Posts
4278
Following
738
Followers
1632
"I'm interested in all kinds of astronomy."
@Framasoft it'd be so great if you'd set the default language of FramaForms Drupal to English...
0
0
0
Me: Let's use this well established OSS project again after several years!
Project: We're in Dependency Hell since last month, builds don't work...

Why is it always like this with me?? #fml
1
0
0
repeated

Call for Failures @ hack.lu 2025 — Because We All Break Things

At hack.lu, we love stories of brilliance — new tools, cutting-edge exploits, and clever defenses.
But let’s be honest: the best lessons often come from things that went spectacularly wrong.

That’s why we’re bringing back the Call for Failures (CFF) — a mini-conference inside hack.lu dedicated entirely to sharing the things that didn’t go as planned.

🗓️ When: Wednesday, 22 October 2025
🕖 Time: 19:00 – 21:00
📍 Where: At hack.lu, Luxembourg

🔗 https://2025.hack.lu/blog/hack.lu-call-for-failures-at-hack-lu/

2
5
0
TIL if you want to change the config of the logging module in PyGhidra you have to reastart #Ghidra for the new config to take effect...

Bonus: There is a predefined `writer` stream object that you can use to log to the GUI console.
0
0
1
repeated
1 hour of sleep, 2 energy drinks in.
I blame UEFI Forum for this akko_giggle
0
4
4
repeated

The official @Defcon recording of HTTP/1.1 Must Die has landed - join me on the mission to help kill HTTP/1.1! https://www.youtube.com/watch?v=PUCyExOr3sE

2
4
0
Edited 9 months ago
I'm looking for publicly available reverse engineered program databases (idb, gpr, bndb, ... ), preferably for relatively small programs.

Any tips?

#ReverseEngineering
3
7
4
repeated

Serious bugs often occur in third-party components integrated by other software. Ivan Fratric and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click.

Integrators should update today!

https://project-zero.issues.chromium.org/issues/428075495

0
9
0
repeated

Hi there! This is again!

Today I'd like to present you one of frequent sources of pain for C64 owners, the infamous PLA. This is MOS 7700R2. They failed way too often, and considering this is custom silicon, the only option was to get another one of the same.

Many thanks to @root42 for providing this sample!

SiPron link: https://siliconprawn.org/archive/doku.php?id=infosecdj:mos:7700r2

3
4
0
repeated

Project Zero Bot

New Project Zero issue:

Dolby Unified Decoder: Out of bounds write in evolution parsing

https://project-zero.issues.chromium.org/issues/428075495

CVE-2025-54957
0
2
1
repeated

How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked https://blog.pixelmelt.dev/kindle-web-drm/

0
2
0
repeated
Edited 9 months ago

My OBTS v8 slides for Apple Compressor (part of Final Cut Pro) unauthenticated LAN RCE. No CVE? Because it’s not patched…🫣

https://github.com/ChiChou/slides/blob/b737cc3037408221217d59c8fc6b8a82706b7062/Queen%20B%200-click%20RCE%20for%20Apple%20Compressor.pdf

0
6
0
"Which of course makes perfect sense when you are in the business of breaking stuff so people have to pay you for fixing it."

This is an old article, but this one sentence explains so many things!

https://dzone.com/articles/why-you-should-avoid-jsf
1
0
1
repeated

Inspirational Skeletor💀

1
19
0
[RSS] exploits.club Weekly Newsletter 89 - iOS GPU Driver Bugs, Kernel Stack UAFs, Hardware Wallet Auth Bypasses, and More

https://blog.exploits.club/exploits-club-weekly-newsletter-89-ios-gpu-driver-bugs-kernel-stack-uafs-hardware-wallet-auth-bypasses-and-more/
0
0
1
repeated

So this October 2025 F5 security notification is pretty wild because of the sheer volume of vulnerabilities disclosed: more than 30 high-severity CVEs (!) and around a dozen medium-severity ones in a single release cycle. This affects almost every F5 product family, BIG-IP (all modules), BIG-IP Next, F5OS, and related components. Something we don’t see very often... and a lot of these vulnerabilities score above 8.0; remote exploitation, denial-of-service or privilege escalation. Also, the number of affected software branches (from 15.x through 17.x) means most F5 deployments are touched in some way. YMMV.
In short, this quarter’s bulletin is probably F5’s heaviest security updates ever. If you run F5 products, patch now. https://my.f5.com/manage/s/article/K000156572

0
3
0
[RSS] I remember taking a screen shot of a video, and when I opened it in Paint, the video was playing in it! What witchcraft is this?

https://devblogs.microsoft.com/oldnewthing/20251014-00/?p=111681
1
1
5
Show older