Posts
2974
Following
697
Followers
1545
"I'm interested in all kinds of astronomy."
repeated
Unfortunately the hv-vendor-id trick didn't work to make KDNET work over Proxmox, at least not by just setting the enlightenment in the cpu entry of the node's Proxmox config :(

https://infosec.place/notice/ArU6AdcfLlqQd1uAzY
0
0
0
repeated
repeated

Open Source Security mailing list

8 CVEs in X⁠.Org X server and Xwayland https://www.openwall.com/lists/oss-security/2025/02/25/1
CVE-2025-26594: Use-after-free of the root cursor
CVE-2025-26595: Buffer overflow in XkbVModMaskText()
CVE-2025-26596: Heap overflow in XkbWriteKeySyms()
CVE-2025-26597: Buffer overflow in XkbChangeTypesOfKey()

0
2
0
I think I should display this somewhere in a frame

https://youtu.be/My_13FXODdU?si=5l_PiCdfXbY3ohSx&t=540
1
2
4
repeated

The Best Security Is When We All Agree To Keep Everything Secret (Except The Secrets) - NAKIVO Backup & Replication (CVE-2024-48248) - watchTowr Labs https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/

0
3
0
repeated
Edited 9 months ago

There are numerous times where I think "if that person simply had better aim, the world would be so very different".

But then I remember that where we are right now globally is not down to one or two evil people - but the result of rot in many social, economic, and governmental systems. The people we think are making evil choices are avatars for the system, more than individuals.

We have to fix the systems.

EDIT: They're still evil assholes. I just mean they're replacable, not unique.

0
2
0
Computer History IBM 1130 System Engineering 1965

https://www.youtube.com/watch?v=SNqii4Hnu9A
0
0
0
[RSS] Pwn everything Bounce everywhere all at once (part 2)

http://blog.quarkslab.com/pwn-everything-bounce-everywhere-all-at-once-part-2.html

New pre-auth RCE exploit chains for old SOPlanning bugs #NoCVE
0
0
1
Edited 9 months ago
[RSS] Pwn everything Bounce everywhere all at once (part 1)

http://blog.quarkslab.com/pwn-everything-bounce-everywhere-all-at-once-part-1.html

Blast from the past: new, configuration independent exploitation method of CVE-2009-1151 (pre-auth RCE in phpMyAdmin)
0
0
1
repeated
repeated

Mildly amusing: this Aussie dude got fed up with people parking in his driveway so he installed a motion-activated sprinkler.

10
20
0
repeated
repeated

We found out that machines performed 7% better if we trapped them in an endless loop of profound existential anguish

2
6
0
This is a pretty good summary of #pentest as a profession:

https://www.reddit.com/r/Pentesting/comments/1ixoq2g/pentesting_is_the_hardest_cybersecurity/

(I don't think comparisons to other fields makes much sense though)
1
0
2
[RSS] Reverse Engineering PowerPoint's XML to Build a Slide Generator

https://merlinai.framer.website/blog/ppt-generator
0
0
1
Fediverse is protecting my mental health by not showing my own posts to me again
0
0
3
Look at this gem I just found:

Using WinDbg Over KDNet on QEMU-KVM

https://www.osr.com/blog/2021/10/05/using-windbg-over-kdnet-on-qemu-kvm/

"The enlightenments that are enabled by default include setting the hypervisor ID to the same ID that’s reported by Microsoft Hyper-V (which is “Microsoft Hv”). [...] when the KDNet transport initializes, it checks the hypervisor ID, and if it discovers it is running under Microsoft Hyper-V [...] it attempts to open a debugger connection using an undocumented protocol over a synthetic hypervisor-owned debug device that Hyper-V provides."

I'll give this a shot tomorrow on Proxmox and I'll drink something strong if modifying the hypervisor ID actually solves my issues! :D

#windbg #reverseengineering #proxmox #kvm
1
2
2
Show older