yrp

139 posts

yrp banner
yrp

yrp

@yrp604

Seattle, WA Katılım Mart 2014
809 Takip Edilen974 Takipçiler
yrp
yrp@yrp604·
@chompie1337 If you’re interested I wrote a clang static analyzer pass to pull similiar info out at compile time, filtered by being cast as the return type from kalloc or appearing in a sizeof passed to kalloc…
English
5
1
10
0
yrp
yrp@yrp604·
#Fatbear2022 is over with @SiouxDenim being crowned as our new fat bear whisperer. Gg to them, and 747! The charity of choice this year is your local food bank.
English
0
0
4
0
yrp
yrp@yrp604·
#FatBear2022 comes to a close: after years of getting close but just not eating enough, 747 finally takes the crown. Current high score is 25, let me know in the next day or two if you can beat it -- winner and winner's charity to follow.
English
0
0
2
0
yrp
yrp@yrp604·
65c70ee367858fad93fa635d0f012b78 fat-bear-2022.png Brackets due tomorrow at 9am pacific.
English
0
0
1
0
yrp
yrp@yrp604·
@halvarflake If you like rust I wrote bindings to Binja’s disassembler here: github.com/yrp604/bad64 Disassembler autogen’d from the spec, pattern matching, and should work in kernel mode.
English
0
0
6
0
Halvar Flake
Halvar Flake@halvarflake·
So for x86-64 disassembly libraries, I am a big fan of ZyDis. That said, I find myself in the position of needing a good Aarch64 disassembler library. What's a good one?
English
3
2
23
0
yrp
yrp@yrp604·
@jonpalmisc I picked walker last year as a dark horse, I was just too early :(
English
0
0
1
0
jonpalmisc
jonpalmisc@jonpalmisc·
@yrp604 12 points — I thought Walker had it in the bag. There’s always next year…
jonpalmisc tweet media
English
1
0
0
0
yrp
yrp@yrp604·
#FatBear2021 is over with OTIS crowned as the old man champ. I tragically scored a total of 1 point, but the high score I'm aware of is 15. If you can beat that, send me your bracket and score in the next two days!
yrp tweet mediayrp tweet media
English
3
1
4
0
yrp
yrp@yrp604·
@itszn13 I got 1 point :(
English
0
0
1
0
itszn
itszn@itszn13·
@yrp604 My bracket is totally rekt :(
English
1
0
0
0
yrp
yrp@yrp604·
f8fbe7c8886c0b7c477a68ea830db083abc2501 fat-bear-2021-filled.jfif
English
1
0
0
0
yrp
yrp@yrp604·
@LiveOverflow A few years ago I wrote some clang code to extract types and layouts from from calls like alloc(sizeof(foo)). Compile your target and wind up with a list of objects, then filter on reachability/relevance. The code is pretty hackish, but I can share if you want.
English
0
0
7
0
yrp
yrp@yrp604·
@saidelike @gaasedelen Does frida otherwise inject and work in the target? If so I can try to debug — getting that script more reliable on windows has been on my todo for a very long time…
English
1
0
1
0
Cedric Halbronn
Cedric Halbronn@saidelike·
Anyone knows the best way to get code coverage of a Windows service (closed source) and load it into lighthouse? github.com/gaasedelen/lig… Afaict all code coverage tools require to start the target which is not doable for a Windows service? cc @gaasedelen
English
4
0
9
0
yrp
yrp@yrp604·
yrp tweet media
ZXX
0
0
1
0
yrp
yrp@yrp604·
Our far bear whisperer has picked GiveWells Maximum Impact Fund as the winning charity. Degenerate bear gamblers, do your thing. Min $20, max w/e. secure.givewell.org
English
3
1
3
0