Posts
2359
Following
513
Followers
1232
A drunken debugger

Heretek of Silent Signal
Go with the fl0w #warcon24
0
0
2
repeated
Edited 3 months ago

Kudos to for defying 's ban on extensions that help Russian users bypass Russian .
https://www.theregister.com/2024/06/14/mozilla_firefox_russia/

1
12
0
repeated

~ Let's make RAM at home, thread #1 ~

In this thread: successful experiment with factory-made ferrite core memory (1 bit for now!), a brief explanation of the experiment, and failed attempts at making a core (so you wouldn't have to try it)

🧵 go~

1
7
0
repeated

I became into toy computers after I got my hands on a wonderful Sumikko Gurashi computer (and started to believe that similarly designed machines can be an answer to our cold heartless world).

I have a few vintage vTech precomputers that run BASIC and have decent IO capabilities (a serial or a parallel port at the very least), but I was curious whether newer toy computers has anything similar.

The exhibit we have here is vTech Media Desktop, a toy computer from around 2010. Its original RPP was about $100, but after a short while slashed to $25. The computer has a non-backlit ~64x48 pixel LCD, two mid-sized speakers to play high-quality digital samples and polyphonic MIDI, a membrane keyboard and a ball mouse.

There is a mini-USB port on the back that switches computer into "Sync" mode. The device presents itself as a 16MB USB stick with 512KB free, and mirrors there the contents of 512KB SPI Flash it has on board.

With the right software (which has vanished from the Internet), new apps can be added.
🧵

1
3
1
repeated
repeated

A proof-of-concept (PoC) exploit for a critical Veeam Recovery Orchestrator authentication bypass vulnerability tracked as CVE-2024-29855 has been released, elevating the risk of being exploited in attacks.

https://www.bleepingcomputer.com/news/security/exploit-for-veeam-recovery-orchestrator-auth-bypass-available-patch-now/

0
2
0
repeated

Release of the old stable (bug-fixed only) version of testssl.sh was overdue but now happened ;-)

You can get it at https://testssl.sh/ or at https://github.com/drwetter/testssl.sh/releases .

You should better use 3.2rc3 though. It is at least as stable and has wayyy more features.

0
1
0
repeated

Inspirational Skeletor💀

Edited 3 months ago
0
1
0
repeated

Scottish physicist James Clerk Maxwell was born in 1831.

His most significant contribution is his formulation of the classical theory of electromagnetic radiation. In 1861-1862, he published a series of papers culminating in "A Dynamical Theory of the Electromagnetic Field," in which he presented Maxwell's equations. He made substantial contributions to the kinetic theory of gases as well as to the Maxwell-Boltzmann distribution

https://www.gutenberg.org/ebooks/author/1586

3
1
0
repeated

2021 retro-link! https://berthub.eu/articles/posts/reed-solomon-for-programmers/ - Practical Reed-Solomon for programmers.

0
3
0
[RSS] Let’s Go into the rabbit hole (part 2) — the challenges of dynamically hooking Golang programs

http://blog.quarkslab.com/lets-go-into-the-rabbit-hole-part-2-the-challenges-of-dynamically-hooking-golang-program.html
0
1
3
[RSS] Relative Offsets in Binary Ninja 4.1

https://binary.ninja/2024/06/12/relative-offsets.html
1
1
3
repeated

Happy Patch Tuesday (er, Wednesday) from Palo Alto Networks:

  • CVE-2024-5905 (CVSSv4: 2.0 low) Cortex XDR Agent: Local Windows User Can Disrupt Functionality of the Agent
  • CVE-2024-5906 (CVSSv4: 4.8 medium) Prisma Cloud Compute: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
  • CVE-2024-5907 (CVSSv4: 5.2 medium) Cortex XDR Agent: Local Privilege Escalation (PE) Vulnerability
  • CVE-2024-5908 (CVSSv4: 5.5 medium) GlobalProtect App: Encrypted Credential Exposure via Log Files
  • CVE-2024-5909 (CVSSv4: 6.8 medium) Cortex XDR Agent: Local Windows User Can Disable the Agent

Palo Alto Networks is not aware of any malicious exploitation of this issue.

1
2
0
repeated

YouTube is currently experimenting with server-side ad injection. This means that the ad is being added directly into the video stream.

This breaks sponsorblock since now all timestamps are offset by the ad times.

For now, I set up the server to detect when someone is submitting from a browser with this happening and rejecting the submission to prevent the database from getting filled with incorrect submissions.

6
21
1
#music #AI #deathmetal
Show content
0
0
0
repeated
repeated

🆕 PrivescCheck update!

I realize that I haven't communicated about PrivescCheck in a while, although I implemented a bunch of new cool features recently. A few of them below:

➡️ Check for listing Attack Surface Reduction (ASR) rules enabled in Defender Exploit Guard.
➡️ SCCM cache folder paths are now enumerated using the registry, and browsed to identify potentially hardcoded credentials.
➡️ New "-Audit" option to enable configuration audit checks.
➡️ New "-Risky" option to manually enable checks that are likely to trigger EDR.

There are also other privilege escalation attack vectors I want to cover in the near future. Stay tuned! :)

👉 https://github.com/itm4n/PrivescCheck

0
3
1
repeated

microsoft: Exploit Code Unporoven

me: i literally gave you a compiled PoC and also exploit code

m$: No exploit code is available, or an exploit is theoretical.

me:

10
24
1
Show older