Posts
2472
Following
662
Followers
1487
"I'm interested in all kinds of astronomy."
repeated
repeated

Wireless hacking doesn't have to be a mess of dongles and ad-hoc code anymore.

Yesterday @virtualabs from Quarkslab and @rcayre from EURECOM released WHAD, a set of open source tools, libraries and firmware to make wireless security research easier.

WHAD implements 6 protocols (BLE, ZigBee, RF4CE, Unifying, ESB, LoRaWAN) and supports 11 different hardware devices, including 4 embedding our custom firmwares to extend their capabilities.

It can be used to sniff various protocols (BLE, 802.15.4, ZigBee, RF4CE, Enhanced Shockburst, Logitech Unifying and even unknown ones via its PHY support), packet injection, MITM attacks, device emulation, device sharing over TCP, and a number of other features and capabilities.

See the code repository here https://github.com/whad-team/whad-client

1
6
0
repeated

if AI wants to be useful, it can read the build instructions of a github readme and tell me which seventeen packages the author forgot to mention I need to install first

4
2
0
repeated

Losing my mind at this. Google says that cellsite simulators are being used to send SMS spam.

https://security.googleblog.com/2024/08/keeping-your-android-device-safe-from.html

4
3
0
repeated

Trend Zero Day Initiative

We had a lot of fun handing out our first-ever Awards. If you couldn't be there, we've updated our blog with all the winners. Check it out at https://www.zerodayinitiative.com/blog/2024/8/1/introducing-the-vanguard-awards

0
3
0
repeated

Looks like we shipped Firefox 129 last week, where the address bar is defaulting to use HTTPS (and falls back to HTTP if it doesn't work). Kudos to the team for shipping! 😀 It's nice to see something happen so smoothly when on vacation

1
1
1
repeated
repeated

Huh, with the new IDAlib headless mode in @HexRaysSA IDA 9.0, can get rid of the visible second IDA instance. Need to play around with this more.

0
1
0
repeated

Step aside, devs. The Infosec Wizards are coming.

https://www.theregister.com/2024/08/09/marlinspike/

0
2
0
repeated

I very much enjoyed this talk by @thegrugq While there are many issues here worth discussing like systems' perception of the world or why is it not so easy to predict how system will fail, I particularly liked discussion on impact of policy decision.

Too often I have heard arguments how certain technical solution can overcome/solve particular issues and make them "policy-proof". In reality scope of influence available to both state and private actors, makes policy way more important factor determining outcome. You can't out-obfuscate your way out of telemetry available to major tech companies or out-encrypt government level targeted surveillance.

https://www.youtube.com/watch?v=P6PnhDfWvx0

0
2
0
repeated

excited to see my janky code being put to good use for jailbreaking flagship smartphones such as the "vtech kidizoom snap touch"

https://bird.makeup/@rdjgr/1818367871086686432

0
2
0
repeated

Interesting paper - A Verification Methodology for the Arm® Confidential Computing Architecture: From a Secure Specification to Safe Implementations https://dl.acm.org/doi/abs/10.1145/3586040

0
1
0
repeated

As a Blind person i never thought i would be on social media savoring photos. But the communal Mastodon alt text game is so strong that sweet, poetic or silly descriptions abound on my timeline. Thanks to legions of people who take time to write a meaningful description of the ephemera they post, i learn so much about insects, plants, buildings, memes — all dispatches from a dimension of the world that i otherwise wouldn't experience. If you're wondering whether anybody reads these things: YES.

9
63
3
repeated

🧵 Saturday reversing thread: I was going to wait until the full release, but since the beta seems to have become more-public-than-intended, let’s look at how the official “IDA as a library” works in IDA Pro 9.0…

1
4
0
repeated
repeated

Happy Zero Cool Day

0
9
0
repeated

One question regarding and : Can I legally make a video showing cuts of videos from multiple news sources? Like, say, I show some ~5 seconds from a video in CNN, then another one from BBC, then another one from a Chinese outlet, etc...

PS: The music & video will be free. Most likely Public Domain.

1
1
0
repeated

Yeah, all decompilers included. Very good day for the RE "community" :PPPPPPPP

Nice addition to my IDA leak collection :-)))))))))

1
1
0
repeated

Picard management tip: Empower others to command when you are unfit. You never know when your mind will be taken over by an alien.

0
2
0
repeated

It’s been a while since we had a good 512-bit RSA key controlling anything important, and I’m here for it. https://arstechnica.com/security/2024/08/home-energy-system-gives-researcher-control-of-virtual-power-plant

2
5
0
Show older