Q&A and launch the Program Misuse module () in 25 minutes, live at . See you there!
1
0
30
Now, we need your help! We have our ideas of hackers and hacks that we'll cover (), but we're fallible. See someone/thing missing? Reply and let me know! If you have some long-form reference material along with your suggestion, that would be even better!
9
7
29
If you’re an aspiring hacker in high school, consider applying to our second annual high school research internship! It’s a great opportunity to work with great minds (plus me) at ASU’s SEFCOM research lab, hack with @asuhackingclub and @shellphish , and learn a lot!
@jackie_lef
Jackie LeFevers
2 years
Know any high school students in the Phoenix area who are passionate about hacking & computer science? The Center for Cybersecurity @asu_gsi is accepting applications for our summer '22 research internship! Due: March 21. Spread the word! 💻More info:
3
10
11
0
7
30
Looking for a tenure track position in Cybersecurity? We're hiring at ASU, with focuses on security of AI, ML, and cryptography! Apply at and come work with @adamdoupe , @___tiffanyb___ , @LtFish_ , me, and other awesome ASU faculty to usher in the future!
0
10
30
Got an hour for a cool discussion at @DEFCON ? Drop by the Policy @DEFCON Roundtable discussion room and talk about Emerging Technical Cyber Policy Topics with @bcrypt , @kurtopsahl , @effffn , and myself at 2pm!
Tweet media one
1
0
29
The videos for Module 8 of , Kernel, are up! Module 8 is about understanding the kernel, and we'll be heavily exploiting said kernel in our second combo module in a few weeks! More details at , and extended Q&A Wed at 4:30pm!
0
4
29
Hello aspiring hackers! Every summer, we host high school cybersecurity enthusiasts from around the Phoenix valley for summer internships through ASU’s Center for Cybersecurity and Trusted Foundations! Applications for this summer close in under a week!
1
10
29
Check it out! This is the prototype associated with our @USENIXSecurity paper ().
@m1ghtymo
Moritz Eckert
6 years
Happy to announce that HeapHopper, our bounded model checking tool for Heap-Implementations has now been released!
1
92
154
0
9
29
Somehow missed this tweet last week! Super honored to give a #EuroSec2022 keynote! Make sure to wear closed toe shoes 🖥️🦶🤖
@EuroSecWorkshop
EuroSec Workshop
2 years
We are thrilled to announce the first keynote speaker of EuroSec 2022! Prof. Yan Shoshitaishvili ( @Zardus ) from Arizona State University, USA will present "How Cyber Reasoning Systems Stub Their Toes". Don't miss it! #EuroSec2022 #EuroSecWorkshop @ASU @lindorferin @jpolakis
Tweet media one
0
4
14
0
3
28
📢ASPIRING HACKERS! A bit lost in the first challenge set? We've pushed some more context (and an additional video) here:
0
4
27
Excited to see the belts finally making it to people! Go pwmcollege (and even )!
@Pascal_0x90
Pascal
2 years
Forgot to attach the photo. Long day lmao
Tweet media one
3
0
9
1
1
27
Sorry for the late announcement! The videos for Module 7 (Return Oriented Programming) of are up! Challenges launching Oct 21!
0
2
26
The first 10 levels of practice problems for module 4 of (Reverse Engineering) are up (except for level7_testing1, which we're tracking down an issue with). A few more levels launching tomorrow! Details at
0
7
26
@ret2systems Giving my students extra credit to tackle #Deusx64 this week. But is it all a ploy to steal the solutions from their writeups? 😈
0
1
26
Okay! Second module extension: Module 6 (exploitation scenarios) is being extended by a week to give the students a bit more time to fully master the concepts! ROP is now coming on 10/21 rather than 10/14. More details on discord!
0
4
25
Interested in the academic peer review process in cybersecurity? Think it can be improved? Check out our upcoming @IEEESP paper where we talked to the experts and analyzed their views on the whole thing. You can start by reading this awesome and extensive thread by @adamdoupe !
@adamdoupe
Adam Doupé
2 years
👏 @AnantaSoneji will present her first first-author paper "“Flawed, but like democracy we don’t have a better system”: The Experts’ Insights on the Peer Review Process of Evaluating Security Papers" @IEEESSP If you're in academia, you'll want to 👀👇 📜
Tweet media one
7
48
223
0
5
25
Looking for an awesome PhD program in Computer Science? Want to do awesome cybersecurity research side by side with DEFCON CTF organizers, prominent CTF players, and other crazy people? Come to ASU! Apply here:
0
8
25
We published a blog post about our Human-assisted Cyber Reasoning System, coming out at @acm_ccs . Check it out!
HaCRS finds 55% more bugs over Mechanical Phish in CGC binaries. See blog post plus paper: #ccs17
1
18
26
1
11
25
Attention hackers! We launched the rest of the Module 4 (reverse engineering) challenges of ! Head on over to and test/develop your skills!
1
3
24
Aaand I screwed up the date. 2021/8/19, not 2021/9/19 :-). I blame sleep deprivation.
Hello aspiring hackers! @ASU 's fall semester starts today (2021/9/19), and that means that @TheConnorNelson and I are bringing you all another iteration of ! Interested in what this year will bring? Let me spin you a thread.
7
41
159
0
2
23
So how do we do it? This semester, @LtFish_ and I are teaching a 1st year hacking class that (hopefully!) requires ZERO technical knowledge! The course is CSE 194: Cybersecurity History and Culture (if you are an ASU student, sign up here: ).
2
4
23
Always wanted leave your mark on “The Olympics of Hacking”? Now you can! Check out @DEFCON ’s Call For Organizers and consider diving in to help make DEF CON CTF an incredible event for the CTF world! As mentioned in the CFO, @oooverflow is happy to help with the transition!
@defcon
DEF CON
3 years
#DEFCON30 Call for #CTF Organizers! Ready to create the next gen of elite CTF tournaments? Do you have the skills to elevate the game for the world’s best players? Info is at . Submit the CTF you want to see in the world. For the chosen, glory awaits.
Tweet media one
6
70
148
0
4
23
Sorry for the belated notification: all 14 levels of the shellcode challenge problems for are now up! Go hack them!
1
7
23
Want to get paid to work on the future of binary analysis tooling? We have a software engineer position open at ASU! Check it out and apply!
@asu_gsi
ASU Global Security Initiative
3 years
. @ASU GSI has an open position for 'senior software engineer' will play a key role in advancing the growth and success of GSI's Center for Cybersecurity and Digital Forensics. Join this thriving and growing team! @ASUResearch ➡️ Apply by Sept. 30th ➡️
Tweet media one
0
2
5
1
4
23