Posts
3368
Following
712
Followers
1579
"I'm interested in all kinds of astronomy."
repeated

bert hubert ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ฆ

So I didn't know, but Europe already has a backup of PubMed, the database of biomedical research publications. The US PubMed broke down over the weekend. And here is our alternative: https://europepmc.org/

1
17
0
repeated

@buherator kdnet has had support for the virtio NIC for years.

In Windows just configure kdnet as you would with any other supported NIC and, in QEMU, configure the virtual NIC as

-netdev user,id=net0 -device virtio-net,netdev=net0,disable-legacy=on

1
1
1
repeated

๐Ÿš€ New Blog & PoC Release: Abusing IDispatch for COM Object Access & PPL Injection ๐Ÿš€
I've developed a PoC exploit that demonstrates an interesting bug class in COM servers implementing IDispatch, allowing indirect object creation within the target process. Specifically, by leveraging the ability to instantiate STDFONTโ€”a legacy COM class not designed for cross-process useโ€”I was able to achieve code injection into a Windows PPL (Protected Process Light) process. This technique enables interaction with protected processes like LSASS.
This research builds on the work of @tiraniddo who identified how COM object manipulation via IDispatch can lead to unexpected process interactions. My PoC takes this concept further by demonstrating its practical impact through registry manipulation and .NET payload execution inside PPL processes.
๐Ÿ” Blog Post: https://mohamed-fakroud.gitbook.io/red-teamings-dojo/abusing-idispatch-for-trapped-com-object-access-and-injecting-into-ppl-processes
๐Ÿ’ป PoC & Source Code: https://github.com/T3nb3w/ComDotNetExploit
Key Highlights:
๐Ÿ”น Exploiting IDispatch in OOP COM servers
๐Ÿ”น Abusing STDFONT instantiation for process injection
๐Ÿ”น Achieving code execution inside PPL and accessing LSASS
๐Ÿ”น Bypassing SEC_IMAGE integrity checks
๐Ÿ”น Leveraging OnlyUseLatestCLR for compatibility

1
5
0
repeated

I keep hearing that Sup shouldn't exist because X exists.

I made Sup to replace Snapchat and Facebook Messenger in my own friend group

I think it might be useful to other friend groups or families too, being that you can join with an email or Pixelfed/Loops or Mastodon account

Not only that, but Sup will be modular, allowing for rich integration with pretty much any other chat platform (Signal, Matrix, Delta, etc)

It's like Beeper, but federated and open source. ๐Ÿš€

0
3
0
[RSS] A Series of io_uring pbuf Vulnerabilities

https://u1f383.github.io/linux/2025/03/02/a-series-of-io_uring-pbuf-vulnerabilities.html

CVE-2024-0582, CVE-2024-35880, ???
0
0
1
repeated

Hi! The slides for my talk today at RE//verse 2025 (@REverseConf), "Reconstructing Rust Types: A Practical Guide for Reverse Engineers", are now published: https://github.com/cxiao/reconstructing-rust-types-talk-re-verse-2025

It's been great to catch up with so many folks - if you're at the conference, come by and say hi!

The presentation was recorded, and the video will be published at a future date!

1
7
0
repeated

This is the most important comment I have heard this week โ€” Polandโ€™s Prime Minister Donald Tusk:

โ€œ500 million Europeans are asking 300 million Americans to defend them against 140 million Russians [โ€ฆ] Europe, if there is something we lack today, it is not economic or demographic power, but the belief that we are truly a global force.โ€

I think Tusk hits the bullseye here. Those 140 million Russians are already fully occupied by fighting Ukraine, and our leaders act like we are Liechtenstein.

31
15
0
repeated

If you are looking for my slides from my Reverse talk, you can find it and useful artifacts here: https://github.com/mahaloz/talks/tree/main/2025/REverse_SAILR

0
7
0
repeated

Framework Desktop: It's not a $3k 1Petaflop 128k Blackwell DIGITS, but it does have Strix Halo/Ryzen AI Max+ 395 unified memory(DDR5x tho) with a 256 wide bus soldered memory on the board - capability that would cost $6k in a Macbook for $2k.

New Framework desktop, engineering sample torn down by iFixit - skip to 7:20.

https://www.youtube.com/watch?v=5mGzEsRM3hs&t=553s

0
2
0
@cR0w Oooh this one looks juicy! Like auth bypass for the thing that stores *everything*?
0
0
1
repeated

There is one democratic leader in this. The rest are Putin's fascist henchmen.

5
4
0
repeated

To the Swedish and French governments, and to all politicians who believe that they can stop data from ending up in the wrong hands with rules and restrictions: donโ€™t be naive.

0
5
0
"depending on the context "1 in 4" also means 'Guaranteed'" - https://bird.makeup/users/gf_256/statuses/1895366648628158503

Sadly gf_256 is not near here, but this is basically the idea behind the the Probabilistic Method in mathematics :)

https://en.wikipedia.org/wiki/Probabilistic_method
0
0
2
repeated

The thing about computer virus detection is once you get deep enough into industry you realize programmers write everything to look like a virus that's going to break the computer.

5
6
0
I'd celebrate #Skype's death with champagne if it wasn't ditched for #!&% teams (yes, lowercase!)

Instead let us enjoy this 2011 presentation about Skype's anti-debug tricks:

https://www.blackhat.com/presentations/bh-europe-06/bh-eu-06-biondi/bh-eu-06-biondi-up.pdf
0
0
3
repeated

The end of Skype. It was pretty good until Micro$oft bought it. https://www.nytimes.com/2025/02/28/technology/microsoft-skype-shutting-down.html

0
1
0
I used the Mastodon client hosted at brutaldon.org to connect to infosec.exchange with the elinks browser - the UI is...not great, but I guess it's just my terminal vs the default elinks configs :D

Anyway, you can ditch your uncool, sellout browsers and experience the Fediverse truly freely!
0
0
0
@cR0w You don't need to spin up a server, they have a hosted instance that can connect to infosec.exchange as a client, will post a screenshot in a sec :D
0
0
1
Show older