Posts
2483
Following
663
Followers
1489
"I'm interested in all kinds of astronomy."
repeated

Anybody knows how to run Python scripts from Ghidra's Script Manager using PyGhidra and *NOT* Jython?

PS: I have already opened an issue in their github https://github.com/NationalSecurityAgency/ghidra/issues/7856

0
3
0
repeated

The 3rd episode of our series, "Streamlining vulnerability research with and ", is here! @raptor introduces new tools to assist with reverse engineering and vulnerability research, based on @HexRaysSA IDA and @binarly_io idalib.

https://security.humanativaspa.it/streamlining-vulnerability-research-with-ida-pro-and-rust

0
4
0
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

"Europe has also underestimated the geopolitical dimensions of technology, leaving itself vulnerable to dependencies and intensifying global competitive
pressures. This vulnerability has become especially apparent amid rising trade wars, the resurgence of populist nationalism, and escalating geopolitical rivalries." - page 98 of the @eurostack paper: https://www.euro-stack.info/docs/EuroStack_2025.pdf

0
3
0
repeated

HyperDbg v0.13 is out! 🎉

This version comes with a new command '!pcicam' for dumping and interpreting PCIe CAM, new anti-anti-hypervisor methods, improved MMIO scripting, plus lots of bug fixes & improvements.
Big thanks to @0Xiphorus & @AbbasMasoumiG.

https://github.com/HyperDbg/HyperDbg/releases/tag/v0.13

More details are available here:
https://docs.hyperdbg.org/commands/extension-commands/pcicam

0
3
1
[RSS] Hacking the Xbox 360 Hypervisor Part 1: System Overview

https://icode4.coffee/?p=1047
0
4
5
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

A Dutch government department (not sensitive) has deeplinked an image from my website on their (apparently) autoreloading intranet page. It is a good thing I'm a responsible person (ahum). Here is the number of hits/minute, clearly showing the lunch break, and that far fewer people work on Friday, and that most visits are in the morning. This is a GREAT example of how much data you leak by putting external content on your (government) web page.

2
5
1
repeated

"Search ads accounted for more than half of Alphabet’s revenue and nearly three-quarters of the company’s advertising revenue in 2023, according to company filings." Source: https://wallethub.com/blog/google-quality-issues-report/147091

Incentives matter. This is what makes Kagi different: https://help.kagi.com/kagi/why-kagi/why-pay-for-search.html

0
4
0
repeated

I post-processed a bunch of Univac 1050 software documents that were in the scanning queue.
http://bitsavers.org/pdf/univac/1050
In the 00s, someone on eBay was selling 7 track diagnostic source tapes from the basement of a Univac factory for the 1050 which Paul Pierce read for me. I haven't looked at the images in 20 years but it's probably time to see if I can print out the data.
As far as I know, this is the only 1050 code that survives.

@bitsavers

1
2
0
[RSS] Announcing Pwn2Own Berlin and Introducing an AI Category

https://www.thezdi.com/blog/2025/2/24/announcing-pwn2own-berlin-2025

P2O will be at OffensiveCon :O Also, AI pwn means RCE (as it should be)
0
0
2
repeated

This isn't a sexy exploit, but this is exactly the kind of thing that can ruin people's lives. Inform your network about how to spot these.

https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/

1
5
0
repeated

New from 404 Media: all 50 states have introduced right to repair legislation. Not all have passed, but it's just a massive milestone for the right to repair movement that just a few years ago was demonized by big tech https://www.404media.co/all-50-states-have-now-introduced-right-to-repair-legislation/

0
6
0
repeated

New video: “rev.ng: an overview”.

Check it out: https://www.youtube.com/watch?v=qbt6Ukoa-sQ

0
2
0
repeated
repeated

Five things we DID NOT do last week

1. Track users
2. Send data to another company or organisation
3. Boost or demote political content
4. Use Google or Bing Search API
5. Train AI using indexed content

1
3
0
@sassdawe Defender usually chokes IO. Are you sure you get up-to-date results (considering you can't use the system otherwise, perf/GUI updates may be late too)?
1
0
0
[RSS] Linux Kernel Some Vsock Vulnerabilities Analysis

https://u1f383.github.io/linux/2025/02/24/linux-kernel-some-vsock-vulnerabilities-analysis.html

Analysis of CVE-2025-21669, CVE-2025-21670 and CVE-2025-21666
0
1
1
repeated

Dan Farmer, who spoke at the first is still at it, this time pointing out some problems on SuperMicro (and most likley other) systems:

https://trouble.org/?p=1227

1
7
0
Show older