Mark Griffin

219 posts

Mark Griffin banner
Mark Griffin

Mark Griffin

@seeinglogic

Dev/hacker | Improving human understanding of code | A picture's worth 1KLOC

Katılım Eylül 2022
105 Takip Edilen376 Takipçiler
Sabitlenmiş Tweet
Mark Griffin
Mark Griffin@seeinglogic·
Kicking off my writing on visualization and software with a post on my most recent Binary Ninja plugin, Ariadne! seeinglogic.com/posts/why-of-a… Learn how interactive graphing helps with reverse-engineering and some common workflows. #infosec #dataviz
Mark Griffin tweet media
English
2
22
92
15.5K
Mark Griffin retweetledi
DistrictCon
DistrictCon@DistrictCon·
Feb. 6-7, 2027 | See you there 🪩✌️
DistrictCon tweet media
English
1
9
32
4.6K
Mark Griffin retweetledi
RE//verse
RE//verse@REverseConf·
RE//verse 2026 talks are live on YouTube! Want to revisit a talk or catch the ones you missed? The full playlist is now available: youtube.com/playlist?list=…
RE//verse tweet media
English
4
57
315
23.5K
Mark Griffin
Mark Griffin@seeinglogic·
Junkyard was an absolute pleasure to host again, it was awesome to see it take off... we even had a Roller Coaster Tycoon exploit this year! In case you missed the show, @caseyjohnellis gave a great writeup of the EOL targets and exploits shared: cje.io/2026/02/07/for…
English
0
2
2
198
Mark Griffin retweetledi
DistrictCon
DistrictCon@DistrictCon·
THATS A WRAP ON DISTRICTCON YEAR 1! ☃️❤️🪩 We sincerely hope you had a great time - it wouldn’t be possible without our amazing team, our speakers, the villages, our sponsors, and most importantly YOU! We hope this brings you a sense of community. Stay warm, be good to each other, and we’ll see you again for Year 2!
DistrictCon tweet media
English
3
13
72
4.4K
Mark Griffin
Mark Griffin@seeinglogic·
@pcaversaccio @Lotem_Kahana If you open a workspace with a .vscode/settings.json file overriding these settings, does that override this? Workspace trust has a lot more surface than it seems, and when I previously reported issues I was told they think "do you trust the authors" is sufficient warning.
English
1
0
2
159
sudo rm -rf --no-preserve-root /
i genuinely think everyone in this space should immediately switch to using Vim. DPRK started abusing VS Code hooks that run _automatically_ in the background when you open a folder. ZERO fucking user interaction required _after_ trusting the repo (the trusting part is important here). Yes, read it again. ZERO. INTERACTION. REQUIRED. so what happens is the following: they (in the usual case the Contagious Interview group, meaning some fake recruiting guy) share GitHub, Bitbucket, and GitLab repos containing a `.vscode/` subdirectory with malicious hooks. the one example I share here executes a fake font that's actually heavily-obfuscated JS and will absolutely rek you. all your fancy software that feels "convenient" makes tradeoffs. those tradeoffs are now being abused to silently rek your devices. use Vim. and use Qubes. Thx.
sudo rm -rf --no-preserve-root / tweet mediasudo rm -rf --no-preserve-root / tweet media
English
168
298
2.2K
372.5K
Mark Griffin
Mark Griffin@seeinglogic·
VSCode has leaned forward on a lot of fantastic usability enhancements... But their recent "terminal autocomplete suggestion" setting has definitely been a mixed bag for me (distracting and suggests bad completions). To disable: settings > "terminal suggest" and uncheck
Mark Griffin tweet media
English
0
0
0
85
Mark Griffin
Mark Griffin@seeinglogic·
A friend told me I buried the lead, and that they felt this chart tells the tale. While the sample size is very small, the data does not favor humans given the specific parameters of LiveCTF (average human solve 22.8 min).
Mark Griffin tweet media
English
0
0
0
171
Mark Griffin
Mark Griffin@seeinglogic·
Finally ran my own experiment with AI on LiveCTF challenges after seeing a bot beat top players. …and I was surprised by the success of current models with a single prompt. Sharing what I did so you can try it yourself: seeinglogic.com/posts/livectf-…
English
1
1
8
2.2K
Mark Griffin
Mark Griffin@seeinglogic·
Team Atlanta's report explains how their 1st place CRS found & patched bugs... and you can just read the code! github.com/Team-Atlanta/a… The report covers a ton: orchestration, LLM strategies, patch generation... but really shines in its coverage of practical fuzzing issues.
Team Atlanta@TeamAtlanta24

🚀 Today, we're excited to release #TeamAtlanta’s technical report on **ATLANTIS**! Check out how ATLANTIS won 1st place at #DARPA AI Cyber Challenge (#AIxCC) at #DEFCON 33! 🌐 team-atlanta.github.io/artifacts/ #AICyberChallenge #Cybersecurity #LLM #GenAI #Agent #Fuzzing

English
0
0
3
293
Battle Programmer Yuu
Battle Programmer Yuu@netspooky·
Are there any decent gameboy rom plugins for binja that aren't in the plugin store? Neither one on there really works that well for even basic disassembly.
English
5
0
6
2.2K
Mark Griffin retweetledi
DistrictCon
DistrictCon@DistrictCon·
Interested in Submitting to Junkyard? Want to hang out with fellow researches? Workshopping ideas? Come hang out with the Junkyard Team for a Virtual Happy Hour! Wednesday October 1, 8pm ET (5pm PT) (1, maybe 2 hours?) RSVP: luma.com/949joy6c
English
0
5
7
2.1K
spaceraccoon | Eugene Lim
spaceraccoon | Eugene Lim@spaceraccoonsec·
Been thinking of picking up binary ninja as an alternative to Ghidra or IDA.. any thoughts or experiences for folks who’ve used various options before?
English
8
1
40
7.5K
Mark Griffin retweetledi
DistrictCon
DistrictCon@DistrictCon·
They're called "forever bugs" for a reason 🐛 districtcon.org/junkyard - submit your best 0day in end-of-life today to win cash prizes!
DistrictCon tweet media
English
0
5
13
1.9K
Mark Griffin
Mark Griffin@seeinglogic·
ICYMI: 5 systems from AIxCC are now Open Source: archive.aicyberchallenge.com An unprecedented opportunity to peek into the toolkit of top security teams. Everything from prompt templates, to terraform code, to implementations of very recent research techniques, it's all there 👀
English
0
1
6
483