DEVCORE
1
Talks Delivered
1
Events Spoken At
0
Countries Visited
1
Years Speaking
1
Total Talks Given
Jian-Lin Peng, aka YingMuo (@YingMuo), is a security researcher at DEVCORE. His work primarily focuses on IoT, macOS kernel and hypervisor security. He has participated in Pwn2Own competitions 2 times, successfully compromising QNAP NAS. He was also a speaker at HITCON PEACE 2022 and DEVCORE CONFERENCE 2024.
Areas of Expertise
Presentation Types
Audience Types
Have you ever thought about using Windows File Explorer to pwn QNAP TS-464?
At Pwn2Own 2024 Ireland, we pwned QNAP TS-464 with several vulnerabilities in SAMBA achieving pre-auth RCE. Unlike the previous engagement when we worked up to the deadline, we identified a distinct vulnerability and gain RCE via Windows File Explorer within three days.
In this talk, we will explain the details of root causes and exploit chain.