固定されたツイート
SerHack
2K posts

SerHack
@serhack_
Security researcher – Author of Mastering Monero @masteringxmr – Writes about cryptocurrencies, information security and RE 🇮🇹 serhack on https://t.co/4LU2O4JgId
Italy 参加日 Ağustos 2017
477 フォロー中3.5K フォロワー

ccs.getmonero.org/proposals/vtne…
My new CCS is in funding!
Upcoming: LWSF /feed unit testing, investigate (indirect) block limits, and new lib for encrypting wallet data with FIDO2.
Done: LWS+F ready for fmcp++, LWS+F /feed implemented, monerolws.com, and Docker improvements.
English
SerHack がリツイート


@serhack_ hey just wanted to say I really enjoyed your article on the bitcoin genesis block and the reolink firmware analyses!
i stumbled upon your site while I was trying to figure something out for monero, but stayed for the rest of your blog.
any new articles on the way?🙏
English

@usgraphics The font on the backside looks amazing, any hints on what they used?
English
SerHack がリツイート

Bravo @serhack_! "Mastering Monero" has been featured in our list of best Monero books of all time! bookauthority.org/books/best-mon…
English

@serhack_ from great work comes a great amount of bestemmie
English

* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago.
* Full disclosure happening in less than 2 weeks (as agreed with devs).
* Still no CVE assigned (there should be at least 3, possibly 4, ideally 6).
* Still no working fix.
* Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot.
* Devs are still arguing about whether or not some of the issues have a security impact.
I've spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more.

English

@Azerpolious @Little_34306 Yes you have to put a generic xml data :) you could figure it out
English

@serhack_ @Little_34306 entitlements.xml: cannot read entitlement data
Català

@Azerpolious @Little_34306 Yes codesign --sign - --entitlements entitlements.xml --force libida.dylib
Català
SerHack がリツイート

To help preserve a safe Internet for content creators, we’ve just launched a brand new “easy button” to block all AI bots. It’s available for all customers, including those on our free tier. Read our blog post for more details: cfl.re/3RQYlxz
English

@evilsocket I can't believe it, most of the people that started with infosec long time ago they were playing with dSploit...
English

And now Amazon too!!! Funny, i'm not qualified as senior software engineer, or AI engineer, or defensive tech engineer even tho I spent the last 15+ years working on exactly that (some of them are actually using my code). Ages ago I developed one of the first WAFs before Cloudflare was even a thing (evilsentinel, in php, it was crap but visionary), Google scans Android apps for malware every single day with my code ... Amazon is working with technologies I have a patent for ... but I'm not qualified I guess! LOL how freaking disconnected is the hiring process from reality?
Simone Margaritelli@evilsocket
rejected by both Google and Cloudflare in less than 48h 🕺
English











