Posts
3915
Following
728
Followers
1601
"I'm interested in all kinds of astronomy."
Has anyone set up kernel debugging with a Windows 11 target with Proxmox (QEMU-KVM)?

This only works with Win10, Win11 doesn't boot for me:

https://forum.proxmox.com/threads/windbg-remote-kernel-debugging-and-proxmox-not-working.163625/

Serial would also be an option if I could make them recognized by guests:

https://forum.proxmox.com/threads/two-windows-guests-communicating-via-serial-console-comn.67588/
0
1
1
repeated

Beating the kCTF PoW with AVX512IFMA for $51k

https://anemato.de/blog/kctf-vdf

0
3
0
A casual player finds a memory corruption in Super Mario allowing arbitrary code execution and speedrunners exploit it *by hand* to warp to the credits screen.

https://www.youtube.com/watch?v=WdadpHLAfdA

#GameHacking is really something else!
0
6
9
repeated

yossarian (1.3.6.1.4.1.55738)

npm is getting trusted publishing soon!

https://github.com/orgs/community/discussions/161015

helping build and design the original version of trusted publishing for PyPI is easily in the top 3 moments of my career so far -- it's really amazing to see it get adopted by RubyGems, Rust (in progress), and now the JS ecosystem.

0
5
0
Had to make a proper GIF of this
0
0
0
repeated

Every time I lock my bike to a wall loop I fear a topologist will appear and prove my bike is not attached to the loop, or in fact, not even locked

5
11
0
repeated
Edited 11 months ago

Hot take: ISO standards do not meaningfully matter to me, because an extremely impoverished, unbanked person cannot freely access their contents from a smartphone or library computer.

Therefore, I go out of my way to avoid referring to them or relying on them in anyway.

15
8
0
repeated

Edge group policy ADMX is truly a masterpiece of bad-faith fuckery even by Microsoft standards: misleading, obfuscation, omission, outright lying.

Top 3 favorites so far:
1. Setting to disable the ChatGPT sidebar is called "Show Hubs Sidebar". Obviously, it is not under the "Generational AI" subfolder.
2. There are a number of "AI assistance" settings tucked under Settings > Languages in the UI. "Collaborate with Copilot" doesn't have a GPO item (forum answer from MS droid suggests that someone "forgot" it).
3. Three separate settings to prevent Edge from running in the background and "preloading" things, in three different folders.

2
4
0
[RSS] Achieving Persistent Client-Side Attacks with a Single WeChat Message

https://www.darknavy.org/blog/achieving_persistent_client_side_attacks_with_a_single_wechat_message/
0
0
1
[oss-security] CVE-2025-48734: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default

https://www.openwall.com/lists/oss-security/2025/05/28/6

I wonder if the now restricted behavior is useful for #deserialization gadgets (I couldn't find references to declaredClass abuse, but haven't finished my coffee yet either...)?
0
0
1
[oss-security]

CVE-2025-46701: Apache Tomcat: Security constraint bypass for CGI scripts

https://www.openwall.com/lists/oss-security/2025/05/29/4

I think "GCI" is a typo in the message (CGIServlet.java is patched), although found the same typo elsewhere in the documentation...
0
0
2
repeated

Decomplexification - making use simpler code

https://daniel.haxx.se/blog/2025/05/29/decomplexification/

3
3
0
repeated

The more mental energy you expend parsing a programming language's syntax, the less you have available for parsing a program's logic—or creating it yourself. This is why core fluency is so important; it frees up your own compute cycles for more important work.

It's also another reason why "vibe coding" is so toxic. It robs you of the opportunity to gain that fluency.

1
4
1
"[Qualys] discovered a vulnerability in apport [...], and a similar vulnerability in systemd-coredump [...]: a race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump"

https://www.openwall.com/lists/oss-security/2025/05/29/3

CVE-2025-5054 CVE-2025-4598
0
7
5
repeated

Google’s search quality has declined, filled with spam and low-quality results, while it maintains dominance through default placements. Cory Doctorow highlights Kagi as a superior alternative, offering cleaner, more relevant search outcomes. Though it requires a subscription, Kagi provides a user-focused experience that recaptures the efficiency Google once had.

I personally HAPPILY pay for @kagihq.

https://pluralistic.net/2024/04/04/teach-me-how-to-shruggie/#kagi

0
3
0
repeated
New assessment for topic: CVE-2025-41232

Topic description: "Spring Security Aspects may not correctly locate method security annotations on private methods ..."

"On May 19 2025, Spring released an [advisory](https://spring.io/security/cve-2025-41232) warning that Spring Security versions before `6.4.6` were vulnerable to a flaw in how Spring security annotations were identified and processed, that could lead to annotations being ignored on private methods, potentially leading to authorization bypasses on those private methods ..."

Link: https://attackerkb.com/assessments/c3734c78-c018-4e5f-9c70-b5f3c074a411
0
1
0
Show older