Posts
2432
Following
590
Followers
1309
A drunken debugger

Heretek of Silent Signal
repeated

My parents to me: Watch less TV, it'll rot your brain.

Me to my kid: Watch more TV, it'll rot / hijack your brain less than the competing alternatives.

1
2
1
repeated

An Open Letter to All European Politicians and Leaders to Abandon X/Twitter:

"By abandoning X/Twitter, leaders can reduce its credibility, promote fairer alternatives, and take a stand against the spread of disinformation, ensuring democratic principles are upheld."

H/T to @everton137 for organizing this - already close to 1,000 signatures:

https://www.openpetition.eu/petition/online/an-open-letter-to-all-european-politicians-and-leaders-to-abandon-x-twitter

2
11
0
repeated

Project Zero Bot

New Project Zero issue:

WebKit: use-after-free in DocumentFontLoader::fontLoadingTimerFired

https://project-zero.issues.chromium.org/issues/374377963

CVE-2024-54502
0
1
0
repeated

Project Zero Bot

New Project Zero issue:

inotify_rm_watch() race with umount() can lead to superblock-related UAF

https://project-zero.issues.chromium.org/issues/379667898

CVE-2024-53143
0
1
0
Edited 12 days ago
#hupol #mfa #vent
Show content
It seems Hungarian education is going so great that one teachers union (we have two of course...) felt that after years of doing nothing now it's time to issue an outraged communique about...

... having to switch to MFA on government portals.

My humble opinion is that these bureaucrats should be reassigned to the job of cleaning dog shit off the streets.

(FD: I have a loving family of teachers)
0
0
2
Lead-free solder is how EU kills innovation.
0
0
3
repeated

Fearsome File Formats by @Ange is a follow-up to Funky File Formats. He explores file fuzzing, hashquines and ways in which files can contain unexpected things (for example different files altogether!)

The Talk: https://media.ccc.de/v/38c3-fearsome-file-formats

The Previous Talk: https://media.ccc.de/v/31c3_-_5930_-_en_-_saal_6_-_201412291400_-_funky_file_formats_-_ange_albertini

0
4
0
The first actually useful desoldering tutorial I encountered:

https://youtu.be/Z38WsZFmq8E?feature=shared
0
2
7
repeated

Deleting any ad-supported apps you don't absolutely need is attack surface reduction. https://www.wired.com/story/gravy-location-data-app-leak-rtb/

3
9
0
repeated

In the aerospace world, a "flat sat" (https://www.esa.int/Enabling_Support/Space_Engineering_Technology/Opened-out_FlatSat_for_CubeSat_testing) is a development mockup of satellite splayed out on a bench with all the boards easily accessible for testing.

Is there a similar term of art for a spread-out functional prototype that's not a spacecraft? I feel like it should have a name but I'm not aware of one.

3
1
0
repeated

In my latest stream, I walked through the binaries of PoCorGTFO.
Not just pure hex analysis, I also covered a few challenging or fun facts along the way.
https://www.youtube.com/live/POg2Qpxbplk?si=oDBmmd1v9pMiRjMY

0
3
0
repeated

It's 2025 and the techbros are still out there with their AGI fantasies.

So Mystery AI Hype Theater 3000 will also still be here taking it all apart with ridicule as praxis.

@alex & I will kick off the new year by aiming that praxis at ARC, o3 and all things OpenAI:

Monday, Jan 13, noon Pacific
https://www.twitch.tv/dair_institute

1
5
0
repeated

Microsoft will force install the new Outlook email client on Windows 10 systems starting with next month's security update.

https://www.bleepingcomputer.com/news/microsoft/microsoft-to-force-install-new-outlook-on-windows-10-pcs-in-february/

2
5
0
repeated

A couple more critical TOCTOU RCEs here, this time from IBM: https://www.ibm.com/support/pages/node/7180636

IBM Engineering Requirements Management DOORS Next could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.

https://nvd.nist.gov/vuln/detail/CVE-2024-41787

IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.

https://nvd.nist.gov/vuln/detail/CVE-2024-41779

1
2
0
repeated

Currently working on adding comment-overlays to Function-Graph-Overview.

The idea is to add special begin- and end- comments, and use those to draw overlays on the graph (think C#'s region thingy).

I hope this will make the CFG more viable as a code-understanding tool, as we'll be able to better document our findings.

0
1
0
repeated

AI generated content in a nutshell

(Disclaimer: This has to be one of the worst videos I've ever watched... enjoy)

4
4
0
repeated
repeated

Reviving a Classic: The Journey to Reconstruct F-15 Strike Eagle II's Code

In a remarkable feat of reverse engineering, a hobbyist has successfully reconstructed the executable for the 1989 game F-15 Strike Eagle II, bringing nostalgia and technical prowess together. This mi...

https://news.lavx.hu/article/reviving-a-classic-the-journey-to-reconstruct-f-15-strike-eagle-ii-s-code

0
3
0
repeated

“Why don’t you take some of that ‘go to mars’ money and actually help rather than Monday morning quarterbacking during a live fire?”

The CEO of Watch Duty is bringing the energy that we need to 2025.

https://sfstandard.com/2025/01/09/wildfires-watch-duty-elon-musk-los-angeles/

1
8
0
repeated

Another take on AI that (at least for now) kinda nails it.

4
16
0
Show older