Show newer
modrobert boosted

We are happy to tell you that we accept your proposal "Broom not included: curling the modern way" in the Network devroom at #FOSDEM 2024.

It looks like I will blab at FOSDEM again.

"In this vulnerability disclosure report, we discuss details of 5Ghoul – a family of implementation-level 5G vulnerabilities. Such a family of vulnerabilities are present in the firmware implementation of 5G mobile network modems from major chipset vendors i.e., Qualcomm and MediaTek. Consequently, many 5G-capable commercial products such as smartphones, Customer-premises Equipment (CPE) routers and USB modems are potentially impacted due to the employment of vulnerable 5G modems in such products."
asset-group.github.io/disclosu

modrobert boosted

I can finally reveal some research I've been involved with over the past year or so.

We (@redford, @mrtick and I) have reverse engineered the PLC code of NEWAG Impuls EMUs. These trains were locking up for arbitrary reasons after being serviced at third-party workshops. The manufacturer argued that this was because of malpractice by these workshops, and that they should be serviced by them instead of third parti
es.

1/4

modrobert boosted

You probably never figured the Caribbean island of Anguilla would be a hotbed of AI activity, but here we are. One of the more interesting press releases I received this morning:

"Due to the rise in popularity of Artificial Intelligence (AI), .ai domain registration figures have skyrocketed. The small island of Anguilla, whose government owns the country code top-level domain (ccTLD) .ai, has had a huge spell of luck after reaping significant profits amid this tech-driven trend."

"Anguilla’s government is earning around $3 million every month from registrations, which has almost surpassed the revenue generated from all goods and services, from all of their shops and restaurants each month of the year so far. Should this trend persist, projections suggest a potential additional revenue of up to $45 million by the end of 2024."

"Although this presents a significant opportunity for a tiny island of only 16,000 inhabitants, such reliance on a single revenue stream poses potential risks to the nation’s economic prospects."

modrobert boosted
modrobert boosted

Always amazes me to find quotes like this one from a coder like Dan Scott: "While I was learning and coding, I was always in awe of the crackers. Cracking encrypted code, rearranging disk Content to find space for a cracktro, one filing games, squeezing 2 disk games onto 1 disk etc.. Seemed like voodoo to me" (eab.abime.net/showthread.php?p)

modrobert boosted

Did you know that there is full coverage of the C radare2 api for Rust and Python autogenerated with bindgen and ctypeslib respectively? It’s not idiomatic and certainly needs some maintainance and cosmetic work but the hard part is done. github.com/radareorg/radare2-b

modrobert boosted
modrobert boosted

The #OPLArchive is my project to preserve the history of DOS-based chiptune music in a central location, using the universal VGM file format. I'm trying to find and add as many songs as I can. Check it out at opl.wafflenet.com - You can even listen in your browser! #YM3812 #YMF262

modrobert boosted

You can learn how to use radius2 by checking the new repository collecting several usage examples! By @alkali github.com/aemmitt-ns/radius2-

"USING CLOUDFLARE TO BYPASS CLOUDFLARE

An attacker can setup a custom domain with Cloudflare and point the DNS A record to victims IP address. The attacker then disables all protection features for that custom domain in their tenant and tunnel their attack(s) through the Cloudflare infrastructure. This approach allows attackers to bypass the protection features by the victim."

certitude.consulting/blog/en/u

modrobert boosted

In 2000, the Beatles created THEBEATLES.COM in relation to a new Beatles compilation album set, "1". For whatever reason, the legendary demoscene group MELON was hired to make flash animations for their songs. The results are now emulated at Internet Archive.

Warning: Flashing lights galore.

archive.org/details/melon-come
archive.org/details/melon-ifee

"Risky Biz News: Chinese APT hacks subsidiaries, pivots to corporate headquarters

In other news: Google and Mozilla patch another Chrome & Firefox zero-day; Cisco patches its own zero-day; and new DarkRiver APT targets Russian defense sector."
riskybiznews.substack.com/p/ch

modrobert boosted

"Risky Biz News: China admits NSA hacked Huawei

In other news: iOS zero-days used to hack Egyptian presidential candidate; new Sandman APT targets telcos across the world; Russia's largest travel agency breached by pro-Ukraine hackers."
riskybiznews.substack.com/p/ch

modrobert boosted
modrobert boosted

#libwebp 1.3.2 has two #security related flaws that have been fixed in main:
• Fix invalid incremental decoding check:
github.com/webmproject/libwebp
• Fix next is invalid pointer when WebPSafeMalloc fails:
github.com/webmproject/libwebp

While these are not as easy to exploit as CVE-2023-4863 it seems evident that there has been some gaps in libwebp fuzzing at google. Also CVE-2023-4863 was obviously assigned to a wrong project. #infosec #vulnerabilities #cve

modrobert boosted

brutal first blood for cytrox on iOS 17, but also damn that's some clear cut misuse.

modrobert boosted

if this infosec stuff doesn't work i'll start an ice cream shop

Show thread
Show older
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.