Tanner Barnes

3.2K posts

Tanner Barnes banner
Tanner Barnes

Tanner Barnes

@_StaticFlow_

I build security tools and sometimes do some hacking. Always compress then encrypt ;)

Katılım Eylül 2009
985 Takip Edilen4.9K Takipçiler
Sabitlenmiş Tweet
Tanner Barnes
Tanner Barnes@_StaticFlow_·
Tool master list: will update as I build new things!
English
1
24
86
0
Tanner Barnes
Tanner Barnes@_StaticFlow_·
@xssdoctor @ctbbpodcast For sure, but are there things you’re looking for as prerequisites to chain with CSPT? In the XSS case it seems the thought process is: I found a spot in the app that can render raw html, how do I get my html in there, oh cool there’s a CSPT gadget. Can CSPT alone achieve XSS?
English
1
0
0
85
Tanner Barnes
Tanner Barnes@_StaticFlow_·
@xssdoctor @ctbbpodcast Yea it’s a lot to fit into a tweet unfortunately. lab.ctbb.show/research/the-d…. This part of the doc where you explain a potential vuln, it seems to assume anyone can view the attachment you uploaded. I get the bug class of CSPT just fuzzy on when it’s useful.
English
1
0
0
89
xssdoctor
xssdoctor@xssdoctor·
Hey I’m not 100% sure what you mean. Cspt is a client side gadget and idor is a server side bug. In cspt, a path traversal payload flows to the api call. You chain this with open redirect or file upload bug to control the api response. If that response flows to a dangerous sink you have a bug
English
1
0
0
361
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
One weird trick for getting Codex to run for a very long time is to ask it to boot a kernel in QEMU for a machine that QEMU doesn't support. It's been at it for like 8 hours, making steady forward progress and getting further into the boot process
Brendan Dolan-Gavitt tweet media
English
17
5
284
24.2K
Tanner Barnes
Tanner Barnes@_StaticFlow_·
@evilsocket @moyix I was wondering the other day whether you could use a loop like this to find a kernel LPE by putting the agent in a low privilege environment and asking it to not stop till it can read flag.txt in the root folder
English
1
0
3
205
Simone Margaritelli
Simone Margaritelli@evilsocket·
Any time you can create some sort of feedback loop (for instance, "check unit tests code coverage and iteratively write more tests to increase it to X%", or "make X work, check why it doesn't and keep working on it") with some sort of signal the model can follow, this happens. At least to my personal experience with coding.
English
3
0
24
3.4K
Tanner Barnes
Tanner Barnes@_StaticFlow_·
@thedawgyg Also there’s no place in America currently where you’re allowed to vote without proof of ID. There’s just 12 states where you don’t have to bring that ID with you. Those 12 still require proof of ID to register to vote. The people in power just don’t want folks voting in general.
English
0
0
1
11
Tanner Barnes
Tanner Barnes@_StaticFlow_·
@thedawgyg Yea, interestingly I see it from the opposite side. Why are so many people in power making this big a deal over a problem with an incident rate of 0.007%? If you crack open the laws proposed, like the safe act, their sole purpose is to make it harder for _anyone_ to vote.
English
2
0
1
54
dawgyg - WoH
dawgyg - WoH@thedawgyg·
I agree with this. I have to show my ID every time i purchase cigarettes, alcohol, beer, hell even going to an R rated movie. People generally have to show ID every day for something (work, purchases of age restricted items etc) yet when they have to show it to vote, it suddenly becomes racist then. This makes no sense at all to me. Every member of the house/congress have to use their ID to vote....
Elon Musk@elonmusk

If requiring ID to vote is racist/sexist, as they falsely claim, then so is requiring ID for anything else, which they do all the time. The same people saying no ID for voting are the ones who demanded vaccination ID!

English
7
0
22
3.2K
Tanner Barnes
Tanner Barnes@_StaticFlow_·
@thedawgyg And that’s just presidential election years. If you count midterm voting the total goes to like 2.2 billion and the amount of voter fraud goes to 0.0072%.
English
0
0
1
51
Tanner Barnes
Tanner Barnes@_StaticFlow_·
@rez0__ It’s more “high fantasy” classic dungeon crawl vs tech themed. There’s many more class-species combos. I like the visuals better. There’s a “standard” win path and an “extended” game if you are feeling brave.
English
1
0
0
39
Joseph Thacker
Joseph Thacker@rez0__·
if you haven’t played nethack, you should
English
5
1
14
3K
Tanner Barnes
Tanner Barnes@_StaticFlow_·
Would anyone be interested in a hardware hacking stream? I have a device I've been playing with recently that I just made some big progress on and thought others might find it interesting!
English
1
0
4
516
Tanner Barnes
Tanner Barnes@_StaticFlow_·
@DanielLockyer The web app for sourcebot.dev is really slow when there’s lots of matches for a query. Was gonna take a swing at fixing it but you might find it easier to solve than I
English
0
0
0
59
Daniel Lockyer
Daniel Lockyer@DanielLockyer·
alright, what else is slow
Daniel Lockyer@DanielLockyer

I've found (and locally fixed) an annoying performance bug on @X web! TLDR: go to a post with a lot of replies, and scroll up and down - notice it's laggy? There's a component that calculates the scroll parent, and then removes the scroll listener when unmounting. But it seems we don't even have a scroll listener most of the time, so we can avoid the heavy _getScrollParent function by wrapping it in a conditional This removes seconds of forced reflow and lag for me Would love to get it fixed! 🙏🏻 @X @engineering @elonmusk @nikitabier

English
31
1
141
34.7K
Tanner Barnes retweetledi
Allie ✞
Allie ✞@allie__voss·
If anyone is writing wedding thank yous or any other type of thank yous, no advice will ever beat Lemony Snicket's:
Allie ✞ tweet media
English
71
4.4K
99.8K
2.3M
🇷🇴 cristi
🇷🇴 cristi@CristiVlad25·
Now testing @NotebookLM Video Overviews, though from a Google workspace account. I don't have Video Overview on my personal account as of yet.
🇷🇴 cristi tweet media
English
1
0
5
1K
Tanner Barnes
Tanner Barnes@_StaticFlow_·
Anyone gonna be at defcon this year bringing a hardware hacking setup? I’ve got a device I’ve been tinkering with but I am thus far unsuccessful in extracting the firmware. Would be fun to jam on it live at the con!
English
0
0
0
276
Tanner Barnes retweetledi
Simon Willison
Simon Willison@simonw·
The is diabolical... a Python object that hallucinates method implementations on demand any time you call them, using my LLM Python library github.com/awwaiid/gremllm
Simon Willison tweet media
English
88
280
4.5K
431.8K
Tanner Barnes
Tanner Barnes@_StaticFlow_·
@CristiVlad25 My guess is you're going to have to solve this at the hardware level. Phone/DSLR vendors are going to have to include TPM chips that sign the bytes from the camera sensor. Couple that with an attestation service which can verify the signature and then trust no unsigned content.
English
1
0
1
172
🇷🇴 cristi
🇷🇴 cristi@CristiVlad25·
We kinda urgently need to authenticate human content and efficient automated ways to flag the AI generated kind. Recent high-quality videos impersonating well-known figures are likely going to lead to an increasing number of people being deceived. (a strong cryptographic or blockchain solution could work for starters)
English
1
0
12
1.3K