Posts
2499
Following
650
Followers
1469
"I'm interested in all kinds of astronomy."
#music #techno #hardstyle
Show content
This guy is just unbelievable :O

https://www.youtube.com/watch?v=8CT6HxYA0cg
0
0
2
repeated

I get really annoyed when a link unexpectedly takes me to X, but since I ended up there today, this is too good not to share.

AI literally Rickrolled a company's customer when they asked for a link to a training video! It replied to a request by sending a link to Rick Astley's video on YouTube.

2
5
0
repeated

Aris Adamantiadis verifiedđź’˛Paid

day gets better

0
2
0
repeated

We're 7 years after the publication of NIST 800-63 on best practice guidance for modern passwords and I still talk to large companies stuck in the past trying to enforce silly password rules and mandatory 90 day rotations. Pretty sure I'm still going to be having these discussions at the 10 year anniversary.

7
6
0
Edited 11 months ago
As I mentioned a number of times, I take good care of the discoverability of my content, which includes #SEO. At the same time, my personal homepage is comfortably low traffic and updates rarely, allowing me to easily spot how Google cheats.

This image shows the ratio of indexed/unindexed pages - as you can see Google just decided not to index thousands of pages.

At the same time, my clicks look great, in part because Google counts clicks to other pages that host the same/similar content (this also results in falsely reported in-links) to my site. I wouldn't be surprised if these clicks were doubly counted to pump numbers...
0
0
1
repeated
Edited 11 months ago

Google's removal of the estimated number of search results is particularly user-hostile.

And it's me. I'm "user".

There's a specific kind of searching where you know that there shouldn't be a ton of results, and you are adding exclusions until your search matches the expected result space.

And now that's impossible (without scrolling to the bottom to see how many pages of results there are).

0
1
0
repeated

Some thoughts on memory safety

https://pacibsp.github.io/2024/some-thoughts-on-memory-safety.html

This post briefly describes some theoretical aspects of memory safety that feel important to me but that aren't always obvious from how I see memory safety being discussed:

1. Memory unsafety is a specific instance of a more general pattern of handle/object unsafety

2. Memory unsafety is relative to a particular layer in a stack of abstract machines

3. Memory unsafety matters because it violates local reasoning about state

4. Safe languages use invariants to provide memory safety, but these invariants do not define memory safety

Also, not sure what was up with the embed in my last post, hopefully this one works.

0
1
0
repeated
Edited 11 months ago

Another SolarWinds RCE vulnerability…

… I instantly had the image from Hunt for Red October when the Soviet ambassador tells the US SecState that they needed help and SecState says "Don't tell me you lost _another_ submarine!"

flan_molotov

1
1
0
repeated

I have some words for the developers who decided that it was completely reasonable to expect a user to be able to precisely hit a single pixel to be able to resize a window.

I've seen this on both Windows and Linux. 🤦‍♂️

7
8
0
repeated
repeated

Versa security advisory: Versa Security Bulletin: Update on CVE-2024-39717 – Versa Director Dangerous File Type Upload Vulnerability
See parent toot above for CISA adding CVE-2024-39717 to the KEV Catalog. Here is some notable information:

  • CVE-2024-39717 affects all Versa SD-WAN customers using Versa Director, that have not implemented the system hardening and firewall guidelines.
  • The impacted users were Managed Service Providers
  • "This vulnerability has been exploited in at least one known instance by an Advanced Persistent Threat actor."
  • The threat actors had Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges, in order to upload malicious files.
  • Impacted customers failed to implement system hardening and firewall guidelines, with an internet-exposed management port.

Versa released a patch to address CVE-2024-39717, and provided Firewall Guidelines and System Hardening guidance.

Note: A CISA joint cybersecurity advisory from 2022 states that “threat actors can use a vulnerable MSP as an initial access vector to multiple victim networks, with globally cascading effects.” This security advisory was published today while all of the other URLs in NVD/Mitre are behind a loginwall.

cc: @ntkramer

1
1
0
repeated
@rostiger Didn't know about this project, it looks great! Thanks for sharing!
0
1
3
repeated

Most mirrors of libgen are now down. Anna's Archive is fighting to keep the lights on.
https://annas-archive.org/

1
6
0
[RSS] Advanced UEFI Analysis with Binary Ninja

https://binary.ninja/2024/08/23/uefi-firmware-analysis.html
0
4
6
repeated

Last year on this day the bogus CVE arrived that triggered a series of events that subsequently made become a CNA.

https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/

0
6
0
repeated

Brief intro on how to use eBPF for syscalls tracing

http://sh4dy.com/2024/08/03/beetracer/

0
1
0
repeated

Andy Jassy talks about the benefits Amazon is seeing from their AI coding assistant. It’s widespread that devs are more productive with these tools.

The question is whether this is like accountants and Excel where it creates jobs or travel agents & the web where it kills them.

0
2
0
repeated

PageJack: A Powerful Exploit Technique With Page-Level UAF

A talk by @pkqzy888 et al. about overwriting slab objects containing a `struct page *` field to achieve arbitrary read/write in physical memory.

Slides: https://i.blackhat.com/BH-US-24/Presentations/US24-Qian-PageJack-A-Powerful-Exploit-Technique-With-Page-Level-UAF-Thursday.pdf

0
2
0
Show older