All Stories

Binary-searching into CVMServer

During the analysis of the patch for CVE-2021-30724 while writing a Fermium-252 report, our researcher (@jinmo123) discovered a vulnerability introduced by the patch. The vulnerability was reported to Apple and...

Welcome to Theori ๐Ÿ‘‹_ํ‹ฐ์˜ค๋ฆฌ ์›ฐ์ปดํ‚คํŠธ ์ œ์ž‘๊ธฐ

์•ˆ๋…•ํ•˜์„ธ์š”, ํ‹ฐ์˜ค๋ฆฌ ์ปค๋ฎค๋‹ˆํ‹ฐ ๋งค๋‹ˆ์ € otwi, ๋””์ž์ด๋„ˆ soi์ž…๋‹ˆ๋‹ค! ์—ฌ๋Ÿฌ๋ถ„์˜ ์ฒซ ์ถœ๊ทผ์€ ์–ด๋– ์…จ๋‚˜์š”? ์–ด์ƒ‰ํ•œ ๊ฑด๋ฌผ์— ๋“ค์–ด์™€ ํ•จ๊ป˜ ์ผํ•  ์‚ฌ๋žŒ๋“ค์„ ์ฒ˜์Œ ๋งŒ๋‚˜๊ณ , ์ผํ•  ์ž๋ฆฌ๋ฅผ ์•ˆ๋‚ด๋ฐ›๊ณ โ€ฆ ์ €๋Š” ๋‚ฏ์„  ํ™˜๊ฒฝ์ด ๊ดœํžˆ ์–ด์ƒ‰ํ•ด์„œ ๋ฌผ ๋งˆ์‹œ๋Š” ์‚ฌ์†Œํ•œ...

Exploiting Safari's ANGLE Component

In early 2022, I (@singi21a) found an interesting bug in WebKit WebGL Component during the code audit. This bug is exploitable and macOS/iOS Safari is affected. The bug is assigned...

Qubit Bridge Post-mortem

On January 28, 2022, Qubit was attacked through their cross-chain bridge. An attacker1 called the deposit function of the Bridge contract2 on Ethereum, passing in a valid resource ID3 that...

2021 Hot๐Ÿ”ฅ ๋ณด์•ˆ ์‚ฌ๊ฑด ์‚ฌ๊ณ  - ํ•˜๋ฐ˜๊ธฐ

์•ž์„  ํฌ์ŠคํŠธ์—์„œ๋Š” ์ƒ๋ฐ˜๊ธฐ์— ๋ฐœ์ƒํ•œ Hot๐Ÿ”ฅ ํ–ˆ๋˜ CVE์™€ ๋ณด์•ˆ ์‚ฌ๊ฑด/์‚ฌ๊ณ ๋ฅผ ๋‹ค๋ฃจ์—ˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฒˆ ์‹œ๊ฐ„์—๋Š” ํ•˜๋ฐ˜๊ธฐ์— ๋Œ€ํ•ด ๋‹ค๋ฃจ๋„๋ก ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค !

2021 Hot๐Ÿ”ฅ ๋ณด์•ˆ ์‚ฌ๊ฑด ์‚ฌ๊ณ  - ์ƒ๋ฐ˜๊ธฐ

๋‹ค์‚ฌ๋‹ค๋‚œ ํ–ˆ๋˜ 2021, ์ฝ”๋กœ๋‚˜๋กœ ์ธํ•ด ๋‹ค์–‘ํ•œ ๋ถ„์•ผ์—์„œ ๋น ๋ฅธ ์†๋„๋กœ ๋””์ง€ํ„ธํ™”๊ฐ€ ์ง„ํ–‰๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋กœ์ธํ•ด ๋‹ค์–‘ํ•œ ์†Œํ”„ํŠธ์›จ์–ด ๋ฐ ์„œ๋น„์Šค์—์„œ ์ทจ์•ฝ์  ๋ฐ ๋ณด์•ˆ ์‚ฌ๊ณ ๊ฐ€ ๋ฐœ์ƒํ–ˆ๋˜ ํ•ด๊ฐ€ ์•„๋‹Œ๊ฐ€ ์‹ถ์Šต๋‹ˆ๋‹ค. ๊ทธ ์ค‘ Hot๐Ÿ”ฅ ํ–ˆ๋˜ CVE์™€ ๋ณด์•ˆ...