@Jbandos The US Navy also used to have touch screens in some of their ships, but then their was a crash that had blamed the design of the controllers saying that they were unnecessarily complex. They then changed them to mechanical controls instead.
https://t.co/4iuqyjw8Qa
Did you know that Java code can be injected into a multiline comment using Unicode escapes (\uXXXX)?
It appears as a comment but executes as code.
Attackers can use this technique to hide backdoors.
Test it yourself to "reveal a hidden message": https://t.co/a3lI6oeV1A
Governments are fallible at securing data.
People ask me, if I get worn down from the constant data breach news. No. What I've learned is since data breaches are inevitable, that I need to take my private data more seriously than ever. Nobody is capable of protecting my data, so I simply will not give it to anyone.
Where I get most frustrated is when the government forces me to give my data. To open a bank account or get medical treatment. Over and over this data I was forced to provide has been breached/sold/spied on.
In one of the #MalwareAnalysis communities I’m in, we were talking about Go malware. Someone mentioned CAPA as a good tool. I have to say, it’s really helpful for finding the 50kb of interesting code buried inside a 5mb Go binary 😎What other tools do you use?
So, I did this stream against my better judgment. I had fun and there were some great questions.
As expected, I received quite a few DM's from haters. I won't name and shame as I really couldn't care; rather, I wanted to share the following as an optimistic message in regard to vulnerability research:
- Do NOT listen to the trolls or haters... They'll always be there... Just wish them the best and move on...
- Believe in yourself, even if no one else does... Find your people... They're out there... I believe in you... I came from a poor background and I'm proud of it! Hacking is for everyone!
- You WILL get frustrated/humbled, it's part of the process... Embrace that... Learn from it...!
- Sometimes it sucks ( quite often! ) and there might be easier paths, but you're learning even when it's not so obvious...
- You are part of the evolution of security... Your work matters...
All of this is coming from a rather cynical person. Let's go! Hack all (of) the things! I hope to see many of you at DEF CON.
@d4rksystem Oh & one thing I found really annoying was that if you change a URL file that has already been triggered, you need to rename it or create a new txt file w/ a diff name & change the ext to .url. Else, it will use the originally triggered url file??idk there was a lot of weirdness
@bettersafetynet I started using EndeavourOS and their AUR news checker and update script to handle db locks, keyrings, and mirrorlist syncing.
I haven't had that problem in a while.
https://t.co/qmkgq3Llar
https://t.co/BmAB8Wy7lK
ha github has a CSS injection glitch right now
tell me i dont have the coolest profile background now
yes this is real
straight MySpace vibes
https://t.co/OB2CHXFkff
@jonasLyk Others have shared your sentiment (not specifc to windows api examples). Some, including myself, have moved to paying for a search engine. Try Kagi out (I'm not associated to them)?
https://t.co/5Fdtb3RC9X
https://t.co/MfSBDvX2Oi