Posts
2589
Following
627
Followers
1397
"I'm interested in all kinds of astronomy."
repeated

it is a very strange world when my terminal emulator program is taking up 1.2GB of memory.

4
2
1
repeated

Here's the latest hackerone issue I mentioned the other day: https://hackerone.com/reports/2871792 another one of those "we found a function call so therefore your program must be vulnerable".

Disclosed for educational purposes. Don't do this.

6
3
0
repeated

Fast conditional breakpoints via eBPF!?! Let's go! https://pernos.co/blog/linux-kernel-additions/

"With the new feature we contributed to 6.10 it's instead possible to filter the breakpoint hits in the kernel without ever trapping to rr or using ptrace. We can install a hardware breakpoint via the perf events subsystem and attach a BPF program to it that checks for matching register values and suppresses signals for those iterations that are not of interest."

1
3
0
[RSS] The fascinating security model of dark web marketplaces

https://boehs.org/node/dark-web-security
0
1
4
[RSS] Dependency Walker Rewrite

https://github.com/hfiref0x/WinDepends
0
0
0

ICP-Brasil issued cert for googgle[.]com

https://bugzilla.mozilla.org/show_bug.cgi?id=1934361

0
0
0
repeated

Got some negative or unrealistic threat model results that still bring interesting insights? A side channel that requires root to leak something from the kernel? Reproducing prior work? Somewhat related to microarchitecture? Here's your venue: uasc.cc

First edition is happening on February 19 in Bochum, the day before RuhrSec.
We accept submissions (papers, posters, talks) starting today and try to provide reviews within a 2 week time frame of submission.
Last Submission Deadline: January 27, 2025

0
4
0

stalld: unpatched fixed temporary file use and other issues

https://security.opensuse.org/2024/11/29/stalld-fixed-tmp-file.html

0
1
2

Linux: Race can lead to UAF in net/bluetooth/sco.c: sco_sock_connect()

https://seclists.org/oss-sec/2024/q4/130

What a mess:

“the reporter also did not reply to any of linux-distros’ members questions, most notably ‘have you contacted either security () kernel org or the bluetooth maintainers about this issue?’”

“the issue may be the same as CVE-2024-27398”

0
3
4

tuned: local root exploit in D-Bus method instance_create and other issues in tuned >= 2.23 (CVE-2024-52336, CVE-2024-52337)

https://seclists.org/oss-sec/2024/q4/127

0
3
5

⛧ SLEIGHER ⛧

2
0
3
repeated

NEW: The phones of the new NATO Secretary General Mark Rutte (including a hotline with the White House):
https://www.electrospaces.net/2024/12/the-phones-of-new-nato-secretary.html

1
2
0
repeated

The Archive has definitely hit the phase of "it works unless it doesn't, and then it will suddenly work". This is where the urge to just throw open what's left just to drop bug reports or complaints is high, but you just need to keep tracking things down. This was a quarter century codebase! It's beyond amazing it got this far, this fast. But every time I go back to work at my interfaces, the team has made them run better and better.

0
1
0
repeated

This was my tenth(!) year building 25 days of puzzles for . You can solve them all for free! Most people write code to solve them, but you can solve them however you like. I hope they help people become better programmers. 🌟

The first puzzle comes out in two hours: https://adventofcode.com/

6
4
0
repeated

The 2024 Economist Word of the Year:

“kakistocracy” - Government by the least qualified or most unprincipled citizens.

https://www.economist.com/culture/2024/11/29/the-economists-word-of-the-year-for-2024

0
4
0
Edited 4 months ago
test
Show content

This is a #test of frequency instruments.

Bass

Drums

Distortion

Artifacts

0
0
0
repeated
Edited 4 months ago
The computing I would like
Show content

After my recent experience with a new laptop, imposed upon me by a client, I feel the need to describe what I’d want from computing, both as a “practitioner” (“shaman”? “fool”?) and as a user.

First and foremost I like to know where my data is, both physically and logically.

I would, therefore, appreciate having some form of storage server which does everything from storing files to my calendar and email. It would be redundant, etc. (i.e. a NAS of some form).

Secondly, we’d have IPv6 so that I could reach said server from everywhere without NAT, CGNAT, transparent carrier-to-carrier NAT (you don’t want to know), etc.

Then, for those who have computing needs, we would have a co-system we would connect next to the NAS, automatically speaking some form of NFS (no, not SMB, not over my dead body) and which would be used automatically by the NAS when a request needed oomph (e.g. video editing on a stored video).

All of this would be topped with a beautiful “portable viewer” which would have a laptop size / format and would do nothing other than connect over the network to your server and allow you to “do things.”

A mobile phone would, similarly, tap into your server to do what it needs to do.

There would be minimal storage on these edge devices.

Wait, you say, this is “The Cloud”.

No, it is absolutely not because I want the data to be mine and nothing to be on the edge devices.

Wait, you say again, this is “Plan 9 meets VNC (in its original Olivetti Research Labs incarnation)”.

Yes, it is.

I still believe that one of the worst ever decisions to be taken was the PC back in 1981 followed by the obtusity of many in thinking that somehow PC “democratised” computing or could replace mainframes, minis and servers with its architecture.

Quoting “The 6M Dollar Man”: We can rebuild him; we have the technology.

We don’t need to continue using the crap they peddle us, we need to sit down and say “OK, now let’s be grown ups and build what we need, not what others want to us to build.” (note: 0xide is a step in that direction)

cm_2

2
2
1
repeated

I love programs with anti-debuger checks. By definition, the people you're "stopping" from debugging your program are the same ones who have the tools to delete your debugger check.

It's like specifically locking a door to keep lockpickers out

0
2
0
Edited 4 months ago

My friends at Ravenfortech wrote an introductory #malwareanalysis post on the INC #Ransomware:

https://translate.kagi.com/https://scribe.rip/@ravenfortech/inc-ransomware-elemz%C3%A9s-a909b5aed114

This gang recently pwned the Hungarian company responsible for military procurement (VBÜ) and now selling the data for $1M.

https://444.hu/2024/12/01/visszakerultek-a-netre-a-vedelmi-beszerzesi-ugynokseg-ellopott-adatai-egymillio-dollarrol-indul-a-licit

Based on the analysis the malware is very simple. INC uses 2023 CitrixBleed (2023) and spear phishing for initial access:

https://www.sentinelone.com/anthology/inc-ransom/

This doesn’t paint a picture of mature security at VBÜ to say the least…

1
3
5
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

I've started a page listing for many fields (physics, computing, biology, history..) the most Totemic Books. The ones that are central to the field, the books you wished you had learned about earlier. The work no one in a field can do without. Please send me your suggestions so we can share the love more broadly! https://berthub.eu/articles/posts/totemic-books-for-many-fields/

18
5
0
Show older