James Forshaw :donor:
tiraniddo@infosec.exchange
<p>Security researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc.</p>
Posts
-
Post #4467159
Found another hilariously trivial Windows PPL, hard to believe I didn't see this one earlier. Doesn't work in full PP due to the nature of it, but TBH PPL-WinTCB is really all you need :)
-
Post #4167056
Seems that the trick I used in https://projectzero.google/2025/01/windows-bug-class-accessing-trapped-com.html by calling ITypeInfo::CreateInstance cross process has been blocked. Sort of. They've "fixed" it in a bizarre way, there's now a new AppCompat key, which doesn't exist by default. It's HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ITypeInfoCreateInstanceSettings and in that you need a AllowedOutOfProcIIDList REG_MULTI_SZ value which provides the allow l...
-
Post #4142897
Currently implementing an airgapped network by adding two network cards to a macbook air and turning on IP forwarding.
-
Post #3161122
@GossiTheDog is Mythos going to be the new go to excuse, after no one believed that they were hit by an &quot;Advanced Attacker&quot;?
-
Post #3161121
Lolz https://www.synacktiv.com/sites/default/files/inline-images/scroll_of_truth.webp https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part-1.html https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part.html
-
Post #3161120
I don&#39;t know flash card, zero rugby balls? The things we teach children today, sheesh.
-
Post #1800970
Project Zero have finally got around to updating the blog to something less blogger-esc, check it out at https://projectzero.google. To coincide with this momentous occasion I dug out the draft of my blog post about Windows Object Manager performance which became the basis of my article in PoC||GTFO #13 and updated it to see if it still worked in Windows 11. You can read it at https://projectzero.google/2025/12/windows-exploitation-techniques.html
-
Post #1800968
My first blog post on Windows Administrator Protection is out. https://projectzero.google/2026/26/windows-administrator-protection.html probably the most interesting and complex bug out of the 9 I found, but that doesn&#39;t mean the rest weren&#39;t interesting as well, stay tuned :D
-
Post #1710308
@lcamtuf $700 a week I assume? :)
-
Post #1000244
Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why. I fucking hate MS and Defender especially.
-
Post #979620
I&#39;ve put up the slides from my Zer0Con 2026 presentation on Administrator Protection. https://github.com/tyranid/infosec-presentations/blob/master/Zer0Con/2026/Protecting%20your%20Administrator.pdf
-
Post #779678
RE: https://hachyderm.io/@pheonix/116050795790003647 FFS
-
Post #779677
Released the second part of my blog post series on Admin Protection. This time it&#39;s about how most of the bugs I found came about due to abusing UI Access which was overlooked as UAC bypasses because, well, they were UAC bypasses. https://projectzero.google/2026/02/windows-administrator-protection.html
-
Post #779676
@0x00string they&#39;re trying, in the UK I can no longer use &quot;social media&quot; parts of xbox live without verifying my ID. As I have no friends that really doesn&#39;t bother me. But I do wonder how long until they do something I do care about. I can apparently play mature content fine, it&#39;s only the online aspects, for now. What&#39;s crazy is the MS account is a US one, paid for by a US CC and yet because the xbox is sitting in the UK they apply the stupid...
-
Post #779675
@GossiTheDog I so dislike going through US immigration. Even with a green card I felt I was one CBP officer&#39;s or computer&#39;s bad day away from being locked up. I finally decided to give up the greencard once I&#39;d been out for 12 months to give me one less thing to worry about if I have to unfortunately travel there for work. Though no doubt I&#39;ll now get questions on why I&#39;d relinquish such a valuable opportunity to become a citizen of the greatest country in...
-
Post #779674
@rupert @GossiTheDog yeah I&#39;m sure it&#39;ll be fine, it was mostly in jest, but you never know. That said, I&#39;m going to do my best to never need to travel there again, which is somewhat hard in the tech industry.
-
Post #779672
The new macbook neo looks somewhat cute, but, it doesn&#39;t come with a PSU? Really? Is this going to be the new normal going forward for laptops? This seems to at least be the case in the UK, checking the US website it comes with a 20W USB-C PSU.
-
Post #779670
The new Google office in London is looking nice. https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/platform-37-the-ai-exchange/ I especially like how it&#39;s super energy efficient and uses low carbon materials while touting the world destroying tech that is AI. A masterclass of green washing.
-
Post #779669
Of course I’m deeply angry that apple chose to prostate themselves to the ineffectual ofcom who should be spending their time enforcing real laws like against GBNews. But I do wonder what happens now with devices if you log off from your unverified apple account. Does it revert to “normal” operation ? Or with 26.4 will it come up by default in kid mode? Can you use an iPhone anymore without ever signing in?
-
Post #427953
My final blog related to admin protection is up. https://projectzero.google/2026/02/gphfh-deep-dive.html I go into a bit of history of the interesting GetProcessHandleFromHwnd API, how it ended up allow you to bypass protected process restrictions and how it's now "fixed".
-
Post #10613
Testament to a Man's Hubris: Unknown Contractor 2024.