Posts
3139
Following
708
Followers
1555
"I'm interested in all kinds of astronomy."
SEC Consult SA-20241009-0 :: Local Privilege Escalation via MSI installer in Palo Alto Networks GlobalProtect (CVE-2024-9473)

https://seclists.org/fulldisclosure/2024/Oct/2
0
2
2
repeated

Palo Alto in 2018:
CVE-2018-10143 - Oops. We'd better fix the "path" parameter for convertCSVtoParquet.php

Palo Alto in 2024:
CVE-2024-9463 - Oops. We'd better fix the "ram" parameter for convertCSVtoParquet.php

1
6
0
repeated

Can someone get this thing to work? Is there any other option to spot gaps in padded fields on structs in C programs? https://github.com/arvidn/struct_layout

2
1
0
repeated

Mozilla is looking for a Staff Software Engineer (remote US/EU/CA ✨) working on sandboxing, hardening, crash-reporting, performance and integration with native widgets **on Linux**. As a staff-level position this will require strong technical and people skills, experience in C++ on Linux or Android. The team is distributed and amazing. Ask me in DM if you have any questions about Mozilla (I am *not* the hiring manager). Please apply at https://grnh.se/2c3dc0111us

2
8
0
repeated

a fedi instance just for people's pets

2
3
0
repeated

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. Update your Firefox ASAP https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/

1
4
0
"You're one of 31,081,179 people pwned in the Internet Archive data breach"

Somehow I didn't feel the same sense of pride with LinkedIn :)
0
1
5
@joxean @tmr232 In this case this tool may be very useful for robust handling of Java types:

https://mypy-lang.org/
2
0
1
@joxean Do you plan to develop using a public repository? I'd love to contribute this (except Q4 is happening :P)
1
0
0
repeated

The Reverse Engineering community has spoken. will be ported to in the next months. I would love to have it working properly by the end of the year, but I cannot be sure. So, no ETA for now.

2
4
1
@tmr232 @joxean Nah with the dark bg it takes ages for my eyes to start bleeding.
1
0
1
repeated

Wow, Specter bypassed XOM and broke the PS5 hypervisor. Awesome work.

"Byepervisor: How We Broke the PS5 Hypervisor".



https://hardwear.io/netherlands-2024/speakers/specter.php

0
5
1
repeated

@thedarktangent SunOS was pseudo closed source, in that of an established customer could purchase a copy. Acquiring a copy was nice, one could trade for let's say a zero day or something. CALEA was one of the "benefits" of this type of trading.

0
2
0
repeated

I remember hackers breaking in to CALEA lawful intercept boxes to spy on each other over 20+ years ago..

IIRC They were default SunOS servers connected direct to internet, no patches or updates applied over the years. Once you mapped them you could wait for a known vulnerability and visit them again.

It’s always been terrible, and always been known. I want it to be taken seriously.

Edit: It may be closer to 30 years than 20, but “a long time ago”

3
11
0
Internet Archive hacked, data breach impacts 31 million users

https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/

As an IA user and donor I'm kind of glad this happened: passwords are properly hashed (bcrypt), there is a chance to improve security.

But anyone who decided they should hack IA of all things can (as we say around here) go and shit out a hedgehog.
0
2
3
repeated

Republicans,
Democrats,
Third party voters

People driven by totally incompatible political and religious ideologies,

Pineapple on pizza people,

People who hate pineapple on pizza and are incorrect,

🤜🏻🤛🏾 hating whomever hacked the Internet Archive

2
7
0
re: uspol
Show content
@0x4d6165 you must have missed the "against humanity" part in the name
1
0
1
#music #metal
Show content
I've been trying to get to a CoF show again for at least 5 years. Last time the event was completely sold out, and I know why: unlike many new (dark) stars of the scene, this band just delivers.

https://www.youtube.com/watch?v=GKTKke-nYQk

Also, finally they found a proper live background vocalist!
0
0
0
Show older