I’ve spent more time inside the Twitter codebase than 99.9999% of humanity and folks, I literally don’t understand what it would mean to give someone a quick “tour” of “the Twitter code”
Binary episode is live in 10 minutes. Today we have some questionably exploitable bugs in Edge, a SHA-3 int overflow, and a recent io_uring exploit.
https://t.co/MdSZr2rxzG
Python 3.11 is out! 🎉
This is one of the most exciting releases in a while, including significant speed upgrades and better error messages.
Here's what's new:
Eko eko ekooo... I will participate in @ekoparty conference next week. This time, I will talk about Misuse of Apple AirTags, and how to protect against them. Adding "reverse stalk engineering" and mimicking AirTag BLE techniques. Also, I will release a spoofing code for Flipper:
SharedMemUtils - A simple tool to automatically find vulnerabilities in shared memory objects (commonly used for IPC in Windows services)
This tool immediately uncovered potential exploitation routes in both Nvidia and Dell Audio services on my system.
https://t.co/fOBs1FuSzB
"Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules"
#infosec#pentest#redteam
https://t.co/BkW8AZEBbW
I'll write a blog post soon - in the mean time check out this incredibly detailed blog post by @0vercl0k about reverse engineering tcpip.sys. this work made the REing of this bug much easier.
https://t.co/Gr7Q5DVAi3
“Golang’s core team released a patch that fundamentally changes how that language parses URLs. Before version 1.17, Golang considered semicolons within a URL query portion as a valid delimiter”
Easy to miss but good vector for auth/authorization bypass! https://t.co/fD8d7CyfVY