Posts
2475
Following
663
Followers
1487
"I'm interested in all kinds of astronomy."
repeated

Intel launched the Pentium processor in 1993. Unfortunately, dividing sometimes gave a slightly wrong answer, the famous FDIV bug. Replacing the faulty chips cost Intel $475 million. I reverse-engineered the circuitry and can explain the bug. 1/9

5
23
1
Writing down (and searching through) every UUID Β· eieio.games
https://eieio.games/blog/writing-down-every-uuid/

/via @filippo

#frombsky
0
4
2
@h2onolan I'm pretty sure it's ownership. See also how Kaspy got banned while CrowdStrike not.
0
0
2
repeated

Breaking the most popular Application Firewalls () in the market

https://nzt-48.org/breaking-the-most-popular-wafs

0
2
0
[RSS] Trying to Exploit My Old Android Device, take 2 (CVE-2020-0401, PackageManagerService)

https://pwner.gg/blog/Android%27s-CVE-2020-0401
0
1
2
"Good Red Team comes on slow. The first month is all waiting, then halfway through the second month you start cursing the service provider who burned you, because nothing is happening. And then... ZANG!" - Hunter CISO Thompson
0
2
7
repeated

I'll just leave this here for the real programmers.

3
4
0
repeated

Forward thinking was just the thing that made Multics what it is today.

β€” Erik Quanstrom

0
3
0
repeated

Santa brought new a blog post!

Handling Arbitrarily Nested Structures with

https://blog.silentsignal.eu/2024/12/06/custom-decoder-for-burp/

0
2
0
repeated

The competition compromises your C2 infrastructure and operator workstations.

"a longstanding campaign orchestrated by the Russian-based threat actor known as 'Secret Blizzard' (also referred to as Turla). This group has successfully infiltrated 33 separate command-and-control (C2) nodes used by Pakistani-based actor, 'Storm-0156.'"

https://blog.lumen.com/snowblind-the-invisible-hand-of-secret-blizzard/

0
2
0
repeated

@bagder @swapgs I highly recommend clicking through the demo at https://www.hackerone.com/hai-your-hackerone-ai-copilot

It's really really bad, even for the low bar of AI slop. It recommends using `X-XSS-Protection` (which is not a thing anymore), claims that calling `dangerouslySetInnerHTML` breaks the principle of least privilege, and then in a report about an SQL dump being publicly available it explains said dump by describing how a CREATE TABLE works without even catching on the fact that it's an export of the database in SQL format.

If the demo they present this with is so hilariously bad, I can only imagine what the real product is like.

2
5
1
[RSS] URL File NTLM Hash Disclosure Vulnerability (0day) - and Free Micropatches for it

https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html
0
0
0
repeated

Pentagrid published two tags for (also Swiss AHV numbers) and for . These tags are available via the Hackvertor Tag Store by @garethheyes. Our blog post explains what these tags do and how they can be used. https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/

1
4
0
repeated

CyberKaida (ァむバーかいだ)

support for writing plugins! And it includes debugging from VSCode!

I am SO EXCITED! Thank you Ghidra team! πŸ’œπŸ’œπŸ’œ

https://github.com/NationalSecurityAgency/ghidra/commit/478d3e6331803ee3c4adda98a9a97e0acab7e242

1
6
1
repeated
repeated

Cyberpunk when?
(Now. Right now)

6
9
0
repeated

Mastodon isn't perfect.

But the fact a social network exists that is completely free to use,

has no venture capital investors,

has no shareholders to answer to,

has no growth targets,

with a web interface with zero cookies,

and mobile apps with zero trackers at all

with ten thousand server administrators who donate their time for user safety

is - in my opinion - mindbogglingly cool, given the state of the world we live in.

Not everything has to be shit. People make things better.

24
86
2
repeated
Edited 9 months ago

So, apparently targeted advertsing may be coming to ...

https://techcrunch.com/2024/12/05/bluesky-ceo-jay-graber-is-reshaping-social-media-but-advertising-isnt-off-the-table/?guccounter=1

This is not a surprise at all, and has been predicted for a while. Despite the protestations from Bluesky enthusiasts saying that selling domain names was going to do it, the BS business plan never made any sense.

And now they are paying for server costs for 20+ million users and watching their $15M investment from Blockchain Capital et al. dwindle.

Reality bites, and it bites hard.

5
13
0
Show older