Posts
2461
Following
661
Followers
1486
"I'm interested in all kinds of astronomy."
repeated

Thorsten Leemhuis (acct. 1/4)

I'd really like to read a well researched article that sums up how Linux distros reacted to the massive influx of CVE that started ~half a year – both for their packages and their live-patching offerings.

But I guess that is an enormous amount of work that no media outlet in this world is willing to pay anyone for writing. 😕

Slide taken from @gregkh's "Why are there so many kernel CVEs?" talk he gave at OSS China yesterday (https://social.kernel.org/objects/c9979d9f-399f-428b-ac56-c41598076dfa )

1
2
0
repeated

I wrote a blog post on my adventures in writing a PE loader for the Xbox One exploit chain by @carrot_c4k3

There's not really anything new and this post was mostly an excuse to document how I fixed thread-local storage, but you might learn something!

https://landaire.net/reflective-pe-loader-for-xbox/

0
2
0
repeated

I just released the blog explaining how I leveraged CVE-2022-22265 in the Samsung npu driver. Double free to achieve UAF over signalfd + cross cache + Dirty Page Table + code inject into http://libbase.so for execution by init. Hope you can enjoy it https://soez.github.io/posts/CVE-2022-22265-Samsung-npu-driver/

0
2
0
repeated

https://v-v.space/2024/08/19/CVE-2024-38148/
Check my blog about Windows secure channel RCE analysis, though MSRC thought it's a DOS. By the way, I'm not the finder. Share for studying

0
3
0
repeated

vuln research is the act of downloading trials and encountering errors while installing them

https://bird.makeup/@flakpaket/1825951830934958211

0
3
0
repeated

Introducing ReSym (CCS'24): our binary analysis technique, an LLM+static analysis solution that recovers names, types, and layouts of variables and data structures from binaries https://tinyurl.com/resym24 @danning_x, @i2huer, @nanjiang719, @xiangzhex XiangyuZhang

0
2
0
repeated

exploit developers reading yet another RFC to see how IPv6 option processing works

0
1
1
repeated

The 32 Video Team videos are now up on https://media.defcon.org Enjoy!

0
4
0
repeated

Google Chrome Zero Day: Stable Channel Update for Desktop
This update includes 38 security fixes. (20 externally reported). CVE-2024-7971 (high severity) Type confusion in V8
Reported by Microsoft Threat Intelligence Center (MSTIC), Microsoft Security Response Center (MSRC) on 2024-08-19

Google is aware that an exploit for CVE-2024-7971 exists in the wild.

cc: @campuscodi @briankrebs @mttaggart @deepthoughts10 @cR0w @regnil @bschwifty @arinc629 @Cali @wvu @hrbrmstr @avoidthehack @bieberium @AAKL (make sure to remove all the mentions to avoid ReplyAll madness)

2
2
0
repeated

Physarum wires: Self-growing self-repairing smart wires made from slime mould: https://arxiv.org/abs/1309.3583 a.k.a. super super gross wires. This is for sure how you end up with the backstory for the Borg.

0
7
0
repeated

This won't likely surprise anyone, but "a prompt injection vulnerability in Slack AI makes it possible to fetch data from private Slack channels".

https://www.theregister.com/2024/08/21/slack_ai_prompt_injection/

0
4
0
repeated

Pretty much. From the brand new issue of Phrack.

4
4
0
repeated

Binji's teaching in Europe! By popular demand and for the first time ever, Novice to Ninja is online in GMT! Uncover the truth behind today's most pressing cybersecurity issues, and what might be done to mitigate them. No reversing experience required! https://binary.ninja/training/n2n-syllabus.html

0
1
0
repeated

The SAILR paper is being presented at @USENIXSecurity
.

It's a nice piece of work. If you're interested in what we think, take a look at the in-depth review we did on Feb!

https://pad.rev.ng/s/T3RdsvKNx#

0
2
0
repeated

It's here! officially released online, and with it my article! http://phrack.org/issues/71/9.html#article It's about writing a good virus, using oldschool techniques to show you how effective old stuff can still be!

1
3
0
repeated

ugh. I picked up a shitty NUC from ewaste and it had a label on it for an AI company.
ahh, another startup that burnt out trying to build some silly AI project on crap hardware. I wonder what they did? I check their URL:
ahh. healthcare. great, great.

3
9
1
repeated

That’s no moon – it’s the Moon 🌗

The first colour images from ESA JUICE’s close lunar encounter last night are out.

Taken by the monitoring cameras, both show sunlit craters & shadows on the surface with parts of the spacecraft in the foreground.

At the top of the second image, you can just make out Earth as a small dark circle, surrounded by the ring of its backlit atmosphere.

We arrive (t)here tonight 🛰️🌏

Kudos to @stim3on for the magical processing 🙇‍♂️

1
5
0
repeated

UPDATE: Palo Alto Cortex XSOAR CommonScripts Critical Vulnerability (CERT-EU Security Advisory 2024-083)

On August 14, 2024, Palo Alto Networks released a security advisory for a critical command injection vulnerability, CVE-2024-5914, in Cortex XSOAR. This flaw allows unauthenticated attackers to execute arbitrary commands within the context of an integration container, potentially compromising the system. The vulnerability affects the product's CommonScripts Pack and is rated as high severity with a CVSS score of 9.0.

https://www.cert.europa.eu/publications/security-advisories/2024-083/

0
1
0
repeated

There's an article written by me in Phrack Magazine: http://www.phrack.org/issues/71/11.html#article.
Very proud to be in that historic hacking magazine! For me, this is a major achievement :)

Bonus: the source code and binaries are here https://github.com/cryptax/talks/tree/master/Phrack-71

Enjoy! And if you really like it, I'd appreciate you nominate it here https://www.virusbulletin.com/conference/peter-szor-award/

Anybody with a paper edition to send me? This offer still stands: https://mastodon.social/@cryptax/112775284733028530

1
2
1
repeated
Show older