Posts
2721
Following
681
Followers
1506
"I'm interested in all kinds of astronomy."
repeated

Let's cut the bullshit and spell out a few things. The IT security industry is about as trustworthy as the food supplement and vitamin industry, but somehow they escaped the same reputation. Their products are overwhelmingly based on flawed ideas, and the quality of their software is exceptionally bad. And while not everyone will agree with the harshness of my words, I'll say this: Essentially everyone in IT security who knows anything in principle knows this.

3
8
2
repeated
Edited 1 year ago

#2961 - CrowdStrike

0
2
0
repeated

hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️‍🌈

The sheer volume of CrowdStrike-esque domains being registered and weaponized today is…staggering.

1
4
0
repeated

@LukaszOlejnik This paper seems to be fundamentally flawed — their simulator failed to properly use an RNG, so it simulated giving people the same topics on every site. See https://github.com/yohhaan/topics_api_analysis/issues/1

This points out how great it is for published papers to post their code and data set on GitHub! It means that we can actually point to the bug in their simulator, offer the one-line fix, and immediately re-run the corrected analysis using the author's own fixed code.

0
2
0
repeated
repeated

Graham Sutherland / Polynomial

Edited 1 year ago

@thephd there's a main kernel driver and a bunch of .sys files that contain update data. the main kernel driver parses those .sys data files. one of those data files has incorrect data in it, which causes the parser (written in C) in the main driver to crash. from what I've seen of the analysis (early days) it looks like bad pointer maths from invalid data, leading to either UAF or OOB memory access.

0
1
0
repeated
repeated

just ran into an incredible bug: portal 2 crashes if you happen to have a CPU with 128 threads

https://github.com/ValveSoftware/portal2/issues/367

0
8
1
repeated

Dear buttplug.io users:

We apologize for the current downtime.

If your butt is BSOD’ing, please try rebooting it a few times.

5
3
0
repeated

Just reiterating, because this is getting lost in a lot of the coverage: the original Azure outage and the Crowdstrike Windows bug are NOT related. That said, a significant number of corps run Windows servers on Azure with Crowdstrike Falcon. Wired coverage has more.
https://www.wired.com/story/crowdstrike-outage-update-windows/

0
1
0
repeated

So I just happened to read a blog discussing some PoC crashes in Office (https://code610.blogspot.com/2017/10/microsoft-outlook-2016-rwra-crash.html) & what I do? I sent them to @expmon_ immediately (https://pub.expmon.com/analysis/110243/).

ht: I've found real exploitable bugs w/ the power of EXPMON, it's not just a 0day detection system.:)

0
1
1
repeated

Graham Sutherland / Polynomial

pour one out for the homies who can't head to the pub tonight because they're stuck unfucking hundreds of computers

2
2
0
repeated

you can outsource the work, but you cant outsource the risk

1
3
0
repeated

❄️☃️Merry Jerry🎄🌲

Edited 1 year ago

Here is a GPO that can apparently run in safe mode to automate the removal of the problematic crowdstrike driver: https://gist.github.com/whichbuffer/7830c73711589dcf9e7a5217797ca617

EDIT: despite my indication that this for running in safe mode, many people seemed to have missed that I said it is for safe mode. So, here is the clarification: IT IS FOR SAFE MODE

H/T @p4gs

0
2
0
repeated

@cynicalsecurity Except if made by a certain RU company, where perfect uptime is required to maximize exfil and stealthiness, and minimize chance of detection if it breaks :X

1
1
1
repeated

When I said "one day my stance on EDR / AV / IPS will be vindicated" I didn't mean for half the Internet to melt down but I am soooooo enjoying this moment.

Thank you for giving me my day of glory. Now I will have a story to tell my grandchildren.

2
4
0
repeated
repeated
repeated

Rairii (bootloader unlocked, MSR_LE set)

so I happen to have a 0day downgrade attack bitlocker bypass, which would be very helpful for people dealing with the crowdstrike issue and have more than about a dozen systems with tpm+secure boot bitlocker lol

the downgrade attack part is why i never publicly documented the original issue yet

also I bet MS are very annoyed that everyone’s saying its their fault

1
2
0
repeated

Explaining to reporters that this is not a Microsoft issue but a Crowdstrike issue - interesting how different the "non tech" world looks at this

2
1
1
Show older