software dev/mgmt, teaching offsec/re. sec researc @DIVDnl, re/vx hobbyist, codes either functional or asm, plays with elf internals,
he/him #HackingIsNotACrime
I never posted about this, but for those who know me; after fighting cancer for 4 years my wife passed away yesterday evening. she went in peace at home and will forever be loved. Christmas will never be the same for our kids and me.
What is it with a _security company_ only running a VDP with 0 compensation for researchers?
And this after being pwned hard in the past, resulting in massive damages for clients worldwide.
F this platform, pushing far right politicians and other crap in my notifications without an apparent way to turn it off.
Expect me to be dormant here (until i can be arsed to clean up my account here or I change my mind and deal with the crap)
@evapro30 "recognized as malware for windows"; by what? based on what? heuristics? do you have a hash? has it been identified or was it reversed? I'd be interested in what kind of malware it embeds, the c2 infra, etc. any more information beyond the post?
@cyb3rops@CISAgov I’m sorry Palo Alto. ofcourse you can be on the list, it was only meant as example. No need to cry, you still get to be with your friends 🤗
What surprised me is not hard coded creds, but that it was just recently discovered. Given how much security researchers and baddies love poking holes in Cisco, I’m inclined to think they were added in a recent code change and this isn’t the “legacy” everything gets blamed on…
@bettersafetynet@MalwareJake most of these posts end with "don't miss out, buy my course" and the authors either did a bootcamp or generated a todo app...
llm's are great at generating snippets for solved problems; haven't seen anything decent beyond that
@thegrugq@dinodaizovi I don't know, before you know it it'll lead to paranoid thoughts like "don't trust anything, authz, verify and validate everything" between those small islands and companies will drown you in marketing misusing the concepts
@HackingLZ "Asking for help to debug code that's part of a larger framework for programmatically sending text messages to attacker specified numbers." counted as the only instance of "LLM-aided development" 😂
I think we're safe
@HackingLZ their usage includes "Asking how to search for specific versions of Log4j that are vulnerable to the critical RCE Log4Shell." resulting in "LLM-informed reconnaissance"
we're clearly doomed... 😂
Dear @Apple I don't think that me using using too many characters for a password implies I entered a weak password, it implies you have technical restrictions...
(sorry for the dutch, image alt contains translation)
Rust knows that \n is 0x0A, but it has been passed generation by generation down from an earlier compiler. The compiler source itself does not have that information. https://t.co/SoSVTTJY2H