Posts
3373
Following
712
Followers
1579
"I'm interested in all kinds of astronomy."
repeated

i love css 💖

also shoutout to Fastmail for rolling out fixes for both reports in <48h
https://www.fastmail.com/bug-bounty/

1
2
1
#IBMi is affected by a user gaining elevated privileges due to an unqualified library call vulnerability in IBM Facsimile Support for i [CVE-2025-36004]

https://www.ibm.com/support/pages/node/7237732

Another one by @silentsignal !
0
0
0
[RSS] CFCamp 2025 Slides - Understanding CFML Vulnerabilities, Exploits, and Attack Paths

https://www.hoyahaxa.com/2025/06/cfcamp-2025-slides-understanding-cfml.html

#coldfusion
0
0
1
I updated the generated #Ghidra documentation I host for 11.4:

https://scrapco.de/ghidra_docs/

Here's the documentation for Decompiler Taint Operations:

https://scrapco.de/ghidra_docs/Features/DecompilerDependent/DecompilerTaint/DecompilerTaint.html
0
0
1
#Ghidra 11.4 released with support for (external) taint engines in the decompiler:

https://github.com/NationalSecurityAgency/ghidra/releases/tag/Ghidra_11.4_build
1
4
6
repeated

📢 @ERNW is preparing the venue for tomorrow's launch of in ! See you soon people! We are super excited! 🥳

0
2
1
@Viss @neurovagrant @dangoodin I think a better analogy would be Stagefright where target diversity was a major factor blocking widespread abuse IIRC: based on my recent experiments with side-channels, target HW can have significant effects.

FTR, this is an example of targeting end-user applications:

https://www.youtube.com/watch?v=ugZzQvXUTIk

And don't forget: as SW mitigations (or even HW assisted ones) get better, attackers may turn to more "painful" alternatives...
0
1
1
[RSS] Abusing copyright strings to trick software into thinking it's running on your competitor's PC

https://devblogs.microsoft.com/oldnewthing/20250624-00/?p=111299

#warez
0
0
3
repeated
repeated

VSCode のターミナルも Sixel 対応してたのか (terminal.integrated.experimentalImageSupport を有効にすると表示される)

0
1
0
repeated

"We will respond to you in 5 days"

3 weeks later... No response.

Anyone who gets mad at people for going full disclosure has never had to deal with the bureaucratic maze of trying to get people to fix their things.

1
4
0
repeated
Edited 7 months ago

PSA: The new version of our browser extension now requires additional permissions to "change your privacy-related settings".

The new permissions are required so we can set KeePassXC as your default password manager backend. Unfortunately, there isn't a better name for this permission set.

6
3
0
@bagder Sounds plausible, although that sounds like lots of work to dig up an unrelated e-mail address :)
1
0
1
repeated

Remote code execution in CentOS Web Panel - CVE-2025-48703 https://fenrisk.com/rce-centos-webpanel

0
3
0
@bagder I'm dying to know
- what the problem was
- how did this person end up emailing you (are gasoline sensors queried with curl in Opel Astra??)
1
0
2
repeated

@buherator No, fel is huztam! Rogton 3 cimen is, mert nem tudtam donteni.

Ha lenne hajam, akkor most csinalnek magamnak jofajta punk frizurat. flan_headbang

1
1
1
Show older