star-sg/Presentations
GitHub: star-sg/Presentations
STAR Labs SG 安全研究团队在各类国际安全会议上的演讲资料归档库。
Stars: 137 | Forks: 16
# 演讲
## 2025
### CodeBlue 2025 - 2025年11月18日至19日
[AI 加速利用:从 DSP 协处理器攻破启用 MTE 的 Pixel](https://github.com/star-sg/Presentations/blob/main/CodeBlue%202025/AI%20Accelerated%20Exploiting_%20Compromising%20MTE%20Enabled%20Pixel%20from%20DSP%20Coprocessor.pdf) 作者:[PAN Zhenpeng](https://twitter.com/Peterpan980927) & [Billy JHENG Bing Jhong](https://github.com/st424204)
[与 Exynos 协处理器共舞:为了乐趣与“利益”攻破三星](https://github.com/star-sg/Presentations/blob/main/CodeBlue%202025/Dancing%20with%20Exynos%20Coprocessor_%20Pwning%20Samsung%20for%20fun%20and%20profit.pdf) 作者:[Muhammad Ramdhan](https://github.com/d4em0n), [PAN Zhenpeng](https://twitter.com/Peterpan980927) & [Billy JHENG Bing Jhong](https://github.com/st424204)
### HITCON 2025 - 2025年8月15日至16日
[攻破 Pixel 8:利用未公开的 DSP 绕过 MTE](https://github.com/star-sg/Presentations/blob/main/HITCON%202025/Cracking%20the%20Pixel%208_%20Exploiting%20the%20Undocumented%20DSP%20to%20Bypass%20MTE.pdf) 作者:[PAN Zhenpeng](https://twitter.com/Peterpan980927) & [Billy JHENG Bing Jhong](https://github.com/st424204)
## 2024
### POC 2024 - 2024年11月7日至8日
[VMware Workstation:通过新途径逃逸 - 虚拟蓝牙](https://github.com/star-sg/Presentations/blob/main/POC%202024/Nguyen%20Hoang%20Thach%2C%20VMware%20Workstation%20-%20Escaping%20via%20a%20New%20Route%20-%20Virtual%20Bluetooth.pdf) 作者:[NGUYỄN Hoàng Thạch](https://twitter.com/hi_im_d4rkn3ss)
[GPUAF:Root 所有基于 Qualcomm 的 Android 手机的两种方法](https://github.com/star-sg/Presentations/blob/main/POC%202024/Pan%20Zhenpeng%20%26%20Jheng%20Bing%20Jhong%2C%20GPUAF%20-%20Two%20ways%20of%20rooting%20All%20Qualcomm%20based%20Android%20phones.pdf) 作者:[PAN Zhenpeng](https://twitter.com/Peterpan980927) & [Billy JHENG Bing Jhong](https://github.com/st424204)
## 2023
### Hexacon 2023 - 2023年10月13日至14日
[对 XNU Mach IPC 进行一年 Fuzzing 的总结](https://github.com/star-sg/Presentations/blob/main/Hexacon%202023/A%20Year%20Fuzzing%20XNU%20Mach%20IPC.pptx) 作者:[Peter NGUYỄN Vũ Hoàng](https://github.com/peternguyen93)
### HITCON CMT 2023 - 2023年8月18日至19日
[过去的幽灵:Trend Micro 企业产品中的经典 PHP RCE 漏洞](https://github.com/star-sg/Presentations/blob/main/HITCON%202023/Ghosts%20of%20the%20Past%20-%20Classic%20PHP%20RCE%20Bugs%20in%20Trend%20Micro%20Enterprise%20Offerings.pdf) 作者:[POH Jia Hao](https://github.com/limerencee)
[眼见非所得:攻破基于 Electron 的 Markdown 笔记应用](https://github.com/star-sg/Presentations/blob/main/HITCON%202023/Pwning%20Electron-based%20Markdown%20Note-taking%20Apps.pdf) 作者:[LI Jiantao](https://github.com/chromium1337)
### Offensivecon 2023 - 2023年5月19日至20日
[挖掘 Apple 生态系统中的漏洞:KidFuzzerV2.0 的艺术](https://github.com/star-sg/Presentations/blob/main/Offensivecon%202023/Unearthing%20Vulnerabilities%20in%20the%20Apple%20Ecosystem%20The%20Art%20of%20KidFuzzerV2.0.pdf) 作者:[PAN Zhenpeng](https://twitter.com/Peterpan980927)
## 2022
### POC 2022 - 2022年11月10日至11日
[如何利用 Time Machine 进行备份与攻破](https://github.com/star-sg/Presentations/blob/main/POC%202022/Nguyen%20Hoang%20Thach.pdf) 作者:[NGUYỄN Hoàng Thạch](https://twitter.com/hi_im_d4rkn3ss)
[走向混合式 Apple 驱动 Fuzzing 之旅](https://github.com/star-sg/Presentations/blob/main/POC%202022/Zhenpeng%20Pan.pdf) 作者:[PAN Zhenpeng](https://twitter.com/Peterpan980927)
### Defcon 30 - 2022年8月11日至14日
[条条大路通向 GKE 宿主机:4 种以上的逃逸方法](https://github.com/star-sg/Presentations/blob/main/Defcon%2030/Billy%20Jheng%20%20%20Muhammad%20Alifa%20Ramdhan%20-%20All%20Roads%20leads%20to%20GKEs%20Host%20%204%2B%20Ways%20to%20Escape.pdf) 作者:[Billy JHENG Bing-Jhong](https://github.com/st424204) & [Muhammad Ramdhan](https://github.com/d4em0n)
### Zer0Con 2022 - 2022年4月21日至22日
[搜寻 macOS 内核漏洞之旅](https://github.com/star-sg/Presentations/blob/main/Zer0Con%202022/A%20Journey%20Of%20Hunting%20macOS%20kernel.pptx) 作者:[Peter NGUYỄN Vũ Hoàng](https://github.com/peternguyen93)
### NUS GreyHats Security Wednesday - 2022年4月6日
[手动源代码审查简介](https://github.com/star-sg/Presentations/blob/main/NUS%20GreyHats%20SecWed%20Apr%202021/Introduction%20to%20Manual%20Source%20Code%20Review/Introduction%20to%20Manual%20Source%20Code%20Review.pdf) 作者:[POH Jia Hao](https://github.com/limerencee)
[V8 中不正确的按位与优化案例分析](https://github.com/star-sg/Presentations/blob/main/NUS%20GreyHats%20SecWed%20Apr%202021/A%20case%20study%20of%20an%20incorrect%20bitwise%20and%20optimization%20in%20V8/CVE-2021-30599_official.pptx) 作者:[Lucas TAY](https://github.com/cExplr)
## 2021
### Indonesia IT Security Conference 2021 - 2021年12月4日至5日
[VM 逃逸案例研究:VirtualBox 漏洞搜寻与利用](https://github.com/star-sg/Presentations/blob/main/IDSECCONF%202021/VM%20Escape%20Case%20Study_%20VirtualBox%20Bug%20Hunting%20and%20Exploitation%20(IDSECCONF%202021).pdf) 作者:[Muhammad Ramdhan](https://github.com/d4em0n)
### HITCON 2021 - 2021年11月26日至27日
[大逃亡 - VM 逃逸与 EoP 漏洞案例分析](https://github.com/star-sg/Presentations/blob/main/HITCON%202021/The%20Great%20Escape%20-%20A%20Case%20Study%20of%20VM%20Escape%20and%20EoP%20Vulnerabilities(HITCON%202021).pdf) 作者:[Billy JHENG Bing-Jhong](https://github.com/st424204) & [Muhammad Ramdhan](https://github.com/d4em0n)
标签:演讲资料, 目录枚举, 硬件安全, 移动安全, 虚拟化安全