ZwClose

636 posts

ZwClose

ZwClose

@zwclose

Beigetreten Haziran 2017
59 Folgt1.1K Follower
Angehefteter Tweet
ZwClose
ZwClose@zwclose·
Multiple vulnerabilities in the Realtek card reader driver. The vulns allow a non-privileged user to write to virtual kernel memory and gain access to physical memory via the DMA controller. Dell, Lenovo and other OEMs affected. The first part of the post: zwclose.github.io/2024/10/14/rts…
English
2
102
235
27.3K
ZwClose
ZwClose@zwclose·
When it comes to Windows kernel networking, ChatGPT becomes pretty hallucinatious. Once I spent an hour looking for a non-existent !wfp extension, which GPT recommended to me, and now it's suggesting !afd. By the way, these extensions would be very useful if they existed.
ZwClose tweet media
English
0
1
5
562
ZwClose
ZwClose@zwclose·
@HaifeiLi Yesterday I spent an hour searching for a WinDbg extension that doesn't seem to exist; I fell to Copilot's hallucination. I also watch the selloff, but I'm sure it will bounce back.
English
0
0
1
81
Haifei Li
Haifei Li@HaifeiLi·
Is vibe coding going to kill all the quality software companies or something? Most stocks 52 weeks low. Wow.
English
2
0
3
1.5K
ZwClose
ZwClose@zwclose·
@artem_i_baranov Considering Intel's recent performance, they either didn't read the Grove's book or it's not that helpful :)
English
0
0
1
61
ZwClose
ZwClose@zwclose·
Older WDKs are back! With each update Microsoft dropped pieces like code samples, so I hoarded a few WDKs, and even planned to search far corners of the web to get more. This is not needed anymore: MS just published a collection of legacy WDKs: learn.microsoft.com/en-us/windows-…
English
0
1
6
147
ZwClose
ZwClose@zwclose·
@yo_yo_yo_jbo This post is not only interesting, but also demonstrates that readme md can be a blogging platform.
English
1
0
0
92
ZwClose retweetet
Jonathan Bar Or (JBO) 🇮🇱🇺🇸🇺🇦
This blogpost is interesting - has Windows internals, my own novel solution to a problem red teamers have had for a while, EDR bypasses, debugging and much more. Spoofing command lines on Windows and solving the problem of length limitations: github.com/yo-yo-yo-jbo/c…
Jonathan Bar Or (JBO) 🇮🇱🇺🇸🇺🇦 tweet media
English
2
47
161
14.1K
ZwClose
ZwClose@zwclose·
@FuzzySec Hey, I have a conference-related question, may I dm?
English
0
0
1
65
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
I want to extend the same offer as I did for BlackHat US and make myself available to provide structural and language feedback on proposals from people that use English as a second language (ESL). From my own experience I know it's not always easy to navigate what a good proposal looks like and I'm here to help 🙇‍♂️
English
2
0
12
1.4K
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
After a successful BlackHat US with so many amazing talks, I'm excited to share that I am also joining BlackHat EU as a guest on the review board for the AI, Vulnerability Research and AppSec tracks 🎊❤️‍🔥 The CFP closes on the 11th of Aug, get submitting: europe-briefings-cfp.blackhat.com
GIF
English
5
2
76
7.7K
ZwClose
ZwClose@zwclose·
@DebugPrivilege @sixtyvividtails Maybe sixtyvividtails put it too harsh but I can see the point: it is unclear how storport mangles the pointer. I haven't looked at the dump myself, but it looks that 0x046dc232 often comes with nt!IovpValidateDO, Logitech and the verifier enabled, but with different bug checks.
English
0
0
1
75
ZwClose
ZwClose@zwclose·
@DebugPrivilege Nice RCA, and lots of useful debugging commands/extensions!
English
0
0
1
78
ZwClose
ZwClose@zwclose·
@lyq_sqsp Does the device do something DMA-related?
English
0
0
1
35
ZwClose
ZwClose@zwclose·
@vxunderground I'm devil's advocate. Users hated the new Windows 95 interface. MS didn't back down. A few years later, no one even thought about going back to 3.11. Although AI is much more intrusive than UI, let's see what users say in a while.
English
0
0
0
183
vx-underground
vx-underground@vxunderground·
Pavan Davuluri, Microsoft President who disabled comments when we (and everyone else) raised hell about Microsoft AI slop. Blah, blah, blah, you DO NOT listen to feedback or give a fuck about developers. You're lying. You keep shoving dog shit slop piss into the OS. Fuck Copilot Fuck Recall Fuck your Ads in the OS Fuck your AI developers Fuck Windows Defender Fuck your AI integrations Want to make people happy? Release a new version of Windows. I'm being completely serious - Windows slop fucking piece of shit edition - Windows with everything ripped out of it, no AI slop, no defender, no fancy UI. Make it Windows 7 or XP era UI. Even give it a dumb fuckin edgy name you guys like, like WINDOWS 11 DEVELOPER NANO CORE You'll have developers throwing money at your face begging for non slop edition
Pavan Davuluri@pavandavuluri

Hey Gergely, I am responding here, and I think this applies to a bunch of the comments that people have made. I mean, a lot of comments 🙂. The team (and I) take in a ton of feedback. We balance what we see in our product feedback systems with what we hear directly. They don’t always match, but both are important. I've read through the comments and see focus on things like reliability, performance, ease of use and more. But I want to spend a moment just on the point you are making, and I’ll boil it down, we care deeply about developers. We know we have work to do on the experience, both on the everyday usability, from inconsistent dialogs to power user experiences. When we meet as a team, we discuss these paint points and others in detail, because we want developers to choose Windows. We know words aren’t enough, it’s on us to continue improving and shipping. Would love to connect with you about what the team is doing to address these areas if you are open to it.

English
82
211
2.6K
187.1K
ZwClose retweetet
diversenok
diversenok@diversenok_zero·
I wanted to understand what information is available in .pdb files, so I made a tool for it 🔎🪲 Welcome DiaSymbolView - a debug symbol hierarchy and properties viewer based on MSDIA: github.com/diversenok/Dia…
diversenok tweet media
English
3
58
187
15K
ZwClose
ZwClose@zwclose·
I may be late to the party, but I didn't know about deepwiki.org, which looks really cool!
English
0
0
0
159
ZwClose
ZwClose@zwclose·
@PetrBenes @C5pider Why are you only counting unique annotations? I doubt you'll find 37,120 annotations by lifting uniqueness, but it's possible there will be more than 782.
English
1
0
0
88
Petr Beneš
Petr Beneš@PetrBenes·
@C5pider For a total of 37120 functions (+59372 methods in interfaces), yeah, I'd say only :)
English
1
0
1
203
Petr Beneš
Petr Beneš@PetrBenes·
In the whole Windows SDK there is only 782 unique SAL annotations. Thank you for your attention to this matter.
English
1
0
11
1.8K
ZwClose
ZwClose@zwclose·
@sixtyvividtails @_r_netsec 0xd2d28044 looks very weird, device code 0x2d2 doesn't belong to any constant from FILE_DEVICE_* list.
English
1
0
3
140
sixtyvividtails
sixtyvividtails@sixtyvividtails·
@_r_netsec Analysis doesn't check out. Claims fail is on ExFreePool, but callstack in all 3 dumps shows fail on ExAcquireFastMutex. There's indeed "elastic_endpoint_driver", but with just tiny minidumps we can't confirm it's not tainted. EP: DeviceIoControl(ioctl=0xd2d28044, inSize=0x41).
English
1
0
9
278
ZwClose
ZwClose@zwclose·
@ericgeller I really doubt it's Anthropic PR report but is does read as Anthropic PR report :) Anyway, the Remote workers fraud part is just as impressive as the Vibe data extortion!
English
0
0
5
667
Eric Geller
Eric Geller@ericgeller·
Anthropic says a hacker used its Claude chatbot "to an unprecedented degree": Claude identified vulnerable companies, wrote infostealer malware, analyzed stolen files for extortion purposes, calculated extortion amounts, and wrote extortion messages. nbcnews.com/tech/security/…
Eric Geller tweet mediaEric Geller tweet media
English
16
113
434
117.1K