@0xBoku@bcherny@AnthropicAI I’ve ran into more and more issues with refusal this week. I wrote this supply chain attack tool last week and now when I open the existing project it shoots out refusals like crazy.
@shoe0nhead@KyleKulinski Wait… I thought you were supposed to turn off the lights and lay in the fetal position while the water falls over you like rain?
Spent the last 2 weeks working on a devirtualizer for VMProtect 3.5 and learning Remill. Idk yet if I will blog about it, but I at least wanted to publish the code:
https://t.co/GLqKWpOOU7
The approach is different from my last blog, as it lifts the whole x86 code of the VM
@brevolve@Wendigoon8 This seems like a years long commitment. I cannot believe Oz was doing all of this work on behalf of Kane for zero credit. Do you think he was there running things during the original web series, too? I mean it’s too good for just one guy to make on his own.
I see a lot of misunderstanding about what this means and what it will do for us
So let's be very clear:
- browser only
- does not prevent AitM by itself
- does not prevent pre-existing malware from tampering with key generation
This is not a panacea, it is a fair compromise
Azure post 1 of 2 is live now, covering traffic hijacking via Smuggle Caching. Post 2 will focus on a Azure Front Door 0-click XSS that worked on HTTP/1.x and HTTP/2.
Smuggling Through the Front Door... Achieving Global Redirect Poisoning at the Edge
https://t.co/4fTtI2gAdL
@parityzero oh. you can probably also just replace their Chrome shortcuts with the following argument too and wait for next session:
--disable-features=DeviceBoundSessionCredentials
again.. invasive and eww.
I don’t know who needs to hear this but your research is your IP not the vendors IP. You can do whatever you want with that IP. Reporting it, publishing it, selling it to a third party or putting it in a box under your bed 🙄
Microsoft Security Response Center put out a blog post today about Eclipse Nightmare guy
Basically they think he's super mean and totally not cool he's dropping zero days. They say you're a jerk if you do this stuff because it's dangerous and stuff
https://t.co/Bg5iFxI3lc