you can build a working HTTP server in x86-64 assembly
just Linux syscalls
create a socket, bind it to 127.0.0.1:8000, listen, accept connections, write an HTTP response, close the socket
the entire server is just raw assembly talking directly to the kernel
Never be the one sitting around waiting for life to happen. Puttering your way through a bare minimum existence as you barely scratch the surface
There’s outcomes that only exist at extreme throughput. Need more hours. Volumemaxxing. Absurd unrelenting devotion as you repeatedly take shots nobody can fathom ever hitting
The machinery starts producing freak events under enough pressure
Now you’re jumping through realities. A thousand lifetimes. Gutter to glory in under a year
> write a list of beliefs you wish to be true
> record them into voice memos
> listen as you fall asleep
> imagine they were 100% truth
> picture what life now looks like
> let this excite you
> wake up as the person you wish to be
Hyundai and Kia added official GrapheneOS support to their apps months before Volkswagen banned GrapheneOS:
https://t.co/k0egvK5SNw
Pressure from Volkswagen customers on them can achieve the same thing. There's no legitimate reason to ban GrapheneOS so they'll undo it with pressure.
Leave a 1 star review for Volkswagen's apps on the Play Store asking them to stop banning GrapheneOS. Explain it's a far more secure operating system and fully possible for them to verify the hardware, OS and their app on it if they insist on doing it. It's far more secure than anything they allow.
Google has misled companies about what the Play Integrity API provides. It doesn't genuinely enforce having a secure device or legitimate app, it only pretends to. It leaves huge security holes open. It enforces Google's business interests and bans having a reasonably secure device with GrapheneOS.
Most companies are unlikely to stop using the Play Integrity API but most are willing to start permitting GrapheneOS via hardware attestation with enough pressure.
In addition to every user of their app on GrapheneOS leaving a 1 star review on the Play Store, multiple other steps can be taken too.
Every GrapheneOS user with one of their cars using the app should file a customer support request. Keep answering them and countering the template responses. Escalate the request higher up. Tell them you want money back for the vehicle due to reduced functionality after the fact and insist on it.
They can trivially stop enforcing the anti-security and anti-competitive Play Integrity API or easily add hardware-based verification of GrapheneOS. Link to https://t.co/KC7xS0Nobe in the customer support request, but don't add any links to Play Store reviews to avoid filtering.
A bunch of apps have added explicit support for GrapheneOS due to pressure from our users. Our userbase is rapidly growing and we'll gain the ability to apply massive pressure to companies doing this. We plan to ship a feature for our Info app for people to opt-in to getting asked for their help.
GrapheneOS is production quality OS from a non-profit paying around 15 people to work on it. It's far more secure than anything supported by the Play Integrity API. We have an official partnership with Motorola and we'll have more. Just counter template responses and insist on compensation or a fix.
Chat, I'm flabbergasted.
I had a few people DM saying this account is spreading malware. They said the GitHub has a .exe which is suspicious.
I poked it with a stick.
It is, in fact, NOT malware.
https://t.co/kEUJOtvY4K
Burp Suite Professional costs 475 dollars a year per seat.
A senior software engineer in Amsterdam built the open source replacement as a side project. He put it on GitHub for free. It has 10,569 stars.
His name is David Stotijn. The software is Hetty.
Here is what Hetty is.
An HTTP toolkit for security research. A machine-in-the-middle proxy that sits between your browser and the target. Every request and every response flows through Hetty. You can read them, search them, intercept them, edit them, replay them, and send them again.
This is the core loop of every web application security test ever performed. Burp Suite charges 475 dollars a year for it. Hetty does the same job for zero.
Here is the feature set.
A machine-in-the-middle HTTP proxy with full logs and advanced search. An HTTP client for manually creating and editing requests, and replaying any request you already proxied. Request and response interception for manual review, with full edit, send, receive, and cancel control. Scope support to keep your work organized to a single target. A web-based admin interface that runs in your browser. Project-based database storage so multiple engagements stay separate. A GraphQL service for programmatic access.
The installer is a single Go binary. Works on macOS, Linux, and Windows. No Java runtime, no enterprise license server, no machine fingerprinting, no telemetry.
Here is the price ladder.
Burp Suite Professional: 475 dollars a year per seat.
Burp Suite Enterprise: thousands per year, contact sales for a quote.
Burp Suite Community Edition: free, but throttled, no scanner, no project save, no intruder rate.
OWASP ZAP: free and open source, now owned by Checkmarx after a 2024 acquisition.
Hetty: zero. Forever. One binary. No account.
A pentester working full time pays Burp 475 dollars a year. A team of 10 pentesters pays 4,750 dollars a year. A bug bounty hunter who finds one vulnerability has already paid for Burp twice over.
Or they download a 30 MB Go binary written by a freelancer in Amsterdam and keep every dollar they earn.
David has not pushed a new commit in 16 months. The last commit was January 13, 2025. That is normal for a tool that is feature-complete. HTTP has not changed. The proxy still proxies. The intercept still intercepts. MIT licensed code does not expire when the maintainer takes a break.
Buy a domain. Find a bug. Cash a bounty.
PortSwigger took a free industry tool and put it behind a 475 dollar paywall. A freelancer in Amsterdam gave it back. On every platform. For zero dollars.
Your proxy. Your binary. Your bounties.
(Link in the comments)
Turned a rooted android tablet into a network-wide DNS firewall blocking 87,771 ad/tracker domains for every device on my network, no raspberry pi. no vps. no subscription. just termux + proot + magisk + pi-hole! automated the whole thing https://t.co/lZi2yX0hIP
#privacy
Today the United States sanctioned Sergey Zelenyuk, and his company Matrix LLC, notably for "acquiring at least eight proprietary cyber tools exclusive to the United States government".
Want to guess what those tools were? See image two!
Info via @jsrailton