Elektrine lite

← Feed

raptor

raptor@infosec.exchange

<p>When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl.</p>

Posts

  • Post #4440231

    TIL newly created #GitHub repositories are no longer automatically watched 🤌 https://github.com/orgs/community/discussions/157470

  • Post #4391135

    #nickcave is a fucking amazing performer 🔥

  • Post #4347134

    Since I picked up programming at 8yo with BASIC, I&#39;ve been a bit of a language polyglot. Over the years I&#39;ve coded in C, Python, Perl, Shell, more flavors of Assembly than I care to admit, occasionally C++, Go, Java and JavaScript, and heck, even PowerShell. Then a couple of years ago I started taking #Rust seriously, and I basically haven&#39;t touched anything else since. Anyway, here&#39;s where that obsession led. This summer&#39;s #GitHub tour, part two: My vulnerability-hunting...

  • Post #4292908

    RE: https://chaos.social/@floyd/117016209667321974 “Maybe companies should have a panel of middle schoolers on their payroll to review logos before launch.” 💯 🍑

  • Post #4239229

    RE: https://infosec.exchange/@david_chisnall/117007707710681727 “All encryption is end-to-end, if you’re not picky about the ends.” -- Chris Fenner

  • Post #4235115

    It&#39;s that time of year again ☀️ The sun is out, deadlines are theoretically on hold, and somewhere a towel is being packed. Following tradition, here&#39;s a summer round-up of a few #GitHub projects that might come in handy for your work, your hobbies, or just some quality holiday reading for nerds. First up, freshly updated: my @semgrep@infosec.exchange ruleset for vulnerability research in C, occasionally C++, and quite often decompiled pseudocode. The ruleset: https://github.com/0xdea...

  • Post #4185621

    The husk of a cool #bug

  • Post #4118293

    RE: https://mstdn.social/@spaf/116986965448090055 James Anderson in 1972: https://csrc.nist.gov/files/pubs/conference/1998/10/08/proceedings-of-the-21st-nissc-1998/final/docs/early-cs-papers/ande72.pdf

  • Post #4105187

    I stumbled upon this analysis of the Internet #worm, written in 1988 by none other than @spaf@mstdn.social. Is this the first public document on buffer overflow exploitation? I love the level of detail 💚 https://spaf.cerias.purdue.edu/tech-reps/823.pdf?pdf_direct=1

  • Post #4086365

    @jadedtwin@corteximplant.com @buherator@infosec.place it’s the only way to learn really

  • Post #4038627

    The new #IDA UI quality of life improvements are pretty nice, especially jump anywhere and pathfinder. I&#39;m starting to like them! https://hex-rays.com/blog/ida-9.4-smarter-navigation-and-quality-of-life-improvements Digging deeper into the SDK now, some recent changes in IDA 9.4 might impact my idalib-based plugins (hopefully in a good way).

  • Post #3996235

    #OpenAI and #HuggingFace partner to address #security #incident during model evaluation https://openai.com/index/hugging-face-model-evaluation-security-incident/ Wow 🤯

  • Post #3931130

    I did a summer thing: https://github.com/0xdea/ttyinject-rs It’s a simple #rust port of @thc@infosec.exchange’s ttyinject, created mostly as an excuse to try out @zed’s remote development feature via SSH (TL;DR it works pretty well, but there are some rough edges here and there). The old-school technique behind the #exploit is fascinating, you might not know it. Too bad it’s sort of obsolete now.

  • Post #3928114

    🤯 wp2shell (CVE-2026-63030): Pre-Auth #RCE Chain in #WordPress Core “WordPress patched it in 6.9.5 and 7.0.2, touching three files and sixteen lines. This post covers what broke, why the bugs connect, and what teams running WordPress need to do.” https://fullhunt.io/blog/2026/07/17/wp2shell-wordpress-core-pre-auth-rce-cve-2026-63030.html

  • Post #3928011

    @InfoCon@defcon.social thank you for the service you provide to the community 🫡

  • Post #3912886

    RE: https://infosec.exchange/@raptor/116941213445764051 In light of the recent news on the demise of #Infiltrate conference videos on #vimeo, I’m happy to announce that I’ve uploaded the videos of my two talks here: INFILTRATE 2019 - Marco Ivaldi - A bug’s life: story of a Solaris 0day https://youtu.be/e6hYrFHkXcU INFILTRATE 2020 - Marco Ivaldi - The INFILTRATE effect: 6 bugs in 6 months https://youtu.be/G8vhifVUmg4 For older videos, see also the @InfoCon@defcon.social archive: https://info...

  • Post #3911536

    It looks like #Immunity videos, including #Infiltrate conference videos are not available anymore? What a shame, a piece of #hacking history gone. https://vimeo.com/user18478112

  • Post #3906248

    👀 https://github.com/Icex0/wp2shell-poc

  • Post #3828818

    RE: https://infosec.exchange/@hnsec/116923239649243702 My #Semgrep C/C++ ruleset is ready for prime time again! Grab it before our new robot overlords take over the field of #VulnerabilityResearch entirely 🤖

  • Post #3827168

    👀 https://github.com/MSNightmare/LegacyHive

  • Post #1779129

    #Bugs #Rust Won&amp;#39;t Catch https://corrode.dev/blog/bugs-rust-wont-catch/

  • Post #1741767

    #CodeQL zero to hero part 2: getting started with CodeQL https://github.blog/2023-06-15-codeql-zero-to-hero-part-2-getting-started-with-codeql/ Part 1 is here: https://github.blog/2023-03-31-codeql-zero-to-hero-part-1-the-fundamentals-of-static-analysis-for-vulnerability-research/

  • Post #1725060

    “I think we are all aware that defensive strategies in cyber are rarely based on available data.” — @dave_aitel@mastodon.social https://seclists.org/dailydave/2024/q4/1

  • Post #1649067

    Outstanding work by @chompie1337, @aaronportnoy, and @fabiusartrel@twitter.com #MSMQ QueueJumper (#RCE #Vulnerability): An In-Depth Technical Analysis https://securityintelligence.com/posts/msmq-queuejumper-rce-vulnerability-technical-analysis/

  • Post #1564633

    lol https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/

  • Post #1020774

    @badsectorlabs hey! Re: https://blog.badsectorlabs.com/taking-a-break-2026-04-06.html I just wanted to thank you for your precious work all these years. I’ve really enjoyed your weekly feed. Best of luck with Ludus! 🥂

  • Post #309526

    [CVE-2022-40303] Integer overflow in xmlParseNameComplex in libxml2 
// by @maddiestone https://gitlab.gnome.org/GNOME/libxml2/-/issues/381

  • Post #131073

    @REverseConf@infosec.exchange @xorpse@infosec.exchange oh cool, looking forward to this!