Posts
3822
Following
724
Followers
1597
"I'm interested in all kinds of astronomy."
repeated

We chose a vulnerability in glibc (CVE-2025-4802) to teach students registered in our binary exploitation training the importance of the libc, loader, dynamic linker, and the kernel in making the execution of a modern Linux binary possible.

Furthermore, it demonstrates how a small oversight in the static glibc code allowed arbitrary libraries to be loaded into privileged code. Do you know the crucial role of the auxiliary vector? Or the main differences between dynamically and statically compiled binaries?

Check out the blog post for a brief analysis of CVE-2025-4802.

https://allelesecurity.com/libc-vuln-analysis/

0
6
0
repeated

When times were simpler:

"text generator"

1
2
0
repeated

joernchen :cute_dumpster_fire:

Edited 14 hours ago

LLMs now do the busywork of finding amazing vulnerabilities for everyone willing to spend the tokens.

But hacking still isn't dead:

  1. We haven't at all solved the underlying problems which come with writing and shipping code.

  2. You still need to understand what you're looking at and what you are operating.

  3. The LLM platforms themselves are a exquisite target for hacking^Wcreative use of the technology.

Now when everyone can pull a CVE or two out of thin silicon and a few kWh of electricity the art of hacking might need adopt and maybe reshape a little but at its core the mind- and skillset will stay as relevant as it always was.

In that sense: keep hacking, keep exploring, break some stuff.

2
6
0
repeated
repeated
Edited 11 hours ago

Blessed are the cheese makers

https://www.youtube.com/watch?v=NFPIGNua5WM

0
4
0
repeated

2 years ago I did a PoC to run 🦀 in the modem

Today it shipped in millions of devices!

They grow up to fast! 🥲

https://security.googleblog.com/2026/04/bringing-rust-to-pixel-baseband.html

0
5
1
[RSS] CVE-2025-8061: From User-land to Ring 0

https://sibouzitoun.tech/labs/cve-2025-8061/
0
0
2
repeated

If all you do in your tech career is:

1. When something is slow, you look carefully at the output of a profiler or a query plan & make measured suggestions about what to improve;

2. When something breaks badly, you gently but insistently ask what & why until you truly know, then the next time similar work is needed you bring up how to avoid doing what broke last time; and

3. When someone lacks info, you make them feel good for learning instead of bad for not knowing;

You will do good work.

3
9
0
@pancake force colored output (if the command supports it) and pipe to xclip?
0
0
0
repeated

😎 Zsolt Hegedűs, a likely candidate for Hungary’s health minister, really got the party going at the “Tisza” victory celebration 🇭🇺

0
4
0
"The compromise is resident, partly because the attack surface is older than most of the people hired to defend it."

https://cje.io/2026/04/08/offense-scales-with-compute-defense-scales-with-committees/
0
2
2
repeated
repeated

Code reviewing.

1
3
0
repeated

Thorsten Leemhuis (acct. 1/4)

7.0 is out:

https://lore.kernel.org/lkml/CAHk-=wj2WqpPBwpAXo8bj_Hx-NxKMRVTVMUaQis7+Vm6XLRZiw@mail.gmail.com/

For a list of new features, see:
* the LWN brief news entry – https://lwn.net/Articles/1067279/ (Screenshotted below)

* the LWN merge-window summaries – https://lwn.net/Articles/1057769/ and https://lwn.net/Articles/1058664/

* the KernelNewbies 7.0 page – https://kernelnewbies.org/Linux_7.0

And reminder: the jump from 6.19 to 7.0 does not mean anything apart from "Linus ran out of fingers and toes to count on."

0
3
0
repeated

New post: Windows Early Boot Configuration: The CmControlVector and PspSystemMitigationOptions https://insinuator.net/2026/04/windows-early-boot-configuration-the-cmcontrolvector-and-pspsystemmitigationoptions/

0
2
0
repeated

Are you a student, just graduated or without a job? You can take Corelan Stack at an insane discount. Corelan Summercamp: https://www.corelan-training.com/index.php/summercamp pls share

0
4
0
#hupol
Show content
The day the Tisza Party swept away Viktor Orbán’s 16-year regime

https://telex.hu/english/2026/04/13/igy-nezett-ki-a-nap-amikor-a-tisza-part-elsoporte-orban-viktor-16-eve-fennallo-rendszeret-english

Such a fucking relief...
1
1
7
re: hupol, in English
Show content
@algernon Please consider that a large portion of current Tisza voters are in fact lefties or other ppl disagreeing with lots of common nationalist bs: my enemies enemy is my friend. So a more realistic picture is a rainbow coalition (very unstable) standing behind one right-wing candidate to beat the fascist. @petko
1
0
3
repeated

@fulelo more "ruszkik haza" ("russians go home") in the Budapest metro

0
2
0
@fulelo important emphasis, thank you!
0
0
1
Show older