Posts
3581
Following
723
Followers
1587
"I'm interested in all kinds of astronomy."
[RSS] AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks

https://www.ndss-symposium.org/wp-content/uploads/2026-f1282-paper.pdf
0
0
0
repeated

Tired of guessing inputs? Let the computer do the work! Learn about symbolic execution from @barbie in "Reverse Engineering 3201" https://ost2.fyi/RE3201 and use SMT solvers to find the exact inputs to reach vulnerable code. Stop guessing, start solving! 

0
2
0
repeated

I already knew that we use nonsense measurement systems here in the US. But only recently did I realize that a US gallon is different than a UK gallon.

3
2
1
repeated

RE: https://infosec.exchange/@mr_phrazer/116166155203519881

I also published my Ghidra Headless MCP that follows similar design principles: https://github.com/mrphrazer/ghidra-headless-mcp

0
4
0
@pleia2 Except there is at least one fundamental difference between the X->Prompt abstraction and everything else he brings up (based on the slides):

https://blog.trailofbits.com/2025/12/19/can-chatbots-craft-correct-code/
1
0
0
repeated

New blog post: Perfect types with `setHTML()` - https://frederikbraun.de/perfect-types-with-sethtml.html - TLDR: Use require-trusted-types-for 'script'; trusted-types 'none'; in your CSP and nothing besides setHTML() works, essentially removing all DOM-XSS risks....

4
4
0
repeated

Composing Sanitizer configurations (https://frederikbraun.de/composable-sanitizers.html): The HTML Sanitizer API allows multiple ways to customize the default allow list and this blog post aims to describe a few variations and tricks we came up with while writing the specification.

0
1
0
repeated
@Sempf I used this model for years, but somehow the keyboard became terrible (didn't register presses or registered double-triple) after a while and it was even worse in brand new phones. How's yours doing?
1
0
2
repeated

Ricard Torres 👨‍💻

Darknet Diaries 170: Phrack

"Phrack is legendary. It is the oldest, and arguably the most prestigious, underground hacking magazine in the world..."

🔗 https://darknetdiaries.com/episode/170/

1
6
0
Watching pro developers discussing how stupid some of the exploits of widely used software are is pretty entertaining:

https://www.youtube.com/watch?v=OgfdyH4iaps

Good to see the "other side" gets it!
0
0
2
repeated
@algernon Hearing this from someone who produces non-trivial Rust software restores my self-esteem a tiny bit
1
0
0
Phrack 73 CFP

https://phrack.org/

With a demo!
0
5
3
repeated
[RSS] Reverse-engineered the WiFi transfer protocol for HeyCyan smart glasses (BLE + USR-W630 WiFi module) -- first iOS implementation

https://alexschar.dev/HeyCyanCaseStudy
0
0
0
[RSS] A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets

https://blog.calif.io/p/a-race-within-a-race-exploiting-cve
0
1
2
[RSS] Reviving a 20-year-old puzzle game Chromatron with Ghidra and AI

https://quesma.com/blog/chromatron-recompiled/
0
1
3
@matdevdug I laughed so hard that my family started to get worried. Thank you!
0
0
2
repeated

If you have not seen Wargames, you absolutely should. Holds up well (as a movie; maybe not the technology so much), all these years later. Currently free on YouTube. https://www.ozbargain.com.au/node/950868

2
5
0
Show older