BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Witchcraft Solver: Automated 0day Discovery in Strip
 ped\n   Binaries\n   Tags: DEF CON Official Talk | Demo ðŸ’» | Tool ðŸ›  |
  Exploit ðŸª²\n   When: Sunday\, Aug 9\, 13:30 - 14:30 PDT\n   Where: LVCC
 W Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - [1]Map\n\n   Description:
 \n\n   You have a stripped binary. No source. No symbols. No harness. You\
 n   want a PoC. How do you get there? Witchcraft Solver (wsolver) is a\n  
  fully automated binary-only 0day discovery pipeline.\n\n   Phase 1 lifts 
 the binary to LLVM IR via wunstrip (.eh_frame symbol\n   recovery\, 99.98%
  accuracy)\, runs an SSA taint pre-filter to cut\n   targets by ~50%\, the
 n drives four parallel formal verification engines\n   (KLEE\, IKOS\, SeaH
 orn\, SMACK) to produce concrete violation witnesses -\n   covering the en
 tire binary in ~30 minutes\, no source required.\n\n   Phase 2 uses those 
 witnesses to seed directed fuzzing (AFLGo) and\n   binary-only concolic ex
 ecution (SymQEMU)\, converting symbolic\n   candidates into working PoCs. 
 An optional Phase 0 handles non-Intel\n   targets via a lifter portfolio (
 RetDec + Anvill + rev.ng)\, covering\n   93% of 39\,364 production ELF bin
 aries across ARM64\, ARMv7\, RISC-V\, and\n   s390x.\n\n   Validated again
 st CVE-2023-2804 (libjpeg-turbo heap-buffer-overflow):\n   SymQEMU produce
 s the first crash in 25 minutes from a stripped binary\n   with zero sourc
 e access.\n\n   The tool will be released under MIT license at the confere
 nce at:\n   https://github.com/endrazine/wsolver\n\n   Experimental valida
 tion against the wider internet is left as an\n   exercise to the audience
 ...\n\n   [1] Brossard\, J. "Unstripping Cloud Container ELF binaries." IE
 EE\n   IC_ETC 2025. https://ieeexplore.ieee.org/abstract/document/11141058
 \n   [2] Brossard\, J. "CVE-2023-2804 Complete Fuzzing Benchmark." Zenodo.
 \n   doi:10.5281/zenodo.19136269 [3] Wojtczuk\, R. "UQBTng." 22C3\, 2005. 
 [4]\n   Poeplau\, S. and Francillon\, A. "SymQEMU." NDSS 2021. [5] BÃ¶hme 
 et al.\n   "Directed Greybox Fuzzing." CCS 2017. [6] Cadar et al. "KLEE." 
 OSDI\n   2008. [7] Fioraldi et al. "AFL++." USENIX WOOT 2020. [8] Brossard
 \, J.\n   "Introduction to the Witchcraft Compiler Collection." DEF CON 24
 \, Las\n   Vegas\, August 2016. Video:\n   https://archive.org/details/you
 tube-1cgtr7VW7gY\n\n   Tool Source (once published at DEF CON):\n   https:
 //github.com/endrazine/wsolver\n\n   SpeakerBio:  Jonathan "endrazine" Bro
 ssard\n\n   Endrazine is a returning DEF CON speaker\, having previously p
 resented\n   the first attack against Microsoft BitLocker and TrueCrypt in
  2008\,\n   the infamous Rakshasa BIOS malware in 2012\, and the Witchcraf
 t\n   Compiler Collection reverse engineering framework in 2016. Endrazine
 \n   has previously presented at premier conferences such as Black Hat\,\n
    CCC\, and HITB in the industry\, as well as IEEE\, USENIX\, and ACM in\
 n   academia. He currently works as CTO at MOABI\, a binary analysis and\n
    vulnerability assessment firm\, after having been Principal Engineer of
 \n   Product Security at Salesforce (San Francisco)\, where he later lead\
 n   the RedTeam. He is wrapping up a PhD in reverse engineering at CNAM\n 
   (Paris) where he has been an Associate Professor for three years\, and\n
    holds master's degrees in Engineering\, Computer Science\, and\n   Cybe
 rsecurity.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T213000Z
DTSTART:20260809T203000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Witchcraft Solver: Automated 0day Discovery in Stripped Binaries
END:VEVENT
END:VCALENDAR
