Posts
2526
Following
648
Followers
1465
"I'm interested in all kinds of astronomy."
repeated

Spent the last four days coordinating incident response for the Squarespace domain hijackings with @tay and @AndrewMohawk. Now that it seems to be resolved, we wrote a little postmortem/retrospective

https://securityalliance.notion.site/A-Squarespace-Retrospective-or-How-to-Coordinate-an-Industry-Wide-Incident-Response-fead693b66c14543a48283d85aec19ad

1
3
0
repeated

Starting from v0.10 (the next version), HyperDbg uses @keystone_engine as its assembler. ❤️

Thanks to our new team member @AbbasMasoumiG for adding it.

The following commands are added to assemble virtual and physical memory:

- https://docs.hyperdbg.org/commands/debugging-commands/a

- https://docs.hyperdbg.org/commands/extension-commands/a

1
1
1
repeated

Clever & fun technique to dump LSA secrets bypassing by @sensepost

Dumping LSA secrets: a story about task decorrelation

https://sensepost.com/blog/2024/dumping-lsa-secrets-a-story-about-task-decorrelation/

0
5
1
repeated

Introduction to the Wild West of Proof of Concept Code () aka SSHing the Masses

https://santandersecurityresearch.github.io/blog/sshing_the_masses.html

0
2
0
repeated
4
19
4
repeated

Everyone complains about meetings, but rarely anybody puts time before the meeting to do the work needed for the meeting to be useful.

6
2
1
repeated

CCC researchers had live access to 2nd factor SMS of more than 200 affected companies - served conveniently by IdentifyMobile who logged this sensitive data online without access control.
You had one job.

https://www.ccc.de/en/updates/2024/2fa-sms

1
5
0
repeated

Does anyone have a technical reference (assuming it is public) for the hardware additions to ARMv8 which Apple made in Apple Silicon to support Rosetta 2?

1
1
0
repeated

“Admiral Grace Hopper’s landmark lecture is found, but the NSA won’t release it “: https://www.muckrock.com/news/archives/2024/jul/10/grace-hopper-lost-lecture-found-nsa/
(I heard her speak at Chapel Hill when I was in grad school. Sadly, she did not hand out nanoseconds at that talk.)

3
3
0
repeated

"adhd is a new thing" is very funny to me, you used to be able to buy amphetamines over the counter, anyone with it could self medicate

much like erdős did, heh

a close friend bet him $500 he couldn't last a month without them. he did

"you have set mathematics back by a month"

2
3
1
repeated

gambling is the only non-substance addiction disorder recognized in the American Psychiatric Association’s DSM-5 🤔 good thing modern smartphone use is totally unlike gambling in any way whatsoever

2
3
0
repeated
repeated

My blog post about several findings in Dynamics 365 Business Central. I tried writing in a .NET primer style for code audit beginners.

https://frycos.github.io/vulns4free/2024/07/10/dynamics-ups-and-downs.html

0
8
0
repeated

VMware security advisory: VMSA-2024-0017
CVE-2024-22280 (8.5 high) SQL-injection vulnerability in VMware Aria Automation: An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database. No mention of exploitation.

0
1
0
repeated

Only something this useless could be this educational https://robertheaton.com/pyskywifi/

2
3
0
repeated

Pwn2Own: WAN-to-LAN Exploit Showcase TP-Link ER605 routers and Synology BC500 IP camera - Part 1: WAN https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase

0
1
0
repeated

Stacey Marshall, the current sendmail maintainer for , has blogged about disabling the CR+LF requirements for SMTP newly enforced in Solaris 11.4.68 and later due to the fix for CVE-2023-51765, for sites stuck with non-compliant SMTP senders:
https://staceymarshall.wordpress.com/2024/07/09/configuring-sendmail-srv_feature/

(Though that should be a short-term solution until you can get the software senders updated to follow the SMTP RFCs.)

0
2
0
repeated

If you missed it: "Run Your Own Mail Server" is now on preorder from my site. You could get ebooks, signed paperback, or signed hardcover.

Or give up the Internet and improve your life. Whichever.

https://www.tiltedwindmillpress.com/product/ryoms-preorder/

0
3
0
repeated

Trend Zero Day Initiative

It's Patch Tuesday once more. While had a tiny release, had one of their biggest months ever - including two 0-days under active attack. Join @TheDustinChilds as he breaks down all the details. https://www.zerodayinitiative.com/blog/2024/7/9/the-july-2024-security-update-review

0
3
0
repeated
Show older