Sabitlenmiş Tweet
Bonus
216 posts

Bonus
@BonusPlay3
programming & hardware & security 🦆 Pretending I know what I'm doing at @stm_cyber. Playing CTFs for @p4_team.
Poland Katılım Mayıs 2012
520 Takip Edilen442 Takipçiler

@FrankOverF1ow Selinux adds access control limiting access to objects even if you change your user, but not your context. If you want to test your poc against something that could prevent it, give @lkrg_org a try.
English

On Fedora, both SELinux and RANDOM_KMALLOC_CACHE are enabled but neither stopped this (>70% success)
Writeup soon...
drivertom@drivertomtt
Hunting Linux kernel 0day with @FrankOverF1ow 5 days, from zero to stable privilege escalation. sha256: 2189d5b196f33d512d8d02c6f00d26f4c10bf79ba1f0ac389d6663e026aebbe8
English

@layle_ctf Cool. What are the advantages over sleigh (other than usable build via cargo)?
English
Bonus retweetledi

‼️At the end of last year, there was a series of coordinated attacks in Polish cyberspace.
📌Today, our team is publishing a report describing the technical analysis of these events. We show the scheme of operation and the tools used by the attackers.
➡️cert.pl/uploads/docs/C…

English

@awawawhoami Wow CCC FOMO hitting harder and harder, chose the wrong year not to attend 😭
English

this is going to be crazy btw.
lexi <img src=x onerror=alert(1)>@1lexxi
gpg dot fail, 2025-12-27, 39c3
English

@matiasgoldberg @telxius They just ignore some of your ICMP requests. Event if there are 5 more hops that don't respond what's important is that last hop (target) responds and gets all the packets. You have 0 packet loss to the target, so that's not the reason for your issues.
English

Why is 90% packet loss coming from an IP owned by @telxius ?
I want to play Genshin Impact but I keep getting huge issues.

English

Public blog post:
opensource.googleblog.com/2025/11/announ…
Source: github.com/google/magika
English

@BonusPlay3 @S1r1u5_ And vendors can have very flawed models of distributing patches — updates are a complex problem and rise costs. Even if that's the case, it's still not a reason to keep users/clients/potential clients in the dark about the product defect for a long (e.g. a year) period of time.
English

@gynvael @S1r1u5_ It would be nice to get them fixed+deployed in a year. But honestly I don't feel like I can demand anything from vendor. I'm just do security audits for my clients so that they can do risk modeling. Would you prefer if vendor made faulty patches during 90 days to satisfy clients?
English

@gynvael @S1r1u5_ Yes, they are aware, but as there are no patches they can't do much. Also, once you buy devices, you have little to no leverage over vendor, as worst you can do is not buy more, which you probably will do anyway, since you've already integrated your systems into their environment
English

@BonusPlay3 @S1r1u5_ Did the vendor notify its clients that there are known cybersecurity problems?
English

@S1r1u5_ I have vulnerabilities that were disclosed 2 years ago and are still not patched, because most attackers try to blow up/pull out an ATM instead of hacking into it. In that case, screaming "90 days" and going public doesn't help anyone (vendor, clients), except researchers ego.
English

@S1r1u5_ It all depends on the threat model. If it's a public facing web app? Sure, try to get vendor to patch ASAP. But for example, ATM/POS solution could require manual intervention in thousands of deployed units to get them patched. 90 days isn't realistic in that case.
English

@RueNahcMohr ???
Literally all you need is to grab an older quartus (web edition) and you can generate & program bitstream.
You can check "purpose" of the chip here: static6.arrow.com/aropdfconversi…
And a pinout for your exact fanout: cdrdv2-public.intel.com/676988/ep1c3t1…
English

@BonusPlay3 one does not just install and fpga program and start playing. I'm looking for the software to do a *particular* series of chip, the cyclone v1. Nobody, it seems, who does fpga stuff, ever talks about which fpga chips things are for, its like its implied its universal.
its not.
English

@RueNahcMohr Huh? What about:
#cyclone%C2%AEseries" target="_blank" rel="nofollow noopener">intel.com/content/www/us…
English

@BonusPlay3 part of the immediate issue is "what version supports the chip I have" which generally tends to not be published :/
English

@travisgoodspeed Consider purchasing dedicated capacitor discharging device for safety reasons.
English












