sam4k
banner
sam4k.com
sam4k
@sam4k.com
pwning kernels & blogging on os internals 🌱
with offensivecon around the corner, i figured id write another post on linux kernel exploitation techniques - this time i cover the world of page table exploitation! enjoy 🤓

sam4k.com/page-table-k...
Kernel Exploitation Techniques: Turning The (Page) Tables
This post explores attacking page tables as a Linux kernel exploitation technique for gaining powerful read/write primitives.
sam4k.com
May 8, 2025 at 1:58 PM
Reposted by sam4k
Diving into Linux kernel security

Alexander Popov published his H2HC talk slides that describe how to get started with learning Linux kernel security and knowingly configure the security parameters of Linux-based systems.

a13xp0p0v.github.io/img/Alexande...
December 18, 2024 at 2:25 PM
Reposted by sam4k
We are extending our call for papers to January 1, 2025!

We are now targeting an end of January release.

If you have any Linux/ELF related research, projects, or papers, we would love to publish them!

Huge thank you to everyone who has already submitted!

tmpout.sh/blog/vol4-cf...
December 16, 2024 at 9:36 PM
it's been a while, but here's a new post in my linternals series where i attempt to introduce the linux kernel's memory management subsystem 🐧

sam4k.com/linternals-e...
Linternals: Exploring The mm Subsystem via mmap [0x01]
In this series we'll explore the Linux kernel's memory management subsystem, using a simple userspace program as our starting point.
sam4k.com
December 16, 2024 at 2:05 PM
for anyone interested in linux kernel or android security research, i'm experimenting with a custom feed here bsky.app/profile/did:...
December 3, 2024 at 7:45 PM
Reposted by sam4k
Novel approach to exploit a limited OOB on Ubuntu at Pwn2Own Vancouver 2024

Slides from a talk by Pumpkin Chang about exploiting a stack out-of-bounds write bug in the traffic control subsystem.

u1f383.github.io/slides/talks...
November 27, 2024 at 6:51 PM
pretty cool UAF in the handling of stack expansion in kernels 6.1 - 6.4 https://seclists.org/oss-sec/2023/q3/4
oss-sec: StackRot (CVE-2023-3269): Linux kernel privilege escalation vulnerability
seclists.org
July 5, 2023 at 1:48 PM
just got back from speaking on kernel exploitation at typhooncon in seoul: awesome organisers, attendees and city :)
June 19, 2023 at 1:54 PM
heading off to seoul tomorrow, super excited for my first time in south korea and at typhooncon
June 8, 2023 at 10:22 PM