@SpecterDev

Interested in Security and Exploit Development. Nano is the one true text editor.

🇨🇦 Ontario
Joined August 2015
Please don’t take this or the replies as justification to personally attack anyone, this is mostly just a consequence of the times we’re in. It just makes me a bit sad and the situation is unfortunate.
LLMs fracturing the console research space feels like a good litmus test of where we're at lmao. The future is slop and the fun is dead.
16
5
197
18,648
LLMs fracturing the console research space feels like a good litmus test of where we're at lmao. The future is slop and the fun is dead.
29
49
4
646
66,119
But r/blackops2 said devkits/testkits have special magic that makes them impossible to ban so this can't be true
There's been a rumor going around that the dev/testkits that were banned were banned because they used a specific update file, the truth is the kits that were banned were banned because they were cheating online and anyone that suggests differently is coping
3
9
1
141
26,759
Method we used (>5 years ago, now) on ps5 to fiddle with mp4 and hv memory: github.com/fail0verflow/pros… hope it helps for linux!
18
106
10
676
146,695
Played @tihmstar's custom beatsaber song, 10/10 would play again
5
6
111
21,953
Some people already know this, but thought I'd mention here too... unfortunately basically all of my low fw PS5s got stolen recently, so I'm not sure what my future in console research will look like. Replacing this stuff might be too be difficult & expensive to be worth it :(
44
25
311
49,899
My @dayzerosec co-host zi and I are giving our 1st training @ hardwear.io with a focus on attacking security hypervisors! Trainings are something we've wanted to do for a while. Take a look and share to those who would be interested :) hardwear.io/usa-2025/trainin…
11
33
1
205
53,914
We have a training by @SpecterDev & Zi on Attacking Hypervisors From KVM to Mobile Security Platforms hardwear.io/usa-2025/trainin…
8
1
36
18,164
I've published a write-up on reversing and analyzing Samsung's H-Arx hypervisor architecture for Exynos devices, which has had a lot of changes in recent years and pretty interesting design. Hope you all enjoy :) dayzerosec.com/blog/2025/03/…
3
108
3
489
55,333
Specter retweeted
Recon Training 23-26 June 2025: KVM to Mobile Security Platforms - Attacking Hypervisors with @SpecterDev and zi from @dayzerosec (4 days) For more details recon.cx/2025/trainingFromKV…
7
34
10,358
My @dayzerosec co-host zi and I are giving our 1st training @ hardwear.io with a focus on attacking security hypervisors! Trainings are something we've wanted to do for a while. Take a look and share to those who would be interested :) hardwear.io/usa-2025/trainin…
11
33
1
205
53,914
RE: byepervisor do people care enough about not wanting to use rest mode and resume to switch the primary exploit for byepervisor to the jump table one? its higher maintenance and possibly slightly less stable but would be slightly more convenient to run I guess
65%yes
35%no
997 votes • Final results
18
13
104
23,340
I've published the repo for Byepervisor (we love named vulns out here). Contains exploit implementation for two PS5 hypervisor bugs for 2.xx and lower. Slides from the talk + vod should hopefully be published soon. github.com/PS5Dev/Byeperviso…
42
117
10
635
101,529
The PS5's hypervisor has kept the system secure for years—now, vulnerabilities are being revealed. What does this mean for gamers? 🕵️‍♂️🚨 Join @SpecterDev at #hw_ioNL2024 Know More: hardwear.io/netherlands-2024… #ps5 #exploit #hardware
8
34
2
221
33,788
There are a few ways on PS5 to defeat HV. One of methods that I've found was related to APIC: struct apic_ops is located in RW segment of kernel data. With KRW you can overwrite a function pointer inside it like xapic_mode and get into ROP, for example (just need to bypass CFI).
33
59
6
579
72,954
Feels great when an idea can finally be tested and works out after like a year :) Shouts to ChendoChap for working out the ROP chain. Protip: staying < 3.00 is a good idea.
48
83
13
745
125,664