Nick G

173 posts

Nick G banner
Nick G

Nick G

@kallsyms

@Xbow. Formerly @google, @capsule8. Professional thing breaker. 👻

San Francisco, CA Katılım Mayıs 2012
748 Takip Edilen746 Takipçiler
Nick G
Nick G@kallsyms·
@techAU Nope, just normal 5.5. Don't need a special model for a 25 year old OS :P
English
2
0
60
14.4K
Nick G
Nick G@kallsyms·
🚨 0-day alert! GPT 5.5 has found and exploited a network accessible RCE in Mac OS 9.2.1 🚨
English
54
118
1.7K
461.7K
Nick G
Nick G@kallsyms·
@moyix Network code for AFP :) Does mean file sharing needs to be enabled, but I've got it continuing to hunt for something better in the core networking stack
English
1
0
3
133
Nick G
Nick G@kallsyms·
At least it's honest.
Nick G tweet media
English
1
0
5
664
Nick G retweetledi
Ian Butler
Ian Butler@kinglycrow·
Another feature from our dev agent. It has full runtime environments spun up on demand to work in with full project context and access to shell tools!
English
0
1
3
624
Nick G retweetledi
Ian Butler
Ian Butler@kinglycrow·
Mentioned last week we're working towards open sourcing something big. Today I want to share a sneak peak into what's coming. Not sure what we're calling it yet but it's basically an open source version of the dev agent we've worked on for the last year and change.
English
0
2
9
593
Nick G retweetledi
Ian Butler
Ian Butler@kinglycrow·
Next.js had a serious vulnerability in their middleware system which allowed bypassing auth, and while bugs happen, the way it was communicated to their community was handled pretty terribly. Normally I'm not posting on the weekend but this is some pretty spicy 🌶️ stuff. In business if you have bad news you're supposed to communicate it quickly and directly, it's a trust exercise for people who put their faith or money in you. This is also true in tech. We've spent years cultivating a blameless culture because we recognize that with system complexity and how fast everyone is always moving there's bound to be issue that make it through checks. If the Twitter sphere is to be believed Vercel: - Knew about this bug for over 3 WEEKS and quietly pushed changes to their new SDKs. - Did not tag their PRs for fixes as a security issue - Waited until the last minute to work with their Open Source community to announce the issue and a path to resolution for those affected Part of responsibly disclosing issues like this is patch first and then move to communicate immediately to all impacted parties. You do not sit on your hands. Because of this multiple platforms went offline today to deal with the bug as a fire drill exercise instead of having proper time to deal with the issue. This is a serious trust issue for what is currently a widely used framework and service. You yourself might be impacted right now. As a steward of such widely used technology you have a responsibility to your users to protect them even if it's uncomfortable from a business perspective.
English
1
2
3
514
Nick G
Nick G@kallsyms·
Man my eclipse photos look weird
Nick G tweet media
English
1
0
1
265
Phil Eaton
Phil Eaton@eatonphil·
@kallsyms Does it expand the options if it's allowed to do dynamic analysis? I run a test case and it lets me query the entire call graph?
English
1
0
0
536
Phil Eaton
Phil Eaton@eatonphil·
Are there static analysis tools that will tell you all the call trees a function might be called from? Particularly for C projects.
English
16
2
47
12K
Nick G
Nick G@kallsyms·
Re the xz backdoor
GIF
English
0
0
2
305
Ian Butler
Ian Butler@kinglycrow·
My co-founder made me give up my long running feature branch. @kallsyms
Ian Butler tweet media
English
1
0
0
84
Nick G
Nick G@kallsyms·
Nick G tweet media
ZXX
0
0
2
307
Nick G retweetledi
Pete Markowsky
Pete Markowsky@PeteMarkowsky·
Here goes nothing. Ship it!
Pete Markowsky tweet mediaPete Markowsky tweet media
English
0
3
23
2K
Nick G
Nick G@kallsyms·
The idea is to use userfaultfd to track memory modified during a program execution and restore it between runs instead of re-forking. It's still a proof of concept, but results are encouraging yielding a ~1.8x increase in execs/sec compared to AFL's persistent mode on libjpeg.
English
0
0
0
0
Nick G
Nick G@kallsyms·
Finally finished up and wrote about an exploratory side project from a year ago: accelerating fuzzing throughput by using userfaultfd to do dirty page tracking and restoring entirely in userland. nickgregory.me/post/2022/12/0…
English
1
6
30
0
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
Is there any service that has archived snapshots of GitHub repos? Trying to reconstruct MS's PyPIBugs dataset right now but a handful of the repos it refers to are gone now, like this one: github.com/alx-k/flask-je…
English
4
0
9
0