Posts
3118
Following
708
Followers
1551
"I'm interested in all kinds of astronomy."
[RSS] CVE-2025-38352 (Part 3) - Uncovering Chronomaly

https://faith2dxy.xyz/2026-01-03/cve_2025_38352_analysis_part_3/
0
0
0
[RSS] RCE via ColdFusion ARchive (CAR) Deployment: One Example of an Authenticated Attack Path in CFAdmin (CVE-2025-61808)

https://www.hoyahaxa.com/2026/01/rce-via-coldfusion-archive-car.html
0
0
1
repeated

Trend in Number: Apple Kernel Space CVEs & Vulnerability Reporters
The blue line represents the number of kernel CVEs, and the green line represents the number of vulnerability reporters across the entire Apple platform. Starting in 2022, the number of vulnerability reporters has been increasing, while the number of kernel CVEs has been decreasing.

1
2
0
repeated

Do you have an idle cluster? Can you spare a couple core-years?

Help me bruteforce some test vectors for RSA key generation edge cases!

Here are the instructions, it's just a matter of running a single self-contained cross-compilable Go binary that will report the results autonomously.

https://gist.github.com/FiloSottile/19e7ceb1fdcdaa128f7d3319ad0939fa

7
11
1
repeated

A German hacker known as "Martha Root" dressed as a pink Power Ranger and deleted a white supremacist dating website live onstage

This happened during the recent CCC conference.

Martha had infiltrated the site, ran her own AI chatbot to extract as much information from users as possible, and downloaded every profile. She also uncovered the owner of the site. She has published all of the data.

https://media.ccc.de/v/39c3-the-heartbreak-machine-nazis-in-the-echo-chamber
Leak data:
https://okstupid.lol/

5
27
0
repeated

*sigh* several weeks ago, I tried to view something on Harvard University's rare manuscript site ("Curiosity Collections"), but the images were all broken. Digging into the javascript console, I found that the images are not missing from the server if you extract their URLs, but the json is being put together wrong and the viewer can't parse it.

I sent an email to the site's contact person with all the info I had. They were apologetic and said their maintainers were "aware" of the issue, but the vague reason they gave me (a VPN issue) doesn't make a lot of sense in the context that the images are all loadable if you know their URL and the viewer is crashing in a json parsing function. So I suspect someone told the contact person a plausible-sounding reason without investigating. At the very least, they don't seem to be trying at all to fix it.

So the rare manuscripts website of a world-major university has been languishing broken for several weeks at minimum, but who knows how long it'd been like that before I, personally, noticed. I guess this is a "state of American education" post.

2
3
0
repeated

shouts out to the nist cve api for having a query parameter in a format that absolutely no http library will emit, basically forcing you to hand-serialise a url

2
1
0
repeated

amazing how many talks at c3, defcon et al boil down to "we looked at the protocol format and it's as though nobody ever thought to do this before"

1
8
0
@hanno I'm afraid there is a general decline of index quality at all major providers (G,Bing,Yandex,???), while alternative engines mostly rely on those. I also noticed that verbatim search is basically dead as not all content is indexed in its original form so even if you know exactly what you are looking for, the index entry is just not there to find it.
0
0
0
@csepp I think @HalvarFlake had a presentation where he talked about hacking like an addiction where accessing more systems (and knowledge) leads you to even more systems, each giving a dopamine rush :)
1
0
3
repeated

My MongoDB honeypot is now open source:

https://gitlab.com/bontchev/mongopot

Visualization (not included in the repo):

https://pandora.nlcv.bas.bg/grafana/d/EysKAV4Dz/mongopot

0
4
0
repeated
Edited 4 days ago

Can anyone recognize this IC? Looking for its p/n and a datasheet ideally. Handles all the analog audio paths in a portable cassette player.

EDIT: A knock-off of Mitsumi LAG668F.

3
2
0
repeated

In the U.S, the Pennsylvania Supreme Court ruled that police can access your Google searches without a warrant.

The court's reasoning: users have no expectation of privacy because "it is common knowledge that websites, internet-based applications, and internet service providers collect, and then sell, user data."

That's what "free" really means. The business model depends on turning your search history into a detailed profile that can be sold, shared, and accessed by third parties.

4
7
0
#music #hardtechno
Show content
New Fernanda Martins & Lukas set :O

https://www.youtube.com/watch?v=x_AQpdS0UTk
0
0
1
repeated

Le Néandertal se sent las, las

0
19
0
repeated

Today's gift from the algorithm: "Visibility undergarments"

🤔

2
2
1
Show older