Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Maxim Suhanov

@errno_fail@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Computer forensics, computer forensics tool validation, etc.

https://dfir.ru
https://github.com/msuhanov/

🕊

0 Followers
0 Following
4 Posts
Joined December 19, 2022
Open post
Maxim Suhanov @errno_fail@infosec.exchange
· 2mo ago
Replying to @Rairii@labyrinth.zone
@Rairii@labyrinth.zone, yeah that makes no sense. Sounds like slop.
1
0
0
0
Open post
Maxim Suhanov @errno_fail@infosec.exchange
· 2mo ago
In 2022, Microsoft decided to propagate Mark-of-the-Web into mounted containers. Here is how they did that and why third-party code (like WinRar) still fails to correctly propagate the Zone.Identifier ADS. https://dfir.ru/2026/06/29/mark-of-the-web-the-rules-changed-the-tools-didnt/
0
0
0
0
Open post
Maxim Suhanov @errno_fail@infosec.exchange
· 2mo ago
Replying to @Rairii@labyrinth.zone

@Rairii@labyrinth.zone,

CVE-2026-6688

Sounds like "if you don't check your buffer size, our callee is vulnerable in your caller's code"... What?

CVE-2026-6687

As a side note, Microsoft violated the spec: "According to [EXFAT 1.00], the volume label limit is 11 characters. However, at least one third-party implementation (exfatlabel) and one old official implementation (the Windows 7 exFAT driver) allow 15 characters".

CVE-2026-6682

Sounds like "you can hack your own device without using a debugger". They state that this results in a buffer overflow (reading more bytes into a fixed-size buffer).

0
1
0
0
Open post
Maxim Suhanov @errno_fail@infosec.exchange
· 2mo ago
Replying to @Rairii@labyrinth.zone

@Rairii@labyrinth.zone,

https://github.com/runZeroInc/vulns-2026-fatfs-chance/blob/main/02_CRITICAL.md#0-espressif-esp-idf--espressifesp-idf

Their write-up suggests that vulnerable external code trusts the file size from stat(), uses it in malloc(), then reads via read(), and read() fills more bytes than stat() reported.

The problem is: the mismatch between the reported file size and the readable data size is so common, so one must never use that stat()->malloc()->read() path.

A simple FAT corruption triggers that (the interrupted update chain is enough: the FAT records a longer cluster chain while a directory entry wasn't updated due to a power loss or a crash).

Even NTFS does that (the file size reported via readdir()-like calls can be different than the file size reported via the stat()-like calls).

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 15:43:22 UTC