Thomas

493 posts

Thomas

Thomas

@_twvd

Cyber Security

Europe Katılım Aralık 2016
447 Takip Edilen87 Takipçiler
HODLmars
HODLmars@HODLmars·
@hakluke Already patched on all my machines 💪 Because this is Linux/FreeBSD only household.
English
2
0
31
14.9K
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
Ouch. The Windows Wi-Fi driver can be exploited by an attacker that is within Wi-Fi range. It requires no interaction from the victim and no prior knowledge of the system from the attacker. Just like the movies! It affects all modern versions of Windows. Patch immediately! 👇
English
35
597
2.9K
493.2K
Thomas
Thomas@_twvd·
@ModernVintageG Why not make it public, so anyone can take a stab at it?
English
1
0
1
456
MVG
MVG@ModernVintageG·
Thank you everyone, i got a few contacts now. Will update. Yes this will be available for everyone once/if we get it running - i don't hoard prototypes.
English
4
9
400
20.4K
MVG
MVG@ModernVintageG·
I've come across a potential interesting N64 prototype find - however the rom in question does not boot on emulators/real hardware. I'm looking for someone who has experience with N64 reverse engineering/rom/binary hacking to see if they can bring this to life so we can preserve this. DM if you can help!
English
29
76
911
88K
Ken Shirriff
Ken Shirriff@kenshirriff·
A pad on the Intel 386 processor. This nice pattern appeared while I was stripping off the layers for analysis. The colors are due to the varying thickness of oxide causing thin-film interference.
Ken Shirriff tweet media
English
13
33
456
31.7K
Thomas
Thomas@_twvd·
@wdormann Remember also CVE-2022-23088? Lack of KASLR made exploiting that remotely a breeze :)
English
0
0
1
428
Brad Spengler
Brad Spengler@spendergrsec·
I think in some years people will come around to two things: 1) KASLR is indefensible 2) The KERNSEAL approach is a much more pragmatic/reliable way of dealing with the impact of speculative execution vulns, by removing the data from reach of exploits, speculative or not.
English
2
0
7
770
Brad Spengler
Brad Spengler@spendergrsec·
EFI compat with KERNSEAL working today 😀
English
1
0
6
1.6K
Thomas
Thomas@_twvd·
@tha_rami Have you seen the GPD Win 4? :)
English
0
0
0
670
Thomas
Thomas@_twvd·
@awesomekling You should start writing your own vector icon editor really :)
English
1
0
1
182
Andreas Kling
Andreas Kling@awesomekling·
I'm currently in the "watching Inkscape tutorials" stage of yak shaving 🦬🪒 I just need to draw a couple of vector icons, how hard can it be.. 😅
English
7
0
53
5.8K
Thomas
Thomas@_twvd·
@0xgaut Dude check out this awesome game Attached: tetris.lnk
English
0
0
0
1.4K
Thomas
Thomas@_twvd·
@dvyukov Why.. is the kernel parsing strings from it's own userland interfaces, generated from its own internal structures?
English
1
0
1
131
Dmitry Vyukov
Dmitry Vyukov@dvyukov·
An interesting twist on this wide spread bug is that #Linux kernel itself mis-parses own /proc/pid/stat output: #L48" target="_blank" rel="nofollow noopener">elixir.bootlin.com/linux/v6.3/sou… #L86" target="_blank" rel="nofollow noopener">elixir.bootlin.com/linux/v6.3/sou…
Dmitry Vyukov@dvyukov

99% of /proc/pid/stat parsing code is buggy. It splits by space, but 2nd field is exe name which may contain space: Bugs are everywhere: OpenJDK, qemu, BoehmGC, containers/sandboxes; same bug in C/C++/Java/Go/Py/JS/Rust, ~every hit: sourcegraph.com/search?q=conte… Fix: strrchr(')') first

English
1
6
40
10K
Thomas
Thomas@_twvd·
@yarden_shafir It is usually buried beneath 20 layers of abstraction
English
0
0
1
523
Yarden Shafir
Yarden Shafir@yarden_shafir·
I love how all offensive Windows people pwn win32k constantly but none of us know how to create a reasonable looking window
English
7
12
104
22.3K
Thomas
Thomas@_twvd·
@vzverovich Rust is even simpler: everything throws a compiler error
English
0
0
0
37
Thomas
Thomas@_twvd·
@vzverovich C++ committee now exhibiting undefined behaviour
English
2
1
6
162
https://mastodon.social/@vitaut
BREAKING: An unsuccessful attempt to replace motions with moves left the C++ committee in an unspecified state.
English
3
1
67
3.9K
Maarten Boone 🇪🇺🇺🇦
Maarten Boone 🇪🇺🇺🇦@staatsgeheim·
Folie op raam geplakt tegen de warmte.... links is met folie en rechts zonder. Dit zou je logischer wijs Andersom verwachten 🤪🤔🤷‍♂️
Maarten Boone 🇪🇺🇺🇦 tweet mediaMaarten Boone 🇪🇺🇺🇦 tweet media
Nederlands
14
0
9
5.7K
Thomas
Thomas@_twvd·
@vzverovich Their ability to confuse beginners once they get to the left-shift operator
English
0
0
2
112
Thomas
Thomas@_twvd·
@awesomekling Ken's blog is a true engineering treasure trove
English
0
0
1
108
Andreas Kling
Andreas Kling@awesomekling·
Fascinating thread about how 8086 instructions were implemented. If I didn't already have multiple huge projects going in parallel, a microcode-level x86 emulator could be fun to tinker with.. 🤓
Ken Shirriff@kenshirriff

The Intel 8086 microprocessor (1978) led to the x86 architecture that your computer probably runs today. The 8086 provided a complicated set of memory access modes to get values from memory. Let's take a close look at how microcode and hardware work together to implement them. 🧵

English
3
1
71
11.4K