Shift

17.6K posts

Shift banner
Shift

Shift

@Shiftreduce

Katılım Haziran 2011
1.6K Takip Edilen2.5K Takipçiler
Brendan Dolan-Gavitt
Did you guys realize that it's now possible to just tell an agent "hey go grab this ICSE 2024 paper, get their artifact working, and then apply it to formally verify <my specific situation>" ?
English
11
11
119
11.1K
Manitcor
Manitcor@Manitcor·
i have a research set i build mostly from vibes right here 1. induct-research - reads, summarizes on a 15 point template 2. bilbilo and cite forward and back ref 3. 4 different indices updated At any time i can ask for something and have it quickly checked against the growing corpus and the internet. If anything new is found in the process I hoover it up. This process is very good at making slop into real work.
English
1
0
2
284
Shift
Shift@Shiftreduce·
We live in interesting times. Last month Linux patched a core uaf in the epoll subsystem, we rarely see these kind of bugs. As i like these kind of bugs, i wrote a few words about it here: guysrd.github.io
English
3
55
182
21K
Shift
Shift@Shiftreduce·
@C2IRIS at 50 you start organizing the parties and events.
English
0
0
2
276
IRIS C2
IRIS C2@C2IRIS·
One thing I’ve always found interesting about vulnerability research, is how it seems to almost always be very age-bounded. You will meet the occasional 15 year old all-star. But usually it takes several years of serious experience to reach Jedi levels. But you almost never meet a 50 year old who still churning out bugs day to day. People “age out” for a lot of difference reasons.
English
13
2
74
40.9K
Shift
Shift@Shiftreduce·
I tried working on this bug only without an infoleak and tried to turn it into a one shot universal root primitive but I did not succeed, I never managed to leak data. You can read the blog and see my attempts at exploiting this, i encourage anyone to try too.
English
0
0
6
588
Shift
Shift@Shiftreduce·
The race itself is pretty tight, but with the right IPI interrupts and some magic it is possible to take control of ep->refs or a mutex_unlock slowpath (providing u an arbitrary kfree primitive), there are other paths available for exploitation.
English
1
0
5
500
Layle
Layle@layle_ctf·
at family dinner, my dad (he's a nerd too) told me about a new emulator he downloaded... it was mine lol
English
19
274
17.8K
213.1K
Renwa
Renwa@RenwaX23·
"Dad, what was it like playing CTFs before AI?"
English
18
216
1.4K
95.9K
Markus Vervier
Markus Vervier@marver·
Running FastAPI or another python ASGI framework? Then patch Starlette now, chances are high it's in your supply chain! A host header parsing issue can lead to vulnerabilities leading from auth bypass up until RCE! Examples for affected packages are liteLLM, vllm, etc... Here is the X41 Advisory: x41-dsec.de/lab/advisories…
English
1
0
1
270
Shift
Shift@Shiftreduce·
@bl4sty this is hilarious :')
English
0
0
0
112
blasty
blasty@bl4sty·
im celebrating the release of the new openbsd but the usb rndis driver, extremely fragile! if someone walks up to your OpenBSD 7.9 thinkpad in starbucks tomorrow and tries to plug in a suspicious usb device into your daily driver whilst yelling "please run `ifconfig urndis0 up` as soon as possible! this is a matter of life and death!" don't fall for it, you've been warned.
blasty tweet media
OpenBSD@openbsd

OpenBSD 7.9 is out now! See what's new here: openbsd.org/79.html

English
7
25
149
22.3K
Shift retweetledi
Josh Terrill
Josh Terrill@joshterrill·
I broke Kindle's DRM protection tonight through a mix of static and dynamic analysis. AES key is derived from accountSecrets, kindle device ID, and voucher path. Book is decrypted in parts using OpenSSL from Ion blobs and then decompressed with LZMA.
Josh Terrill tweet media
English
25
229
2.3K
85.7K
NiNi
NiNi@terrynini38514·
It’s time to reveal our secret AI model which we’ve been using for years even back when the ChatGPT wasn’t a thing. Let me introduce you the top-secret model trained in Taiwan, It’s security-focused, fully automated, requires no prompting, and is ready to use out of the box. That is: OrangetsAI !
TrendAI Zero Day Initiative@thezdi

That's a wrap on Pwn2Own Berlin 2026! 🏆 $1,298,250 awarded. 47 unique 0-days. 3 days of absolute chaos. And talk about main character energy - congrats to DEVCORE for claiming Master of Pwn with 50.5 points and $505,000 - they never slowed down. See you next year! #Pwn2Own #P2OBerlin

English
10
16
309
28.7K