Posts
2500
Following
650
Followers
1469
"I'm interested in all kinds of astronomy."
repeated

If you are using Signal, and you are doing something the government considers illegal, the way they are going to read your messages about it is they will arrest the person you sent the messages *to*, and make your counterparty show them the logs. We know this because this technique came up again and again in, for example, the Jan. 6 court filings.

There may, hypothetically, be other Signal exploits available to a government, but this is the one they will use, because it works.

21
12
0
repeated

***Dave Hill 🇺🇸🇺🇦🇨🇦🏳️‍🌈🏳️‍⚧️

Via my son:

5
16
0
repeated

I just published a blog post about getaddrinfo and all the other weird DNS APIs that we use in Firefox to resolve HTTPS records.

https://valentin.gosu.se/blog/2025/02/getaddrinfo-sucks-everything-else-is-much-worse

All this was part of the talk I gave at FOSDEM last weekend.

1
3
0
repeated

ROPing our way to “Yay, RCE” - and a lesson in the importance of a good nights sleep!

From vulnerability to exploit - follow our Colleague Michaels journey of developing an ARM ROP chain to exploit a buffer overflow in uc-http

Via Return-Oriented Programming chain small code snippets, or gadgets, already present in a program’s memory can be leveraged

By chaining these gadgets together, they can execute arbitrary code without injecting anything new

Dive into the process of reverse engineering, gadget hunting, and crafting a working exploit.

Learn all about it in Michaels full report.

https://modzero.com/en/blog/roping-our-way-to-rce/

2
6
0
@screaminggoat @ntkramer Sooo, deserialization, IIS... have they left their ViewState key exposed? /speculation
1
0
1
@munin Their mother was a hamster and their father smelt of elderberries!
0
0
1
@mttaggart @GossiTheDog Some recurring themes in these repos are 1) abandonware 2) test/training code

Also, TIL you can use boolean expressions, e.g. you can filter for autogenerated keys:

https://github.com/search?q=%3CmachineKey+validationkey+path%3Aweb.config+NOT+autogenerate&type=code
1
0
1
repeated

Why pay for search?

(Illustration by @chazhutton for Kagi)

1
3
0
@GossiTheDog Yeah, edits are weird around here, thanks for the clarification! I can only see npm being used for frontend stuff in .NET projects, could you perhaps link an affected repo/npm page?
0
0
1
@GossiTheDog Thanks! Now I'm more confused: npm does .NET these days? Or we're talking NuGet?
0
0
0
[RSS] Micropatches Released for Windows OLE Remote Code Execution (CVE-2025-21298)

https://blog.0patch.com/2025/02/micropatches-released-for-windows-ole.html
0
0
1
repeated

Daniel weekly February 7, 2025

https://lists.haxx.se/pipermail/daniel/2025-February/000099.html

old security, ssh security, BBC, URLs from file, you can help, curl up CVE-2024-7264, EOSAwards, Workshop, FOSDEM, 1337, release, regressions, release candidates, codeql, no goods

0
1
0
repeated

Enfys J. Book [they/them]

If you use Signal, Discord, or any other messaging app and you DON'T want Google or Apple monitoring/reading/learning from your messages, follow these steps.

Android:
1. Open Google app
2. Tap your profile photo
3. Settings
4. Google Assistant
5. "Your Apps"
6. Choose the app (e.g., Signal)
7. Toggle "Let your assistant learn from this app" off

iPhone:
1. Settings
2. Apps
3. Choose the app (e.g., Signal)
4. Toggle Apple intelligence or Siri settings to off (“learn from this app”)

20
50
0
@screaminggoat @zeljkazorz @GossiTheDog "However, due to inadequate server configurations, attacks become possible if *the serialized data is not verified* (CWE-642)" - this sounds more like disabled MAC than leaked key to me
1
0
0
repeated
repeated
repeated

UK orders Apple to put backdoor in iCloud encryption (Advanced Data Protection, which is end-to-end encrypted):
https://www.theverge.com/news/608145/apple-uk-icloud-encrypted-backups-spying-snoopers-charter

The way this plays out is that UK iPhones lose the Advanced Data Protection feature, right?
Right??

0
2
0
@GossiTheDog Forgive my ignorance, what is nom?
0
0
0
Show older