shuffle2
2.2K posts


@_gcali @mncoppola Something at top/after stack that gets used when handling a crash, or by different thread?
English

We (Project Zero) got a new website! Because the last one was so...2014?
projectzero.google
English

@majordouzie @ross_hewage Friends of mine used this thing and the volume freaked me out but the child seems to be ok (like 6 y/o now). 1/1 test cases is 100% fine
English

@majordouzie Leaving a metal water bottle in there and drinking the superheated water is a treat
English

@yo_yo_yo_jbo No, sorry I misunderstood the original question. I thought you were asking for a secure boot implementation which was optionally uefi-compatible.
English

@shuffle2 But does it support Secure Boot without MOKs?
English

What is the best bootloader built in #rust ? 🦀 And does it support UEFI Secure boot?
English

@yo_yo_yo_jbo hm i was thinking vboot doc.coreboot.org/security/vboot… would be rust by now but it's not
English
shuffle2 retweetledi

while ago I did some quick hax to speedup existing AES DFA project with AES-NI, now the author improved upon my work and merged into main repo! github.com/arusson/dfa-ae…
afaik this is only (public) accelerated AES DFA tool?
English
shuffle2 retweetledi

We've open-sourced GReAT’s plugin for the IDA Pro decompiler - an indispensable set of tools for analyzing malware, shellcodes, etc. Grab our secret ingredient for reverse engineering and check out the GIFs demonstrating its usage - github.com/KasperskyLab/h…
English
shuffle2 retweetledi

x.com/thezdi/status/… how it's going
TrendAI Zero Day Initiative@thezdi
Boom! In the 1st SOHO Smashup of Day 3, PHP Hooligans / Midnight Blue (@midnightbluelab) went from the QNAP QHora-322to the Lexmark CX331adwe - even printing their own "money". They head off to the disclosure room to explain themselves. #Pwn2Own #P2OIreland
English
shuffle2 retweetledi

Here's the link to the tool I meant to release at the end: github.com/symbrkrs/ps5-u…
It makes fiddling with EMC/EFC/EAP easy, have fun!
English

Having a great time at #TheSAS2024 ! You find find slides for my talk here: symbrk.rs/presentations/… I didn't get through all slides...😅
English

@chrisrohlf @NedWilliamson can't we just have a superior model to introduce bugdoors which the superhuman checker can't find
English

While I love this idea, I can’t help but think this model would only be useful for a very short period of time, essentially long enough to secure all of the existing code that’s ever been written. But shortly after that a model like this would just be used to write/compile bug free software going forward. But I suppose how it would achieve that bug hunting capability very much effects this prediction.
English

I’ve been thinking for 2 years every day about what the first principles ideal fuzzer would look like and as I get closer to cracking it I can’t help but keep worrying it might just be AGI. I think there’s room for us to do something with a neural net before we get there, but we probably only have a few years left to win the race to solve it. At least that’s what I tell myself to make myself feel the urgency to spend 5 years on it :) I plan to share some thoughts soon as soon as I have something good!
English

@bl4sty @David3141593 Title reminded me of the ps3 glitch to skip htab updates, wasn’t surprised to see the exploit methodology :p
English

da.vidbuchanan.co.uk/blog/dram-emfi…
love this new blogpost by @David3141593 -- clicky lighter driven DRAM EMFI yielding a reasonably (given the low-tech manual fault trigger) reliable linux LPE on x86_64 🤓
English











