Posts
2584
Following
627
Followers
1397
"I'm interested in all kinds of astronomy."
[RSS] Llama's Paradox - Delving deep into Llama.cpp and exploiting Llama.cpp's Heap Maze, from Heap-Overflow to Remote-Code Execution

https://retr0.blog/blog/llama-rpc-rce
0
4
4
[RSS] Blasting Past Webp

https://googleprojectzero.blogspot.com/2025/03/blasting-past-webp.html

An analysis of the NSO BLASTPASS iMessage exploit
1
4
4
repeated

@xgranade Relevant article: LLMs use a lot of the same techniques as psychics' "cold reading" to convince people they know more than they do.

https://softwarecrisis.dev/letters/llmentalist/

0
3
0
@nixfreak submodules maybe? also pls note that I linked an experimental branch, you'll be better off with upstream. if you encounter problems please use the GH issue tracker so others can learn from the answers too!
1
0
1
repeated

If it annoys you— as it somewhat does me— that the precise definition of the Rust programming languages is "vibes" and "three separate PDFs, none of them authoritative" and "well, whatever the reference compiler does is the language", this is pretty neat news. https://mastodon.social/@rustfoundation/114229759326166359

4
2
0
#music #deathmetal
Show content
Some quality Hungarian death metal (from Bandcamp Daily):

https://mesacounojo.bandcamp.com/album/t-viskert-a-k-s-rt-s-r-k-rzete-lid-rcharang
0
1
2
repeated

When you do this, you think you’re showing how savvy, smart, or “realistic” you are. What you’re actually doing is wasting the time of, and demoralizing, the people who are actually working to try to stop the thing you’ve already surrendered to.

2
2
0
repeated

Protip: if someone posts a technical or legal analysis of something the administration is doing or proposing and your response is that legalities are irrelevant and a waste of time, the problem is YOU.

You know who wants you to think laws don’t matter anymore and that pushback is hopeless? Fascists.

Don’t act like a fascist.

4
11
0
repeated
Edited 25 days ago

Conservative folklore peeps in Hungary: "Folktales carry our Traditional Values and the Ancient Wisdom of Our Ancestors. They follow a strict set of Traditional Rules"

Literal Hungarian folktales I found in archives:

- Princess Rosalia Lemonfarts

- The Diamond Prince in a Rubber Suit

- The Magic Flying Penis

- Rapunzel, but it's a bloke who makes a rope from his body hair

- Saint Peter got drunk and puked the first 🌈

- The Princess who became a Prince

2
4
0
repeated

CodeQLEAKED – Public Secrets Exposure Leads to Potential Supply Chain Attack on GitHub CodeQL https://www.praetorian.com/blog/codeqleaked-public-secrets-exposure-leads-to-supply-chain-attack-on-github-codeql/

0
3
0
Edited 25 days ago
As you probably know loadlibrary by @taviso can load Windows DLL's - including Windows Defenders mpengine.dll - on Linux.

Since the loader needed some debugging I ended up figuring out how to load the Linux-native mpclient into #Ghidra's debugger and use it to debug the PE module too:

https://github.com/v-p-b/loadlibrary/blob/x64_waffle/GHIDRA.md

This can spare an IDA license and performing dark arts with awk and gas...which is actually pretty badass, so if you want to keep doing that without IDA here's a Ghidra script too:

https://gist.github.com/v-p-b/c7d934234297158047b678f655c7d99f
3
9
24
CVE-2025-30232 Exim use-after-free can potentially lead to privilege escalation

https://exim.org/static/doc/security/CVE-2025-30232.txt

(was ZDI-CAN-26250)
0
0
1
repeated

Day 421. Following up on the no longer available sustainability fact sheets of data centers from day 420, we have added those that we know of to the Internet Archive.

See https://pastebin.com/5f0dFRqZ

0
3
0
repeated
bisecting will continue until morale improves
0
2
0
@rk @lizzy I'm sorry there's just too much meme potential in this post!
0
3
13
repeated
while reverse engineering, the eternal question of

"am i misunderstanding what the code is doing or is whoever wrote this really fucking stupid"
8
11
1
repeated

The AI bots that desperately need OSS for code training, are now slowly killing OSS by overloading every site.

The curl website is now at 77TB/month, or 8GB every five minutes.

https://arstechnica.com/ai/2025/03/devs-say-ai-crawlers-dominate-traffic-forcing-blocks-on-entire-countries/

23
29
0
Show older