Posts
2545
Following
644
Followers
1450
"I'm interested in all kinds of astronomy."
👷 After 15 years of entrepreneurship and a few months of sabbatical I'm looking for a regular old job.

My ideal role would be primarily technical, aimed to dissect software to uncover vulnerabilities. Beyond bug mining I'd love to learn to mine better and make new kinds of pickaxes.

My public works and contact info are on my homepage:

https://scrapco.de

Get in touch if you want to know more!

Boosts are appreciated! #FediHire
3
34
6
Slides like this will always have a special place in my heart! Source:

https://www.youtube.com/watch?v=goEb7eKj660
0
2
10
I created a library from prefetch-tool so you can more easily experiment with side-channel #KASLR bypasses on Windows:

https://github.com/v-p-b/prefetch-lib

For dogfooding I exploited HEVD on Windows 11 24H2:

https://github.com/v-p-b/HEVD-prefetch
0
6
11
[oss-security] CVE-2025-4748: Erlang/OTP 17.0–28.0.0 absolute-path traversal in zip:unzip/zip:extract

https://www.openwall.com/lists/oss-security/2025/06/16/5

Exquisite bug!
3
13
22
Edited 13 days ago
I tried to improve on @carrot_c4k3 's work to bypass Windows KASLR with a prefetch side-channel. I summarized my results in a new blog post, spiced up with some geek art:

https://scrapco.de/blog/visualizing-prefetch-infoleaks-to-defeat-kaslr.html
0
6
10
Edited 14 days ago
Make some noise!
1
0
1
This was the original version. While Adeptus Mechanicus clearly represents my general understanding of things, the Sister of Sororitas praying on a hill of skulls better captures my current mental state. #wh40k #IT #Windows
0
0
0
I have no idea why this works now and why it didn't work before...

Praise be the Omnissiah!
1
0
0
Had to make a proper GIF of this
0
0
0
@david_chisnall @kenshirriff Just for the record, I find this part of AS/400 history pretty fascinating (from Inside AS/400, by Frank Soltis) :)
0
0
5
Would you?
0
1
2
@mttaggart or maybe giving RNGs full access to your repos is not a great idea?
1
0
1
#uspol #insidejob
Show content
Seriously?
1
0
2
@kimzetter Thank you! So DOGE still doesn't have the authority but lower-ranking staff basically obey their requests that don't align with cabinet secretaries or agency heads? Why don't they just go full-on Cheryll on these requests?
0
0
0
Show older