raptor
raptor@infosec.exchange
<p>When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl.</p>
Posts
-
View post
Extending #Scapy for #Hardware Reverse Engineering https://voidstarsec.com/blog/scapy-spi-reconstruction
-
View post
πππ πππ@phrack@haunted.computer #KeepHacking
-
View post
TIL newly created #GitHub repositories are no longer automatically watched π€ https://github.com/orgs/community/discussions/157470
-
View post
#nickcave is a fucking amazing performer π₯
-
View post
Since I picked up programming at 8yo with BASIC, I've been a bit of a language polyglot. Over the years I've coded in C, Python, Perl, Shell, more flavors of Assembly than I care to admit, occasionally C++, Go, Java and JavaScript, and heck, even PowerShell. Then a couple of years ago I started taking #Rust seriously, and I basically haven't touched anything else since. Anyway, here's where that obsession led. This summer's #GitHub tour, part two: My vulnerability-hunting...
-
View post
RE: https://chaos.social/@floyd/117016209667321974 βMaybe companies should have a panel of middle schoolers on their payroll to review logos before launch.β π― π
-
View post
RE: https://infosec.exchange/@david_chisnall/117007707710681727 βAll encryption is end-to-end, if youβre not picky about the ends.β -- Chris Fenner
-
View post
It's that time of year again βοΈ The sun is out, deadlines are theoretically on hold, and somewhere a towel is being packed. Following tradition, here's a summer round-up of a few #GitHub projects that might come in handy for your work, your hobbies, or just some quality holiday reading for nerds. First up, freshly updated: my @semgrep@infosec.exchange ruleset for vulnerability research in C, occasionally C++, and quite often decompiled pseudocode. The ruleset: https://github.com/0xdea...
-
View post
The husk of a cool #bug
-
View post
RE: https://mstdn.social/@spaf/116986965448090055 James Anderson in 1972: https://csrc.nist.gov/files/pubs/conference/1998/10/08/proceedings-of-the-21st-nissc-1998/final/docs/early-cs-papers/ande72.pdf
-
View post
I stumbled upon this analysis of the Internet #worm, written in 1988 by none other than @spaf@mstdn.social. Is this the first public document on buffer overflow exploitation? I love the level of detail π https://spaf.cerias.purdue.edu/tech-reps/823.pdf?pdf_direct=1
-
View post
@jadedtwin@corteximplant.com @buherator@infosec.place itβs the only way to learn really
-
View post
The new #IDA UI quality of life improvements are pretty nice, especially jump anywhere and pathfinder. I'm starting to like them! https://hex-rays.com/blog/ida-9.4-smarter-navigation-and-quality-of-life-improvements Digging deeper into the SDK now, some recent changes in IDA 9.4 might impact my idalib-based plugins (hopefully in a good way).
-
View post
#OpenAI and #HuggingFace partner to address #security #incident during model evaluation https://openai.com/index/hugging-face-model-evaluation-security-incident/ Wow π€―
-
View post
π€― wp2shell (CVE-2026-63030): Pre-Auth #RCE Chain in #WordPress Core βWordPress patched it in 6.9.5 and 7.0.2, touching three files and sixteen lines. This post covers what broke, why the bugs connect, and what teams running WordPress need to do.β https://fullhunt.io/blog/2026/07/17/wp2shell-wordpress-core-pre-auth-rce-cve-2026-63030.html
-
View post
@InfoCon@defcon.social thank you for the service you provide to the community π«‘
-
View post
RE: https://infosec.exchange/@raptor/116941213445764051 In light of the recent news on the demise of #Infiltrate conference videos on #vimeo, Iβm happy to announce that Iβve uploaded the videos of my two talks here: INFILTRATE 2019 - Marco Ivaldi - A bugβs life: story of a Solaris 0day https://youtu.be/e6hYrFHkXcU INFILTRATE 2020 - Marco Ivaldi - The INFILTRATE effect: 6 bugs in 6 months https://youtu.be/G8vhifVUmg4 For older videos, see also the @InfoCon@defcon.social archive: https://info...
-
View post
It looks like #Immunity videos, including #Infiltrate conference videos are not available anymore? What a shame, a piece of #hacking history gone. https://vimeo.com/user18478112
-
View post
π https://github.com/Icex0/wp2shell-poc
-
View post
RE: https://infosec.exchange/@hnsec/116923239649243702 My #Semgrep C/C++ ruleset is ready for prime time again! Grab it before our new robot overlords take over the field of #VulnerabilityResearch entirely π€
-
View post
π https://github.com/MSNightmare/LegacyHive
-
View post
#Bugs #Rust Won&#39;t Catch https://corrode.dev/blog/bugs-rust-wont-catch/
-
View post
#CodeQL zero to hero part 2: getting started with CodeQL https://github.blog/2023-06-15-codeql-zero-to-hero-part-2-getting-started-with-codeql/ Part 1 is here: https://github.blog/2023-03-31-codeql-zero-to-hero-part-1-the-fundamentals-of-static-analysis-for-vulnerability-research/
-
View post
βI think we are all aware that defensive strategies in cyber are rarely based on available data.β β @dave_aitel@mastodon.social https://seclists.org/dailydave/2024/q4/1
-
View post
Outstanding work by @chompie1337, @aaronportnoy, and @fabiusartrel@twitter.com #MSMQ QueueJumper (#RCE #Vulnerability): An In-Depth Technical Analysis https://securityintelligence.com/posts/msmq-queuejumper-rce-vulnerability-technical-analysis/
-
View post
lol https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/
-
View post
@badsectorlabs hey! Re: https://blog.badsectorlabs.com/taking-a-break-2026-04-06.html I just wanted to thank you for your precious work all these years. Iβve really enjoyed your weekly feed. Best of luck with Ludus! π₯
-
View post
@REverseConf@infosec.exchange @xorpse@infosec.exchange oh cool, looking forward to this!