#555: VirtualBox VM Escape: Integer Overflow Explained Clearly
David Bombal10 Mars

#555: VirtualBox VM Escape: Integer Overflow Explained Clearly

In this episode, David Bombal sits down with vulnerability researcher Vladimir Tokarev (with Dawid on the interview) to show what AI-assisted vulnerability research looks like when it actually works. Vladimir walks through two real vulnerability case studies and uses them to explain a practical workflow for finding bugs faster with LLMs, without pretending the AI is “fully autonomous.” Demo 1: Gemini CLI command injection Vladimir demonstrates a command injection issue in Gemini CLI tied to the IDE / VS Code extension install flow. He shows how a malicious VSIX file name or path can be crafted so that when the install command is executed, the system ends up running an attacker-controlled command (the demo uses a harmless calculator launch to prove execution). The conversation then breaks down what a VSIX is, what the realistic attack paths are (user tricked into installing a malicious extension or placing it in the right directory), and why this class of bug matters for endpoints running local AI agents. Demo 2: VirtualBox integer overflow and VM escape class impact Next, Vladimir switches to a VirtualBox vulnerability involving an integer overflow that can lead to out-of-bounds read/write in the host process. Because of architecture constraints, he shows the exploit behavior via a recorded clip, then explains the bug using source code. The key teaching moment is the mismatch between 32-bit arithmetic used in bounds checking and 64-bit pointer arithmetic used during the actual memory move, creating a pathway to bypass checks and copy memory outside the intended buffer. Vladimir also explains why having both read and write primitives is powerful for exploitation, and how modern mitigations make “blind” exploitation unrealistic without memory disclosure. How the bugs were found with AI Vladimir then explains the workflow he uses in real engagements: • Run static analysis to generate leads at scale • Use an LLM to triage and filter out noise • Validate the remaining findings by tracing code paths and checking exploitability • Use AI again to accelerate setup, debugging, reverse engineering, and iteration He shares a key insight: the win is not “AI finds everything for you,” it is that AI helps you spend your time on the hardest parts—validation, exploit logic, and decision-making—instead of drowning in thousands (or millions) of findings. Why there is no fully autonomous vuln-research agent yet Finally, Vladimir lays out four practical blockers: 1. Depth reasoning (long multi-step exploit chains) 2. Context limits (missing system-level constraints and assumptions) 3. Learning from failure (repeating bad leads) 4. Exploration (poor goal-driven search without strong reinforcement learning) // Vladimir Tokarev’s SOCIAL // X: https://x.com/G1ND1L4 LinkedIn: / vladimir-eliezer-tokarev // Dawid van Straaten’s SOCIAL // LinkedIn: / dawid-van-straaten-31a3742b X: https://x.com/nullaxiom?s=21 // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... Disclaimer: This video is for educational purposes only.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(500)

#596: This is the Real Cybersecurity Problem

#596: This is the Real Cybersecurity Problem

Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people. Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a softwar...

20 Aug 28min

#595: How to Detect Fake Cell Towers Near You

#595: How to Detect Fake Cell Towers Near You

Big thanks to Proton VPN for sponsoring this video. To sign up for Proton VPN please use the following link https://protonvpn.com/davidbombal and get 70% off. Learn how fake cell towers and Stingray...

18 Aug 1h 2min

#594: How to Protect Your Network From Insecure IoT Devices

#594: How to Protect Your Network From Insecure IoT Devices

Hackers are using overlooked IoT devices such as IP cameras, printers and smart speakers to gain access to networks and spread ransomware. Philip Wylie explains how an outdated IP camera became a ran...

30 Juli 31min

#593: How to pass the CCNA exam (advice from two Cisco instructors)

#593: How to pass the CCNA exam (advice from two Cisco instructors)

Two Cisco training veterans break down how to know you are ready for the CCNA exam, what changes in CCNA 2.0, and whether the CCNA is still worth it in 2026. Brian Bays has been teaching official Cis...

25 Juli 36min

#592: Why most enterprise AI fails (and how to succeed)

#592: Why most enterprise AI fails (and how to succeed)

Agentic AI is putting a 400x load on enterprise networks. Cisco and NTT Data experts reveal why only 13% of leaders successfully scale AI, the nightmare of quantum threats, and how to secure your infr...

15 Juli 37min

#591:  Inside the Cisco Live 2026 NOC (exclusive tour)

#591: Inside the Cisco Live 2026 NOC (exclusive tour)

Big thanks to Cisco for sponsoring my trip to Cisco Live EMEA and for changing my life and the lives of many other people. // Joe Clarke SOCIAL // LinkedIn: / joeclarke2 // YouTube video REFER...

15 Juli 26min

#590: CCNA 2.0: What did Cisco just remove from the exam?

#590: CCNA 2.0: What did Cisco just remove from the exam?

Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Vegas. Cisco has officially announced a major update to the CCNA, moving from version 1.1 to the new CCNA 2.0 bluepr...

2 Juli 44min

#589: How to run an AI agent INSIDE your network CLI for 2026

#589: How to run an AI agent INSIDE your network CLI for 2026

Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Vegas 2026. Network engineers, are you ready for 2026? Learn how to deploy an AI agent directly into your CLI using...

30 Juni 31min

Populärt inom Teknik

uppgang-och-fall
market-makers
rss-elektrikerpodden
rss-laddstationen-med-elbilen-i-sverige
skogsforum-podcast
 och-bilen-gar-bra
rss-en-ai-till-kaffet
rss-uppgang-och-fall
bli-saker-podden
rss-technokratin
hej-bruksbil
bilar-med-sladd
gubbar-som-tjotar-om-bilar
rss-veckans-ai
under-femton
klocksnack-tillsammans-med-nymans-ur-1851
rss-milpodden
bosse-bildoktorn-och-hasse-p
elbilsveckan
natets-morka-sida