Elektrine lite

← Feed

cryptax

cryptax@mastodon.social

<p>Anti-Virus Researcher (Mobile, IoT) and Lead organizer of Ph0wn CTF. <br />This account does not represent my employer.</p>

Posts

  • Post #4276527

    Currently decompiling LabubaRAT with Ghidra. It&#39;s taking ages to perform the initial analyzing, probably because of Rust. https://blackpointcyber.com/blog/labubarat-a-rust-based-remote-access-tool-masquerading-as-nvidia-software/ #malware #rust #RAT #labubaRAT

  • Post #4247348

    The badge for THCon2026, a DVID board, had 2 firmware : the conference firmware, which was reversed by @virtualabs@mamot.fr here: https://virtualabs.fr/geekeries/thcon26-badge-writeup and a challenge firmeware here: https://github.com/dvid-security/dvidv2-opensource/tree/main/workshop/thcon2026 That I solved here: https://cryptax.github.io/2026-06-thconbadge/ (writeup/spoiler). #badge #hacking #challenge #ESP32 #thcon #writeup #spoiler

  • Post #4247214

    Je cherche un réparateur de confiance pour mon hautbois, proche des Alpes Maritimes (06). Il a ~50 ans, et besoin de révision. Je sais expliquer les problèmes (mais pas les résoudre lol). J&#39;ai cherché jusqu&#39;ici sans succès. Je cherche qqun d&#39;honnête, qui sait comment réparer un hautbois (pas qqun qui révise un hautbois tous les 5 ans). Re-post bienvenu. #alpes-maritimes #hautbois #luthier #vent #bois #musique #reparation #oboe #repair

  • Post #4158627

    I&#39;ve just been reviewing a paper that explains how to create malware more or less automatically. I won&#39;t get into the details of how nor which conference as it&#39;s confidential. It&#39;s not the first time I review such papers, and I want you to know, that if I am in the review board, such a submission will never get accepted whatsoever. I strongly feel against it. Android malware alone, we have between 6,000 and 10,000 new samples PER DAY. Do you really think we need more? #ethics...

  • Post #4107724

    Sunday morning, and currently fixing an unhappy update on Linux Mint 22.3 yesterday. To my understanding, Mint is not the cause, but it&#39;s the Nvidia drivers which were not rebuilt and signed (Secure Boot) correctly. Fortunately, ChatGPT is helping me out here or this would have been a horrible mess... :( #linux #nvidia #dkms #secureboot

  • Post #3044331

    FYI, I updated my blog post on CTFs and AI, because I wasn&amp;#39;t entirely satisfied with what was in it + people press me for my opinion... so I added it. https://cryptax.github.io/posts/ctf-ai/ Want it brielfly?

  • Post #3044330

    Ca me &amp;quot;tue&amp;quot; le nombre grandissant de services avec une facturation &amp;quot;floue&amp;quot;: - souscription mensuelle à de l&amp;#39;IA : je ne vois aucun contrat, garantie de service. Par ex, pour Warp, ils ont essayé de me prélever mensuellement alors que je n&amp;#39;ai pas souvenir d&amp;#39;avoir signé pour une souscription mensuelle, juste que je voulais essayer un mois. Nuance. - supermarchés où on te donne de moins en moins ta facture. - etc Vous avez trop d&amp;#3...

  • Post #3044329

    Mounted my first Luksbox, protected by a Yubikey. Works very well. Compared to Gocryptfs: you have support for FIDO2 keys. Compared to veracrypt and truecrypt, the big advantage is you don&amp;#39;t have to reserve x Gb for the encrypted partition. #luks #encrypted #partition #volume #fido #crypt #file #linux cc: @Penthertz

  • Post #3044328

    https://geohot.github.io/blog/jekyll/update/2026/05/24/the-eternal-sloptember.html Interesting point of view. I don&amp;#39;t agree with all of it, but lots. &amp;quot;the adoption of AI agents into software development will be one of the most costly mistakes in the field’s history.&amp;quot; --&amp;gt; Disagree (anyway, it&amp;#39;s done). &amp;quot;Agents cannot program&amp;quot; --&amp;gt; yes and no. Agents are worse than a good software engineer, but far better than a bad one.

  • Post #3044327

    Learning about Landlock with a sandboxed opencode in nono. Nono is a sandbox, uses Landlock, and for example we can restrict directories opencode can go into. #auvergnhack #landlock #sekoia

  • Post #3044326

    Last Friday, I was at Auvergn&amp;#39;hack, a small single-tracked conference in the middle of France. A very friendly atmosphere, beautiful weather, great venue, and several very interesting talks. https://cryptax.github.io/posts/auvergnhack-2026/

  • Post #3044325

    My CTF team at Auvergn&amp;#39;hack was fabulous. We had awesome discussions about Java, Python, security in general, but also Saint Nectaire and French pastry. Thanks to my team mates, and again thanks so much for the Saint Nectaire. Write-up for the Crypto challenge: https://cryptax.github.io/auvergn2026-crypto/

  • Post #1842501

    Devastating privilege escalation on Linux: https://copy.fail/ Explanation: https://xint.io/blog/copy-fail-linux-distributions Implementation in Go: https://github.com/badsectorlabs/copyfail-go ... and I learned today that there are AF_ALG socket types, to access cryptographic functions of the kernel. #Linux #CVE-2026-31431 #crypto #AF_ALG

  • Post #690090

    Message privé: bisous maman ! #24ans #heaven

  • Post #690089

    Je viens de passer ~1 jour à avoir un environnement de développement stable avec Android Studio. Entre toutes les horreurs de gradle, de dependancies bizarre, d&amp;#39;émulateur qui était trop lent etc. Makefile, c&amp;#39;était pas parfait, mais au moins c&amp;#39;était bien scriptable et compact. Là, je continue à pester contre ces nouveautés qui n&amp;#39;améliorent au final rien. #jaimeraler #frustration #android

  • Post #690087

    https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/ #Android #malware #AI

  • Post #690085

    @davbucci --&amp;gt; @ghspacefr peut être ?

  • Post #690083

    Il n&amp;#39;y avait pas de lumière dans ces toilettes. Je suppose que là, c&amp;#39;était parce que c&amp;#39;est inutile aux malvoyants ? #humour

  • Post #690081

    Je ne savais pas que Cline, dans VS, était capable d&amp;#39;ouvrir un navigateur et d&amp;#39;aller cliquer là où il faut se loguer et faire les taches demandées. Wow. #IA

  • Post #690079

    RE: https://infosec.exchange/@laluka/116227151646437596 Ph0wn CTF Social Challenge. So many awesome submissions, I enjoyed seeing them all, and this one is particularly excellent :) #ph0wn

  • Post #690078

    Y a qqun qui me dit demande si j&amp;#39;ai du temps pour discuter avec lui sur un sujet. Ma réponse est &amp;quot;non désolée, pas avant la fin de la semaine prochaine&amp;quot;. Et il insiste &amp;quot;je dois rendre ma réponse vendredi&amp;quot;. Certes. Mais qu&amp;#39;est-ce qui n&amp;#39;est pas suffisamment précis dans le &amp;quot;non&amp;quot; et &amp;quot;pas avant la fin de la semaine prochaine&amp;quot; ? ;-) NB. Je fais rarement ce genre de réponses.

  • Post #389529

    Retrieved a printed copy of PagedOut at BlackAlps! Awesome! Nice to read, good paper quality and colors :) @PagedOut

  • Post #389525

    RE: https://infosec.exchange/@PagedOut/115315462232710825 PagedOut #7 is out. I recomment page 66 ;-) #linux #trigona #ransomware #r2ai