Posts
2529
Following
648
Followers
1464
"I'm interested in all kinds of astronomy."
Since I literally have to watch the paint dry, here's a bot for Project Zero issues too:

@p0bot
1
1
2
repeated

That’s no moon – it’s the Moon 🌗

The first colour images from ESA JUICE’s close lunar encounter last night are out.

Taken by the monitoring cameras, both show sunlit craters & shadows on the surface with parts of the spacecraft in the foreground.

At the top of the second image, you can just make out Earth as a small dark circle, surrounded by the ring of its backlit atmosphere.

We arrive (t)here tonight 🛰️🌏

Kudos to @stim3on for the magical processing 🙇‍♂️

1
5
0
#LazyFedi What is the easiest way to generate a (machine-readable) function call graph from an NPM package?

Alternatively, what is the easiest way to generate a function call graph for packages of any package manager?

#Programming #StaticAnalysis
0
1
1
The Insane Engineering of the Gameboy

https://www.youtube.com/watch?v=BKm45Az02YE
0
0
1
repeated

UPDATE: Palo Alto Cortex XSOAR CommonScripts Critical Vulnerability (CERT-EU Security Advisory 2024-083)

On August 14, 2024, Palo Alto Networks released a security advisory for a critical command injection vulnerability, CVE-2024-5914, in Cortex XSOAR. This flaw allows unauthenticated attackers to execute arbitrary commands within the context of an integration container, potentially compromising the system. The vulnerability affects the product's CommonScripts Pack and is rated as high severity with a CVSS score of 9.0.

https://www.cert.europa.eu/publications/security-advisories/2024-083/

0
1
0
Linux: landlock can be disabled thanks to missing cred_transfer hook; and Smack looks dodgy too

https://bugs.chromium.org/p/project-zero/issues/detail?id=2566

This is CVE-2024-42318
1
1
2
repeated

There's an article written by me in Phrack Magazine: http://www.phrack.org/issues/71/11.html#article.
Very proud to be in that historic hacking magazine! For me, this is a major achievement :)

Bonus: the source code and binaries are here https://github.com/cryptax/talks/tree/master/Phrack-71

Enjoy! And if you really like it, I'd appreciate you nominate it here https://www.virusbulletin.com/conference/peter-szor-award/

Anybody with a paper edition to send me? This offer still stands: https://mastodon.social/@cryptax/112775284733028530

1
2
1
@pancake Isn't this achievable by a blog-like ActivityPub service (or an actual ActivityPub-enabled blog engine, like WriteFreely)?
2
0
0
@pancake You mean you'd like to e.g. show RSS content under your own account?

This definitely sounds like a feature request, still I think a 3rd-party service with scoped credentials (at least Akkoma supports this, my bots have post-only creds for example) can still hit a sweet spot.
0
0
0
repeated
@kpwn I have no first-hand experience, but this must be pretty nice (Steven Seeley does it) for advanced topics: https://srcincite.io/training/
1
0
1
@pancake Fediverse SW (plz don't just promote Mastodon) have nice open API's so we can go nuts with our ideas without going through standardization rituals.

A quick search got me this little tool: https://codeberg.org/MarvinsMastodonTools/feed2fedi , and IIRC there was some service that did the same without coding/hosting yourself.

On the other hand I use Fedi as an RSS _generator_, so I kind of agree that having some features built-in makes a difference - question is how we determine if the API is not enough?
4
0
1
Along with the release of the latest Phrack, today in #Hungary we celebrate the founding of our nation by Saint Istvan
0
1
3
repeated

joernchen :cute_dumpster_fire:

0
8
0
repeated
Edited 10 months ago

it you would like to read ~10k words about going from "a 12kb binary that fell off a truck" to "a disassembler that knows the whole instruction set except like five opcodes", all without running a single instruction, phrack 71 is up and has a treat from me to you: http://phrack.org/issues/71/3.html#article

0
14
0
@Viss To be fair, cloud is not responsible for the utter stupidity of its users...
0
0
0
repeated

go to the cloud they said
it'll be fine they said

4
1
0
repeated

@johnefrancis
I was able to open up a Titan missile guidance computer and examine it hands-on. Unfortunately, nobody would give me a Minuteman guidance system to teardown. But I found that the National Air and Space Museum has extremely detailed photos that I could use for analysis.
https://www.righto.com/2020/03/inside-titan-missile-guidance-computer.html

0
1
0
repeated

I wrote a blog post that goes into much more detail on the Minuteman guidance system and computer, so check it out: https://www.righto.com/2024/08/minuteman-guidance-computer.html
22/23

1
4
0
Show older