Posts
2529
Following
647
Followers
1459
"I'm interested in all kinds of astronomy."
repeated

In case anyone here has connections with the Python team: can you please tell them to update their docs on XML security? The way it is is quite misleading, and it's been annoying me for a while. I raised this a while ago in their issue tracker, but it got no reaction whatsoever. https://github.com/python/cpython/issues/127502 🧵

1
1
0
repeated

Computer History Museum 🇸🇮

PHP just turned 30! 🎉 Did you create guestbooks for your website like the early users of the language? 📜 Do you remember technologies like PHP-Nuke, phpBB, or browsing vBulletin forums? 💻

1
3
0
repeated

The slides for @offensive_con talk "Hunting for overlooked cookies in Windows 11 KTM and baking exploits for them" by @saidelike and I are here:

https://docs.google.com/presentation/d/1M_ziQt6rZA01ghsv0qo7lhqyOLIZYNnV-qjHWun6A1g/edit?usp=sharing

1
3
0
repeated

another day, another binary file format with a badly designed magic number

not gonna call it out specifically but here are some RFC2113 MUSTs for magic number design:

MUST be the very first N bytes in the file
MUST be at least four bytes long, eight is better
MUST include at least one byte with the high bit set
MUST include a byte sequence that is invalid UTF-8
SHOULD include a zero byte, but you can usually get away with having that be part of the overall version number that immediately follows the magic number (did I mention that you really SHOULD put an overall version number right after the magic number, unless you know and have documented exactly why it's not necessary, e.g. PNG?)

good examples:

  • PNG
  • ELF

bad examples:

  • GIF
  • PE
  • PDF
5
7
0
@algernon IIRc I only used qtorrent from the terminal/web frontend. Transmission-daemon with web ui is also nice.
1
0
1
repeated

End of an era: our CVSweb service turned 21 today, and was promptly retired. Our anoncvs was similarly shut down at the age of 21 two years ago, quietly.

https://bird.makeup/@openwall/1367145526093893641

0
4
0
repeated
Edited 23 days ago

💥 I'm a youtuber now! 📺

Just recorded a short video solving a crash in the decompiler to lower the barrier to help new contributors get handy with the radare2 codebase and common developer workflows.

https://www.youtube.com/watch?v=Fr6cOa_YRkI

1
3
0
repeated

Just launched Code Auditor CTF — https://auditor.codes

A web platform to practice finding real-world C/C++ vulnerabilities
• 8000+ challenges
• Progress tracking + leaderboard
• Beginner-friendly
• Fully open source (beta): https://github.com/20urc3/auditor.codes

0
5
0
repeated

Alan Turing died by suicide on 7 June 1954. Turing was convicted of gross indecency in 1952 and given a choice between imprisonment and probation. His probation would be conditional on his agreement to undergo hormonal physical changes designed to reduce his libido. Turing's conviction led to the removal of his security clearance and barred him from continuing with his consultancy for GCHQ. He was denied entry into the United States after his conviction.

6
23
0
repeated

Standing by the printer holding a hammer just to make sure it does what it's told

5
3
1
repeated

Besides watermelon, there should be windmelon, firemelon and earthmelon - the four elemelons.

5
12
0
repeated

@matildalove @soatok
ISO: "We created global standards for everyone to follow"
Everyone: "Can we see them?"
ISO: "No"

6
21
1
repeated

The Tiny Awards are back, and so am I! After a year off, I'll be a judge helping to decide "the best of the small, poetic, creative, handmade web" made in the last 12 months. Nominations open until the end of June, submit anything you love! https://tinyawards.net/

1
2
0
repeated
Edited 1 month ago

So, my technical report on fuzzing CPython with fusil is almost done.

I'd really appreciate some help categorizing the found issues by relevance/severity/importance or any other name for impact.

Do you have the chops to help with that? And do you have time and interest? Please get in touch if so! And please boost if you can :)

A plot, some tables, links to the report and some discussion are available in this thread:

https://discuss.python.org/t/feedback-on-the-recent-fusil-fuzzing-campaign-of-cpython/91737

0
5
0
repeated

We sponsored and printed out copies of @PagedOut #6 for SecurityFest and as I’m reading through it I’m not even mad about the messed up font, I just miss good old paper fanzines. PDFs are great but just don’t soothe my old soul the same way.

1
3
0
Edited 1 month ago
I tried to improve on @carrot_c4k3 's work to bypass Windows KASLR with a prefetch side-channel. I summarized my results in a new blog post, spiced up with some geek art:

https://scrapco.de/blog/visualizing-prefetch-infoleaks-to-defeat-kaslr.html
0
6
10
repeated
repeated

FreddyB Aviation Photography

0
1
0
Show older