Posts
2762
Following
681
Followers
1504
"I'm interested in all kinds of astronomy."
@joxean @wirepair I'd need something permanently online so I can ise then as CI test cases
0
0
0
repeated

The official @Defcon recording of HTTP/1.1 Must Die has landed - join me on the mission to help kill HTTP/1.1! https://www.youtube.com/watch?v=PUCyExOr3sE

2
4
0
@reynardsec What really annoys me is that some teams decide to publish a latest tag, yet they have no process for updating is, so the latest tag becomes anything but... It would be much more honest if they called it "favorite" or something that doesn't imply freshness when they don't even attempt to guarantee that.
0
0
1
Edited 1 month ago
I'm looking for publicly available reverse engineered program databases (idb, gpr, bndb, ... ), preferably for relatively small programs.

Any tips?

#ReverseEngineering
3
7
4
@algernon I ran some tests and you are right: LLMs are still far from reaching n-gate-level snark
0
0
1
@algernon Wait, could an LLM faithfully imitate n-gate?
1
0
0
@algernon I miss n-gate's webshit weekly so much :,(
1
0
2
repeated

Serious bugs often occur in third-party components integrated by other software. Ivan Fratric and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click.

Integrators should update today!

https://project-zero.issues.chromium.org/issues/428075495

0
9
0
repeated

Hi there! This is again!

Today I'd like to present you one of frequent sources of pain for C64 owners, the infamous PLA. This is MOS 7700R2. They failed way too often, and considering this is custom silicon, the only option was to get another one of the same.

Many thanks to @root42 for providing this sample!

SiPron link: https://siliconprawn.org/archive/doku.php?id=infosecdj:mos:7700r2

3
4
0
repeated

Project Zero Bot

New Project Zero issue:

Dolby Unified Decoder: Out of bounds write in evolution parsing

https://project-zero.issues.chromium.org/issues/428075495

CVE-2025-54957
0
2
1
repeated

These kinds of issues are more common than people would expect. I remember running tcpdump in 2003 and seeing some obvious kernel data being leaked over the network. Similar to the coredump case, it's there but nobody really looks:
https://bird.makeup/users/grsecurity/statuses/1252558055629299712

1
3
0
repeated

How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked https://blog.pixelmelt.dev/kindle-web-drm/

0
2
0
repeated
@waifu 1 point because in this part of the world nobody trusts anyone with paper checks. The conclusion is that I'm essentially a teenager.
0
0
0
repeated
Edited 1 month ago

My OBTS v8 slides for Apple Compressor (part of Final Cut Pro) unauthenticated LAN RCE. No CVE? Because it’s not patched…🫣

https://github.com/ChiChou/slides/blob/b737cc3037408221217d59c8fc6b8a82706b7062/Queen%20B%200-click%20RCE%20for%20Apple%20Compressor.pdf

0
6
0
(fair warning: if you are a JSF author, you better not come to punching distance of me)
0
0
1
"Which of course makes perfect sense when you are in the business of breaking stuff so people have to pay you for fixing it."

This is an old article, but this one sentence explains so many things!

https://dzone.com/articles/why-you-should-avoid-jsf
1
0
1
repeated

Inspirational Skeletor💀

1
19
0
Show older