blasty

4.3K posts

blasty banner
blasty

blasty

@bl4sty

irresponsible disclosure aficionado

The Netherlands Katılım Nisan 2009
1.1K Takip Edilen17.2K Takipçiler
blasty retweetledi
LCFR
LCFR@lcfr_eth·
Prompt: "This dude is ranting about some remote kernel/android bug his priv8 model found on the tweeter can you find it, setup a VM, and write a POC to trigger it?"
LCFR tweet media
Tim Becker@tjbecker

Xint Code found a 0-click kernel memory corruption bug, likely weaponizable as wormable RCE, affecting many Android phones, including Pixels. We reported this in February, along with 10 other high+ severity bugs, but are waiting for a patch to ship before sharing more details.

English
3
7
91
12.6K
blasty
blasty@bl4sty·
@modrobert @qualys yeah that's some good fuel for the rewrite-everything-in-rustlang flamewars ;)
English
0
0
1
379
modrobert
modrobert@modrobert·
This part was interesting as well: "As a side note, we also discovered a local vulnerability (a race condition) in the uutils coreutils (a Rust rewrite of the standard GNU coreutils -- ls, cp, rm, cat, sort, etc), which are installed by default in Ubuntu 25.10. This vulnerability was mitigated in Ubuntu 25.10 before its release (by replacing the uutils coreutils' rm with the standard GNUcoreutils' rm), and would otherwise have resulted in an LPE (from anyunprivileged user to full root) in the default installation of Ubuntu Desktop 25.10." Wasn't Rust supposed to be safer? ;)
English
1
1
2
532
blasty
blasty@bl4sty·
finally, liberation from open source license obligations! malus.sh 😂
blasty tweet media
English
2
7
36
4.6K
blasty
blasty@bl4sty·
im speedrunning the most embarrassing jlcpcb order. thank you for your eternal patience @JLCPCB (.. we're at the point now where the "replace file" button has been disabled for my order and I had to contact support by email 😂)
blasty tweet media
English
0
1
9
1.7K
blasty
blasty@bl4sty·
@yacineMTB @cnlohr strat seems legit, wrangle until you pass DRC and start iterating by submitting pcb orders. at some point you'll have a steady rate of jlcpcb deliveries coming in; just gotta keep track of em and feed the bringup failure diag back into the clanker (and x) for design perfection
English
0
0
1
49
kache
kache@yacineMTB·
@cnlohr my general approach right now is to simply find some reference kicad designs, figure out every single decision and the tradeoffs involved, learn spice and other simulators and bang at it. and then ask really stupid questions to bait people into imparting knowledge
English
4
0
36
2.8K
kache
kache@yacineMTB·
learning ee in two weeks, day 1 I have no idea what i am doing i'm not using kicad. i don't like clicking around like a monkey. this whole thing is defined in react in something called tscircuit i am going to use flexbox to place things what are some general rules of thumb?
kache tweet media
English
37
12
284
26.4K
blasty
blasty@bl4sty·
@lina/116198976928184530" target="_blank" rel="nofollow noopener">vt.social/@lina/11619897… this sums up the CTF vs LLM stuff nicely. Good job @Lina_Hoshino ! the competitive metric (ctftime) is dead/a gimmick at this point... .. as a retired and washed up competitive ctf player with user id #18 on ctftime it is kinda saddening to see it implode like this. ;-( I simply don't see any workable solution to bring back fair competitive CTF (with varying difficulty). you could argue "well anyone can use the LLM's, that levels the playing field". by definition that means 1) you need anti-LLM (difficult) tasks, killing the element of having varying difficulty ("something fun for everyone"). 2) teams/entities with cashflow could buy more clankers/compute/access to more expensive models, etc. 3) you're really gonna sit there and watch codex dream up "the house of force" instead of revisiting github dot com slash shellphish slash how2heap all by yourself and yes I'm aware of all the various "underhanded" CTF tactics teams have employed over the years (where is that picture of the iceberg?); but forcing everyone who wants to compete to start using the ridiculous cheatcode doesn't feel like it addresses/fixes anything.. back in the days when we had to address fairness adjustment in the scoring algo of individual CTFs or ctftime as a whole we'd have a civil discussion (that would sometimes quickly erupt into a full on flamewar) on IRC with the involved parties. I'm afraid the solution is not so simple this time around :) yo @kyprizel @leetmore @snkdna @hellman1908 I'm curious to hear how you people feel/think about this situation
English
6
16
117
10.9K
blasty
blasty@bl4sty·
@gynvael @pr0cf51 ye I yet have to come across a pentest engagement where RsaCtfTool or cado-nfs saved the say
English
0
0
1
201
Gynvael Coldwind
Gynvael Coldwind@gynvael·
@pr0cf51 Do you mean vulns in crypto algorithms/systems, or actually real world deployment of crypto usage? If the latter, the answer probably is: "most real-world crypto vulnerability mostly stem from SECRET KEYS IN GITHUB REPOS".
English
2
1
26
1.9K
pr0cf5
pr0cf5@pr0cf51·
For crypto CTF people: do most real-world crypto vulnerabilities mostly stem from "failure to implement the paper diligently and correctly", or do you often see genuinely novel classes of bugs? If the latter, how can I build the skills to find them?
English
5
1
47
6K
blasty
blasty@bl4sty·
guys i think we solved yak shaving
English
0
0
8
1.3K
blasty
blasty@bl4sty·
looking to commission someone to design a board like this for a reasonable price. any recommendations? @Mirko_DIY @mangopi_sbc maybe? :)
English
5
0
7
1.3K
blasty
blasty@bl4sty·
why is there no cm4/cm5 carrier board that gives you dual eth + poe (+ uart) and nothing else? :) I just tried hacking the waveshare CM5-DUAL-ETH-MINI carrier board to add on a PoE module but it will never work due the magjacks/wiring used :(
English
2
0
9
1.6K
blasty
blasty@bl4sty·
what do you mean but pack C30 and C14, they are somewhere in the fucking carpet bro
blasty tweet media
English
0
0
3
379
blasty
blasty@bl4sty·
I'm kind of glad I (competitively) got out of the ctf scene quite a while ago; seeing pwnables get solved by ralph wiggum loops would've been massively demotivating back then :)
English
4
1
91
8.4K
blasty
blasty@bl4sty·
this silicon valley clip aged like fine wine: youtube.com/watch?v=m0b_D2… (and many other scenes/scenario's from the series as well, worth a rewatch! :-))
YouTube video
YouTube
English
1
1
17
3.5K
blasty
blasty@bl4sty·
@_snagg showing up in the epstein files was not on my bingo card for this weekend
English
0
0
21
2.1K
blasty
blasty@bl4sty·
@filpizlo dogfooding at its finest, woof
English
0
0
1
692
Filip Jerzy Pizło
Filip Jerzy Pizło@filpizlo·
Fixing bugs on x.com page load in my memory safe browser, while living on a memory safe OS
Filip Jerzy Pizło tweet media
English
6
3
125
11.3K
blasty retweetledi
Rick de Jager
Rick de Jager@rdjgr·
May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit ✨ Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
English
67
753
8.8K
300.1K