Posts
2524
Following
646
Followers
1461
"I'm interested in all kinds of astronomy."
I updated the generated #Ghidra documentation I host for 11.4:

https://scrapco.de/ghidra_docs/

Here's the documentation for Decompiler Taint Operations:

https://scrapco.de/ghidra_docs/Features/DecompilerDependent/DecompilerTaint/DecompilerTaint.html
0
0
1
#Ghidra 11.4 released with support for (external) taint engines in the decompiler:

https://github.com/NationalSecurityAgency/ghidra/releases/tag/Ghidra_11.4_build
1
4
7
repeated

📢 @ERNW is preparing the venue for tomorrow's launch of in ! See you soon people! We are super excited! 🥳

0
3
1
[RSS] Abusing copyright strings to trick software into thinking it's running on your competitor's PC

https://devblogs.microsoft.com/oldnewthing/20250624-00/?p=111299

#warez
0
0
3
repeated
repeated

VSCode のターミナルも Sixel 対応してたのか (terminal.integrated.experimentalImageSupport を有効にすると表示される)

0
1
0
repeated

"We will respond to you in 5 days"

3 weeks later... No response.

Anyone who gets mad at people for going full disclosure has never had to deal with the bureaucratic maze of trying to get people to fix their things.

1
5
0
repeated
Edited 9 days ago

PSA: The new version of our browser extension now requires additional permissions to "change your privacy-related settings".

The new permissions are required so we can set KeePassXC as your default password manager backend. Unfortunately, there isn't a better name for this permission set.

6
4
0
repeated

Remote code execution in CentOS Web Panel - CVE-2025-48703 https://fenrisk.com/rce-centos-webpanel

0
3
0
repeated

yyzkevin.ca has been working on making the first emulator to work with the odd IBM AS/400 drive standard. Here's his AS/400 booting IPL'ing with a BlueSCSI!

Still a lot to do but now even AS/400 users can have a modern, fully opensource, storage solution.

https://youtu.be/J8GztrUvox8?si=mpY88vrSCqVwUFvs&t=608

0
3
0
As they say, Hungarian Railways have 5 enemies: the four seasons and the passengers.

This summer started off esp. bad, while official online services allowing the tracking of delays suspiciously started to disappear.

Train enthusiasts however built an unofficial website that showed accurate info about the position and delays of the trains based on scraped data.

Then the Minister of Transportation accused these guys of phishing (he pbbly doesn't know what that means), DoS and of course conspiring the opposition party, so the site was voluntarily taken down...

...but the code is open source, so now we have multiple sites with the same functionality :D

https://github.com/iben12/holavonat

#Hungary #StreisandEffect
3
8
8
repeated
Edited 9 days ago

Pre-auth RCE in CentOS Web Panel (CVE-2025-48703) found by the friends at Fenrisk. This is beyond madness that Shodan finds 200k of these exposed publicly.

(this post is sponsored by strace®, because no one cares about ionCube)

https://fenrisk.com/rce-centos-webpanel

0
3
0
repeated

Finally published today the second blog I'd promised for the 11.4.81 CBE release last month:
https://blogs.oracle.com/solaris/post/whats-new-in-the-solaris-modular-debugger-mdb-in-the-oracle-solaris-11481-cbe

A very deep dive into a narrow topic - what's changed in the Solaris Modular Debugger (mdb) since the previous CBE release in 2022. @cgerhard and others have put an impressive amount of work into making debugging easier and better for the users of this tool.

0
2
0
repeated

Hat tip to thegrugq for featuring this in his newsletter, a 1991 video of Italian hackers purporting to show them hacking a U.S. military system over x25. Has a real gonzo Max Headroom broadcast signal intrusion vibe with the masks & just general weird vibes, love it.
https://www.youtube.com/watch?v=43FyQlaA6YY

2
8
0
repeated

Dear Fedi,

For 3 years, I've been working with friends from the world as a team of freelancers and it's been great: we love what we do and our clients are happy and stay with us for years.

But the terrible state of the world has badly affected our clients financially, and we find ourselves suddenly in need of more

We focus on systems design, development, and administration. We offer SRE-level quality and processes for companies that cannot afford a whole team

Boosts welcomed

0
4
0
[RSS] You have to tell Get- and Set-Security-Info the object type, you can't make it guess

https://devblogs.microsoft.com/oldnewthing/20250618-00/?p=111281
0
0
0
The trick with making your morning coffee is that you have to manage to make your morning coffee before having your morning coffee
1
1
6
repeated

Misfile essential documents.

0
2
0
repeated
@InfoCon Is Off-by-One Conf on your radar already?

https://www.youtube.com/@offbyoneconf
2
0
0
Show older