Posts
2528
Following
649
Followers
1466
"I'm interested in all kinds of astronomy."
Pretty sure that x509 parser and the dozen other features in the kernel are flawless...
0
0
5
Can't look into this rn, but based on comments on the other site this Chinese post claims the #CrowdStrike bug is exploitable for LPE:
https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ
1
0
2
repeated

I have just added support in for 9.0 (currently in beta). I wrote the changes this weekend, but I had to test multiple things... anyway, enjoy it.

https://github.com/joxeankoret/diaphora/commit/232a2720d56d17acce809b6bf82a6a561c980d82

0
1
0
repeated

New fashion goals 💾

2
5
0
[RSS] Unquoted service paths: The new frontier in script kiddie security vulnerability reports

https://devblogs.microsoft.com/oldnewthing/20240723-00/?p=110032
0
0
1
[RSS] There is no mystery over who wrote the Blue Screen of Death, despite what some may want you to believe

https://devblogs.microsoft.com/oldnewthing/20240730-00/?p=110062
0
0
0
[RSS] What are the dire consequences of registering a RunOnce command from my RunOnce command?

https://devblogs.microsoft.com/oldnewthing/20240805-00/?p=110098
0
0
0
repeated
x86 ISO warning sticker
4
25
2
repeated

Last week, Public Citizen’s Rick Claypool and I filed a complaint with the Federal Election Commission based on my research into apparent campaign finance violations by the Coinbase cryptocurrency exchange.

Read the full complaint and my updated article.

Complaint: https://www.citizen.org/article/coinbase-fec-complaint/

Updated article: https://www.citationneeded.news/coinbase-campaign-finance-violation/

4
7
0
repeated

Resorts World Las Vegas announced they're performing periodic room checks for the duration of the blackhat / defcon hacking conference. When asked what they are looking for, one of the employees responded with "people hacking our stuff" ☠️

Reminds me of that old blog post by some dude who got pulled aside by the TSA so they could search his bag for "bitcoins".

https://www.404media.co/hotel-to-search-rooms-during-def-con-hacking-conference/

5
3
0
repeated

The original Pentium chip was introduced in 1993. It was the first "superscalar" x86 chip, able to run two instructions per clock cycle. I took this die photo of the chip yesterday. The chip has three metal layers; the thick lines you see are the top metal layer, mostly power and ground. The silicon itself is almost entirely obscured. Around the edges of the chip, tiny bond wires connect to the bond pads, providing the connections to the chip's external pins. 1/N

2
3
0
@Viss This includes availability, right? They will take a look at how many ppl can't use Teams at any given time, right??
1
0
2
repeated

Currently trending on the bad place (Twitter): Leaked Wallpaper
Proof of concept for CVE-2024-38100 (7.8 high, disclosed 09 July 2024 by Microsoft Windows File Explorer Elevation of Privilege Vulnerability.

This is a privilege escalation tool (fixed with CVE-2024-38100 in KB5040434) that allows us to leak a user's NetNTLM hash from any session on the computer, even if we are working from a low-privileged user.

0
1
0
[RSS] Government Emails at Risk: Critical Cross-Site Scripting Vulnerability in Roundcube Webmail

https://www.sonarsource.com/blog/government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail
0
0
0
repeated

New from 404 Media: we got a massive leak from inside Nvidia (emails, Slack chats, documents) which show how it created a yet-to-be-released AI model. The leak shows that Nvidia scraped YouTube en masse, had clearance from highest levels of the company https://www.404media.co/nvidia-ai-scraping-foundational-model-cosmos-project/

1
3
0
repeated
@csepp @uint8_t Yes, it was phishing according to the news, so from the professional side this is meh...
0
0
0
repeated

The flow is pretty straightforward:
First, the MotW is written when the from-the-internet ZIP is extracted, as any well-behaved (e.g. NOT 7-zip) archiving utility will do.

Then, as Windows parses the LNK file, it rewrites it to fix the path. In the process of doing this, the MotW is removed.

Finally, Windows checks to see if it needs to use SAC or SmartScreen. Because there is no MotW, the file is deemed "safe" and no SAC or SmartScreen comes into play. 🎉

2
2
0
Show older