Posts
2987
Following
697
Followers
1545
"I'm interested in all kinds of astronomy."
[RSS] Analysis of CVE-2024-20439 in Cisco Smart Licensing Utility

https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html
0
0
0
[RSS] 0-Click RCE in MediaTek Wi-Fi Chipsets -- 4 exploits, 1 bug: exploiting CVE-2024-20017 4 different ways

https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html
0
1
2
repeated

Shameful how some people objectify Palo Alto Networks.

2
2
0
[RSS] Lessons from the buzz - What have we learned from fuzzing the eBPF verifier [PDF]

#fuzzing #eBPF

https://lpc.events/event/18/contributions/1946/attachments/1473/3119/Lessons%20from%20the%20buzz%20-%20LPC.pdf
0
0
2
repeated

So Cards Against Humanity just sued M*sk for ruining a piece of land they bought in Texas for their customers...

https://www.elonowesyou100dollars.com/

2
11
0
repeated

How it started, how it's going

1
1
0
repeated
repeated

📢 We’re now releasing weekly mass testing results 📢

https://mass.rev.ng

Here you can find a weekly report on using revng to decompile tons of binaries.

There’s information about crashes, timeouts and nice graphs.

Our goal is to now bring them all down week-by-week 🦾

1
1
0
Edited 1 year ago
Oracle may have been experimenting with LLM's for longer than we'd assume.

Remember those essays by M.A.D.?

https://web.archive.org/web/20150811052336/https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t
1
0
2
90's edition (h/t @SensorLock for the idea)
0
0
5
repeated

Been doing a fun new reverse engineering project: Figuring out the file formats of the 1999 Windows/PS1 game Attack of the Saucerman. It's the first time I'm doing this on a 3D game. I'm now at a point where I can partially display the levels, and extract most of the assets:
https://github.com/lethal-guitar/SaucerMapViewer

I already made an attempt many many years ago, but was only armed with a hex editor at the time and couldn't make any sense of the data. (cont.)

1
2
0
repeated

Qubes OS Summit 2024 just started

You can assist live on YouTube

https://vpub.dasharo.com/e/16/qubes-os-summit-2024/

1
2
0
repeated

9.9 has been released: https://www.openssh.com/txt/release-9.9

The significant new feature is support for post-quantum mlkem768x25519-sha256 KEX as specified in https://datatracker.ietf.org/doc/html/draft-kampanakis-curdle-ssh-pq-ke-03

0
4
0
repeated

gaining access to anyones browser without them even visiting a website

https://kibty.town/blog/arc/

2
7
0
repeated

Continuing the tour of my @github projects, the toolkit deserves to be mentioned. It's now a bit old, but I believe the concept still applies, and very much so.

https://github.com/0xdea/tactical-exploitation

"The Other Way to Pen-Test" -- @hdm & @Valsmith

I've always been a big proponent of a tactical approach to that doesn't focus on exploiting known software , but relies on techniques such as and . While being able to appreciate the occasional usefulness of a well-timed 0day, as a veteran penetration tester I favor an exploit-less approach. Tactical exploitation provides a smoother and more reliable way of compromising targets by leveraging process vulnerabilities, while minimizing attack detection and other undesired side effects.

Since a few years, I've meant to give a talk on this very subject, with the working title of "Empty Phist Style - Hacking Without Tooling" (inspired by @thegrugq). Sooner or later it will happen.

0
3
0
repeated
repeated

Couldn't let happen without a little bit of to commemorate.
Here's a little sketch of perhaps my number one fave pirate, Guybrush Threepwood :) arrrr! /piratevoice

0
2
0
Show older