Posts
2570
Following
627
Followers
1397
"I'm interested in all kinds of astronomy."
Edited 26 days ago
As you probably know loadlibrary by @taviso can load Windows DLL's - including Windows Defenders mpengine.dll - on Linux.

Since the loader needed some debugging I ended up figuring out how to load the Linux-native mpclient into #Ghidra's debugger and use it to debug the PE module too:

https://github.com/v-p-b/loadlibrary/blob/x64_waffle/GHIDRA.md

This can spare an IDA license and performing dark arts with awk and gas...which is actually pretty badass, so if you want to keep doing that without IDA here's a Ghidra script too:

https://gist.github.com/v-p-b/c7d934234297158047b678f655c7d99f
3
9
24
CVE-2025-30232 Exim use-after-free can potentially lead to privilege escalation

https://exim.org/static/doc/security/CVE-2025-30232.txt

(was ZDI-CAN-26250)
0
0
1
repeated

Day 421. Following up on the no longer available sustainability fact sheets of data centers from day 420, we have added those that we know of to the Internet Archive.

See https://pastebin.com/5f0dFRqZ

0
3
0
repeated
bisecting will continue until morale improves
0
2
0
repeated
while reverse engineering, the eternal question of

"am i misunderstanding what the code is doing or is whoever wrote this really fucking stupid"
8
11
1
repeated

The AI bots that desperately need OSS for code training, are now slowly killing OSS by overloading every site.

The curl website is now at 77TB/month, or 8GB every five minutes.

https://arstechnica.com/ai/2025/03/devs-say-ai-crawlers-dominate-traffic-forcing-blocks-on-entire-countries/

23
29
0
repeated

You can help by testing this final release candidate, rc3, before the real release happens next week:

https://curl.se/rc/

0
2
0
repeated

an ominous I-am-under-NDA-coded warning to immediately uninstall atop has been posted by a reputable tech blogger. https://rachelbythebay.com/w/2025/03/25/atop/

10
17
0
[RSS] Inside Windows' Default Browser Protection

https://binary.ninja/2025/03/25/default-browser-upcd.html
0
0
1
[RSS] CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)

https://starlabs.sg/blog/2025/03-cimfs-crashing-in-memory-finding-system-kernel-edition/
0
0
0
repeated

"Is that free as in beer, or free as in freedom?"

"It's free as in use-after."

2
13
0
repeated

https://www.andrea-allievi.com/blog/a-minikvm-to-rule-all-machines-remotely/ Finally after hours and hours of assembling a YouTube video... MiniKvm 1.0 is there :-) Have fun and let me know if you find it useful...

0
3
0
repeated

David Chisnall (*Now with 50% more sarcasm!*)

When I was a student, I read a lot about how Silicon Valley companies were looking for 'problem solvers' rather than people with experience with specific technologies. At the time, this struck me as odd because problem solvers are not rare. Most people can solve a problem if you explain it to them. Indeed, the lesson from most of the formal verification classes was that a sufficiently detailed description of a problem is indistinguishable from a solution to that problem.

The real rare skill is working out which problems are the right ones to solve. Without that, you keep falling down dead-end rabbit holes and chasing local optima.

Everything I've seen in the last decade or so indicates what happens when problem solvers end up in senior leadership positions. You get companies that are great at solving completely the wrong problems.

0
8
0
repeated

This is outrageous. Where are the armed men who come in to take the spammers away? Where are they? This kind of behavior is never tolerated in Cascadia. You phish like that they put you in jail. Right away. No trial, no nothing. Cloudflare sites, we have a special jail for Cloudflare sites. You use QR codes: right to jail. You are domain squatting: right to jail, right away. Too many URL parameters: jail. Too few: jail. You are asking for gift cards, Monero, Bitcoin: you right to jail. You text a journalist? Believe it or not, jail. You receive a text, also jail. Send, receive. You use a hyphen in your domain name, believe it or not, jail, right away. We have the best users in the world because of jail.

3
3
0
repeated

smbfs is a fuck

2
2
0
repeated
Edited 26 days ago

Please remember that what you see on social media is what people choose to present, not an accurate representation of their life. Few people post about the horror.

Don't put off seeing friends because "they're having fun" or "they're busy" and "you'll see them later". You do not know that any of these things are true.

0
6
0
repeated
repeated
repeated

I probably sound like a broken record at this point, but we're not sold yet on the world-ending nature of Next.js CVE-2025-29927.

The fact that the bug isn't known to have been successfully exploited in the wild despite the huge amount of media and industry attention it’s received sure feels like a reasonable early indicator that it's unlikely to be broadly exploitable (classic framework vuln), and may not have any easily identifiable remote attack vectors at all.

https://www.rapid7.com/blog/post/2025/03/25/etr-notable-vulnerabilities-in-next-js-cve-2025-29927/

1
2
1
Show older