How Container Filesystem Works 🧐
Building a Docker-like container from scratch using only standard Linux commands (unshare, mount, pivot_root, etc.) is a great way to understand exactly what a container runtime like runc does under the hood to turn a container image into a fully-fledged rootfs.
Deep dive: https://t.co/PC7c9Zy1SJ
Everyone can use an llm. everyone can build things. But do you know the outcome of what you're building.
95% of people dont. thats what makes the difference when a technical and a non-technical person uses an llm. professionals know exactly what they want to build, why they're building it, and what outcome they want to achieve.
using an llm is easy. knowing exactly what to build (you have the whole flow running inside your thoughts) , how to build it (your way of design), and why it matters is what makes a lot of difference.
for example before 4 months i don't know too deep about compilers & stuffs. i started to refer llvm books, understand how things happens and done tried something in it ( and this is the coolest book ever ). i read books, a lot of books to understand stuffs, learn 1 or 2 different things to make things different. ( everyone cant post everything Problème de sécurité opérationnelle )
small story:- i have a friend of mine who works in xyz red team lead. his junior team mate got same model, same harness. Junior found nothing, while my friend found five 0 days in an month, reported himself, got a large sum amount and started a small startup.
Hey, I just published a book for learning Windows Kernel Segment Heap Internals and exploitation techniques based on my own notes.
Read it here: https://t.co/Nf1Y0qzHVm
There's a lot to wrap your head around, so I started creating my own diagrams and explanations to make it easier to understand. Hope it helps! :)
Original write-up on the fastjson 1.2.83 gadget-free RCE.
Have fun reading, I hope you missed writeups without AI slop.
Comment here your opinion.
https://t.co/cbAKOAeY62
We found a gadget-free RCE in Fastjson 1.2.83 - the final release of the 1.x line, and still one of the most widely-deployed Java JSON libraries in production today, even with 2.x around.
No classpath gadget. One payload-> RCE.
And this one is human insight w/ LLM-assisted research. Took about one week to finish everything. The AI really rescued me from a lot of tedious work
— excluding the part where it changed the Domain Admin password, locked me out, and claimed it got RCE 🤦
🌏 Browser Exploitation 101: A Series of Blog posts for anyone interested in Chrome Browser Exploitation.
Part 1: https://t.co/2MyvKCeU3k
Part 2: https://t.co/ouhLfrY74O
Part 3: https://t.co/hAsE5UIpDZ
#infosec
THE CHINESE DARK GHOST
Super excited to have completed this China OSINT CTF! It was one of those rare challenges that required me to think beyond just tools. Kudos to the team and @OSINT_Community for organizing such a great challenge! I learned a lot!
#UK_OSINT#Cybersecurity
Presentations about getting started with Linux kernel exploitation
"Linux Kernel Exploitation for Beginners" by Kevin Massey:
https://t.co/HNuwKGLTv1
"Control Flow Hijacking in the Linux Kernel" by Valeriy Yashnikov
https://t.co/9HqgXvCpX4
#Linux#infosec
Anyone has a job that needs strong OS/System research and engineering skills?
My postdoc Jongyul Kim is looking for a research oriented job. He does great work on Storage and Memory Systems. You can find his work at: https://t.co/VofPcAp3Al
His CV can be found at: https://t.co/BmyNymxwTg