Show newer
modrobert boosted

Always amazes me to find quotes like this one from a coder like Dan Scott: "While I was learning and coding, I was always in awe of the crackers. Cracking encrypted code, rearranging disk Content to find space for a cracktro, one filing games, squeezing 2 disk games onto 1 disk etc.. Seemed like voodoo to me" (eab.abime.net/showthread.php?p)

modrobert boosted

Did you know that there is full coverage of the C radare2 api for Rust and Python autogenerated with bindgen and ctypeslib respectively? It’s not idiomatic and certainly needs some maintainance and cosmetic work but the hard part is done. github.com/radareorg/radare2-b

modrobert boosted
modrobert boosted

The #OPLArchive is my project to preserve the history of DOS-based chiptune music in a central location, using the universal VGM file format. I'm trying to find and add as many songs as I can. Check it out at opl.wafflenet.com - You can even listen in your browser! #YM3812 #YMF262

modrobert boosted

You can learn how to use radius2 by checking the new repository collecting several usage examples! By @alkali github.com/aemmitt-ns/radius2-

"USING CLOUDFLARE TO BYPASS CLOUDFLARE

An attacker can setup a custom domain with Cloudflare and point the DNS A record to victims IP address. The attacker then disables all protection features for that custom domain in their tenant and tunnel their attack(s) through the Cloudflare infrastructure. This approach allows attackers to bypass the protection features by the victim."

certitude.consulting/blog/en/u

modrobert boosted

In 2000, the Beatles created THEBEATLES.COM in relation to a new Beatles compilation album set, "1". For whatever reason, the legendary demoscene group MELON was hired to make flash animations for their songs. The results are now emulated at Internet Archive.

Warning: Flashing lights galore.

archive.org/details/melon-come
archive.org/details/melon-ifee

"Risky Biz News: Chinese APT hacks subsidiaries, pivots to corporate headquarters

In other news: Google and Mozilla patch another Chrome & Firefox zero-day; Cisco patches its own zero-day; and new DarkRiver APT targets Russian defense sector."
riskybiznews.substack.com/p/ch

modrobert boosted

"Risky Biz News: China admits NSA hacked Huawei

In other news: iOS zero-days used to hack Egyptian presidential candidate; new Sandman APT targets telcos across the world; Russia's largest travel agency breached by pro-Ukraine hackers."
riskybiznews.substack.com/p/ch

modrobert boosted
modrobert boosted

#libwebp 1.3.2 has two #security related flaws that have been fixed in main:
• Fix invalid incremental decoding check:
github.com/webmproject/libwebp
• Fix next is invalid pointer when WebPSafeMalloc fails:
github.com/webmproject/libwebp

While these are not as easy to exploit as CVE-2023-4863 it seems evident that there has been some gaps in libwebp fuzzing at google. Also CVE-2023-4863 was obviously assigned to a wrong project. #infosec #vulnerabilities #cve

modrobert boosted

brutal first blood for cytrox on iOS 17, but also damn that's some clear cut misuse.

modrobert boosted

if this infosec stuff doesn't work i'll start an ice cream shop

Show thread
modrobert boosted

Need to know whether a piece of hardware is supported by free software? #hNode has you covered! Its search engine will help you verify #freesoftware compatibility. u.fsf.org/3uj

modrobert boosted

@lupyuen

100MHz FM transmitter from 1982, 25 Watts that we used for 3 months of non-licensed radio broadcast. A few coils in power amplifier are missing, and 2N6081/2N6082 (wrong marking) replaced the very expensive original BLY87/BLY89 (~$80-100 for a pair in those days!).

modrobert boosted

A while ago I tested #nostr and all i found was cryptobros and porn. Today it seems like the porn issue is under control and the feed seems nicer.

Clients got significant UI improvements, but still it feels a bit dangerous to post on a place where data spreads beyond author's control.

I managed to remove notes i published. But in theory all devs say this is UB. Considering there are tons of relays replicating and caching data, some users may still see it.

About this privacy topic it makes me think about the fact that we are not aware enough about all the data we give away and the false feeling of controlling it. Maybe being anonymous instead of having your real persona in this network is the way to go.. but still, i have mixed feelings with this interesting technology (yeah i like the protocol and it's simplicity)

Thoughs?

Live in 115 minutes...
"Unidentified Anomalous Phenomena Independent Study Report"
youtube.com/watch?v=idJKLP5hcu

modrobert boosted
Show older
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.