A thread on file abuses:
the typical goal of file abuse is to make space for your foreign data, and optionally put in another header for a different file type if you want a polyglot.
Slides for my NorthSec talk "Regions are types, types are policy, and other ramblings" are now available at https://t.co/bdKKRnKPP8 Thanks for the excellent and challenging questions, #nsec20 attendees!
@richinseattle@Shiftreduce@epakskape Woops, I missed that, silly Twitter.
For those of you complaining about a 404 on the original link, it was missing a character... https://t.co/GppqS44zMT
Slides from my @_kernelcon_ talk "Bushwhacking your way around a
bootloader" are now available at https://t.co/UjZXw0nrdM
🌽Congrats to @_kernelcon_ for putting together such an excellent inaugural con! 🌽
@travisgoodspeed I've been bypassing all of that nonsense (with mixed success) by using a mixture of the .incbin assembler directive, ld -e, and objcopy --change-section-address to create a custom ELF
It's official! The inaugural BSides NH will take place May 18 2019 at Manchester's @SNHU
The CFP is now open! Submit a bio and abstract to [email protected]. Presenters of all experience levels and backgrounds are encouraged to submit.
See you there!
Today wind gust speeds on Mt. Washington are literally off the chart... an interesting analog equivalent to an integer overflow. Although it looks more like a buffer overflow...
If you haven’t seen @xoreaxeaxeax ’s talk ( God mode unlocked ), do it, it's 5/7, an exceptional speaker that takes hyper complex concepts and can explain it so that normies like me can understand: https://t.co/oXW50hDTUI
Nice work @stewartsmith and others.
This is how SoC's are made... gluing not-necessarily-trustworthy IP blocks together over AHB or other 'trusted' links. ASPEED is likely the norm, not the exception.
Details:
https://t.co/xuqatrNmDg
@matthew_d_green@thegrugq@scouttle did some interesting research related to this topic. Her discussion of authentication in a clinical medical setting may be of interest -- https://t.co/J5OoJn38Vs