Posts
3004
Following
698
Followers
1546
"I'm interested in all kinds of astronomy."
@schrotthaufen @Viss I've heard a couple of tracks featuring these at various EDM events (annoying af tbh).
1
0
0
repeated

Normally you can't auth to Entra ID connected webapps with bearer tokens. But if Teams can open SharePoint/OneDrive with an access token, I guess so can we. roadtx now supports opening SharePoint with access tokens in the embedded browser 😀

0
5
0
repeated

So, coup by the evil venture capitalists. I kindly suggest the good venture capitalists should proceed to stand up and actively fight this, before everything goes full Palpatine.

2
3
0
repeated

Thrilled to share that Kagi has reached 40,000 members! 🚀

Thank you to each and every one of you for believing in a better, more private, and ad-free search experience. Your support fuels our mission every day. Here's to the next milestone! 🙌

1
2
1
repeated
@Viss ...and cause that weird noise in the nearby HiFi systems?
1
0
3
repeated

Inside imessage-exporter: Reverse Engineering Apple's typedstream Format by @rxcs

https://chrissardegna.com/blog/reverse-engineering-apples-typedstream-format/

0
2
0
repeated
repeated

I should just share all of Trails of Bits new posts, right? It's the best cryptography blog I know of.

This time they're discussing key derivatives (as in, how to get a private key? How to generate more keys out of it?).

https://blog.trailofbits.com/2025/01/28/best-practices-for-key-derivation/

1
3
0
repeated

If you haven’t noticed malicious emails abusing Microsoft Library Description files (.library-ms), watch out and block them.

From Microsoft “Library description files are XML files that define libraries. Libraries aggregate items from local and remote storage locations into a single view in Windows Explorer.”

Threat actors, in an effort to evade detection, use them as a way of connecting their target to a remote share directly via File Explorer.

https://learn.microsoft.com/en-us/windows/win32/shell/library-schema-entry

0
4
0
[RSS] Microsoft Edge Developer VM Remote Code Execution

https://infosec.rm-it.de/2025/02/17/microsoft-edge-developer-vm-remote-code-execution/

This is fun: take DNS name, pwn researchers :)
0
0
3
repeated

We are thrilled to announce the winners of the 2024 Hex-Rays Plugin Contest!

🥇1st Place: hrtng
🥈2nd Place: aiDAPal
🥉3rd Place: idalib Rust bindings

Check out our reviews of the winners and other notable submissions here: https://hex-rays.com/blog/2024-plugin-contest-winners

Huge thank you to all participants for their innovative contributions. Your creativity continues to enhance the IDA community.

0
3
0
repeated

Added AMD support to hvext, the windbg extension for reversing Hyper-V!
https://github.com/tandasat/hvext

You can check what SVM features are enabled, which MSRs and IO ports are accessible, and how nested page table looks like, for NT, SK and regular VMs.

1
3
0
@pancake This reminds me of that guy who tried to use an LLM to decode base64...
0
0
0
I am Ed Zitron's increased blood pressure.
0
0
1
repeated
repeated

Here's some nice empirical evidence to support what we all feel: insecure configuration and insecure defaults drive compromises more than software vulnerabilities. This paper argues that the Secure-By-Design initiative would be better served by focusing on the former.

https://www.documentcloud.org/documents/25524680-sbd-feb-2025-seymourwoods/

1
3
0
repeated

X appears to be blocking Signal's "Signal.me" links in DMs, posts, and profile pages, giving error messages and showing a warning page for users clicking them (Matt Binder/disruptionist)

https://www.disruptionist.com/p/elon-musks-x-blocks-links-to-signal
http://www.techmeme.com/250217/p8#a250217p8

1
4
0
Show older