Posts
2614
Following
623
Followers
1385
"I'm interested in all kinds of astronomy."
repeated

Gynvael Coldwind (@gynvael.bsky.social)

(please RT for reach - thank you!)
Learned a cool new Linux trick? Know an interesting quirk in a network protocol? Or have something else to share?

Write a 1-page article for the issue of Paged Out! :)
https://pagedout.institute/?page=cfp.php

Soft deadline is Feb 1st.

0
4
0
repeated

Donating to the Wikimedia Foundation is great. Becoming a volunteer editor is even better.

https://youtu.be/bRRHR1NEOqE

2
8
0
repeated

From over at the Bad Place:
https://gist.github.com/alfarom256/f1342f14dc6a742de7ea4004a1b6d7ed

IObit Malware Fighter has a driver device called IMFForceDelete123.
When you call the only exposed IOCTL to this device, 0x8016E000, along with a specified path, the Windows kernel will delete the specified file/directory. NTFS ACLs don't matter because we're the kernel.

Who is allowed to interact with this device? EVERYONE.

The more software you have on your system, the less secure it is.

2
7
1
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

Progress WhatsUp Gold SnmpExtendedActiveMonitor path traversal vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2089

CVE-2024-12105
0
1
0
@slp This keyboard is tripping balls
0
0
0
repeated

The art of programming is the art of organizing complexity, of mastering multitude and avoiding its bastard chaos as effectively as possible.

— E. W. Dijkstra

0
3
0
repeated

Backdooring Your Backdoors - Another $20 Domain, More Governments - watchTowr Labs https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/

0
3
0
repeated
repeated

This is it! Its on!

Save the date and polish your speaking or training skills-> call for papers, workshops, trainings, sponsors and volunteers open!

Submit: https://pretalx.com/bsidesluxembourg-2025/cfp

PS: sponsor package options available on info@bsides.lu!

2
6
0
@atomicpoet @dansup Worse: it created friction for legit use-cases (that can't be undone!), creates ~0 friction for illegitimate ones *while* giving a false sense of security.

Limiting discovery is def in the top3 stupidest ideas I've seen during my long time on the Web.
0
0
1
repeated

Please support one of our own! If you ever have been to defcon, needed network security, used MFA, touched HAM radio, etc… dearest cjunkie made your life better one way or another - one of the most awesome human beings I know (and I know tons of them!) https://www.gofundme.com/f/support-marc-rogers-road-to-recovery

0
2
0
@Ange you know when some smart bureaucrat draws black rectangles over paragraphs then someone on the Internet does a Ctrl+A Ctrl+C Ctrl+V and publishes the whole text layer
0
0
3
@Ange considering impact: select to unredact :)
1
0
4
repeated
Confirmed. ChatGPT is actively indexing the Fediverse, even small servers like mine who have not explicitly consented to their indexing.

So while people on Mastodon got angry about Mastodon having built-in discovery features, ChatGPT just went ahead and slurped up all your posts.
18
22
0
repeated
repeated

Google Chrome security advisory: Stable Channel Update for Desktop
New Google Chrome version 131.0.6778.264/.265 for Windows, Mac and 131.0.6778.264 for Linux includes 4 security fixes, including 1 externally reported: CVE-2025-0291 (high severity) Type Confusion in V8. No mention of exploitation

0
2
0
repeated
repeated
repeated

In the latest Doyensec research, our Nobert Szetei (@sine) takes a closer look at the SMB3 Kernel Server (ksmbd) component of the Linux kernel. Check it out today to learn what he found, which led to multiple CVEs!

https://blog.doyensec.com/2025/01/07/ksmbd-1.html

0
6
0
Show older