ucsb-seclab / boomerang
Exploiting the Semantic Gap in Trusted Execution Environments
☆55Updated 5 years ago
Alternatives and similar repositories for boomerang:
Users that are interested in boomerang are comparing it to the libraries listed below
- Some tee/trustzone helper stuff☆51Updated 5 years ago
- Debugger for the Shannon Baseband☆58Updated 4 years ago
- trustonic tbase research☆31Updated 7 years ago
- Android user space components for the Trustonic Trusted Execution Environment☆35Updated 9 years ago
- ☆32Updated 4 years ago
- An IDA file loader for Mobicore trustlet and driver binaries☆59Updated 5 years ago
- Source code for building an exploitable linux kernel challenge iso.☆44Updated 11 years ago
- Qualcomm TrustZone kernel privilege escalation☆63Updated 8 years ago
- FirmWire has replaced ShannonEE. OLD: A dynamic analysis environment for Samsung's Shannon baseband.☆40Updated 3 years ago
- Fuzzing utility which enables sending arbitrary SCMs to TrustZone☆61Updated 9 years ago
- Standalone C version of the MSM8974 TrustZone exploit☆27Updated 4 years ago
- Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86) adapted to afl++☆44Updated 3 years ago
- A firmware base address search tool.☆44Updated 9 months ago
- A clang analyzer checker that looks for kernel uninitialized memory disclosures to userland.☆59Updated 6 years ago
- ☆56Updated 4 years ago
- just an experiment☆21Updated 6 years ago
- Webkit JavascriptCore Array unshift function had a race condition, it leads to RCE.☆44Updated last year
- ☆30Updated 4 months ago
- Tasteless CTF 2019☆20Updated 5 years ago
- QSEE Shellcode to directly hijack the "Normal World" Linux Kernel☆54Updated 8 years ago
- ☆38Updated 4 years ago
- Reverse-engineering tools and exploits for Samsung's implementation of TrustZone☆148Updated 5 years ago
- IDA+Triton plugin in order to extract opaque predicates using a Forward-Bounded DSE. Example with X-Tunnel.☆52Updated 5 years ago
- A code-searching/completion tool, for IDA APIs☆83Updated last month
- CVE-2014-4322 Exploit☆24Updated 9 years ago
- QEMU with support for QDSP6 user mode emulation☆32Updated 5 years ago
- ☆89Updated 2 years ago
- Abstract library to generate angr states from a debugger state☆59Updated 4 years ago
- American Fuzzy Lop + Dyninst == AFL Fuzzing blackbox binaries☆74Updated 3 years ago
- ☆31Updated 4 years ago