blasty

4.4K posts

blasty banner
blasty

blasty

@bl4sty

irresponsible disclosure aficionado

The Netherlands Katılım Nisan 2009
1.1K Takip Edilen17.2K Takipçiler
blasty
blasty@bl4sty·
@me_irl oh snap, brb, i need to root some motorola 68k linux targets with your fine slopwork
English
1
0
0
66
the government man
@bl4sty and mine supports *every* arch supported by nolibc, which is most of them
English
1
0
0
103
blasty
blasty@bl4sty·
to celebrate the release of Copy Fail and the professional way the embargo and disclosure was handled by all involved parties i have sacrificed my lunchbreak to do a quick C port (with aarch64 support and some other small things) of the original PoC gist.github.com/blasty/d7b5d05…
English
8
61
297
20.7K
blasty
blasty@bl4sty·
@andersonc0d3 no, but if I had to guess: the page cache is shared with the host, but it would only affect things that are bind-mounted or use the same underlying image overlays (eg. multiple docker containers derived from same base); mostly speculating here though :)
English
1
0
8
589
blasty
blasty@bl4sty·
@ergot86 its pretty zen every now and then, do not forget the good old craft
English
0
0
8
780
Daniel
Daniel@ergot86·
@bl4sty Wait, did you do artisanal code writing?
English
1
0
1
821
Brad Spengler
Brad Spengler@spendergrsec·
@bl4sty As if there was an embargo and distros were even contacted at all
English
1
0
14
1.3K
blasty retweetledi
grsecurity
grsecurity@grsecurity·
Creating a separate post so more people see this: the mitigation recommended by Theori.io for copy.fail *WILL NOT WORK* for any RHEL or RHEL-derived distro, including CentOS, Fedora, Oracle, and Alma as the vulnerable code is built-in.
English
4
59
152
39.2K
blasty
blasty@bl4sty·
crazy, gj xint! 🦾🤖
Tim Becker@tjbecker

Very cool Linux bug found by @xint_official 100% reliable, instant LPE from a portable python script that works on all platforms and distros. Root cause is a subtle logic bug at the intersection of several subsystems. I highly recommend patching and checking out the details!

0
3
26
5K
Toan Pham
Toan Pham@__suto·
@halvarflake you will never know, there is some report about these misbehaving provider few months ago on openrouter. I think it happen more than often!
English
1
0
3
1K
Halvar Flake
Halvar Flake@halvarflake·
How do I know that a token provider is providing the model itself and not a hardcore quantization?
English
13
4
39
11.6K
blasty
blasty@bl4sty·
@halvarflake curious about your setup. its super easy to burn $2.5k worth of opus-4.6 tokens and come back (mostly) empty handed. if I had to guess there's probably quite some variant overlap included in that 270 metric as well
English
2
0
8
2.4K
Halvar Flake
Halvar Flake@halvarflake·
After burning $2.5k on tokens and LLM findings, I have a question about the 270 Firefox bugs: were they all attacker-reachable? The findings I got where often "legitimate bad code" but also "not reachable in any sane scenario".
English
31
19
293
30.2K
blasty
blasty@bl4sty·
the buzzwords for this week are "orchestration" and "scaffolding". if you'd like to avoid these (undervalued!!!1) methodologies you can also put the needle right next to the haystack and pray to the internet gods no-one notices your rigged victory.
English
1
2
16
1.7K
blasty
blasty@bl4sty·
@bienpnn you need to gaslight it harder and introduce serious repercussions for not following orders
English
0
0
2
628
Bien 🇻🇳
Bien 🇻🇳@bienpnn·
what is the point of making a todo list if the llm just casually skip and mark the todo as completed LMAO
English
1
0
6
1.3K
blasty
blasty@bl4sty·
@OwariDa new llm benchmark: vimtutor any%
English
0
0
1
641
Joel Eriksson
Joel Eriksson@OwariDa·
Experimenting with providing vim-motion based edit tools to agents, with support for treesitter-based text objects etc to allow for efficiently replacing full function bodies etc It works, but even SoTA LLMs seriously need to up their vim-golfing skills 😅
English
2
0
0
1.2K
blasty
blasty@bl4sty·
@bj2rn epomaker x feker galaxy80
Polski
0
0
0
206
björn
björn@bj2rn·
@bl4sty nice keyboard! what model is that?
English
2
0
1
1.1K
blasty
blasty@bl4sty·
do NOT give claude cart blanche for interfacing with your printer
blasty tweet mediablasty tweet media
English
13
11
483
36.2K
blasty
blasty@bl4sty·
@Nadsec11 bambulab + claude = house on fire, most likely
English
2
0
36
3.1K
nad
nad@Nadsec11·
@bl4sty Try the 3d printer next
English
1
0
19
3.1K
blasty
blasty@bl4sty·
@OwariDa yup, the (early) code probably provides more clues than a bunch of stylometry done on cypherpunks mailinglist posts. wasn't there some remains of a poker client in there as well? it's been a while since I looked at it :)
English
0
0
1
571