Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

~swapgs

@swapgs@infosec.exchange
  • Open on infosec.exchange

zigzagging my way through cursed code and bugs

0 Followers
0 Following
8 Posts
Joined November 07, 2022
blog:
https://swap.gs

Posts

Open post
swapgs
~swapgs @swapgs@infosec.exchange · Jul 21, 2026
~swapgs
@swapgs@infosec.exchange

zigzagging my way through cursed code and bugs

infosec.exchange
Replying to @buherator@infosec.place
#music #mathcore Hover or focus to reveal Sensitive
@buherator@infosec.place The Dillinger Excel Plan! Loved the video :)
0
0
0
0
Open post
swapgs
~swapgs @swapgs@infosec.exchange · Jul 18, 2026
~swapgs
@swapgs@infosec.exchange

zigzagging my way through cursed code and bugs

infosec.exchange
Replying to @raptor@infosec.exchange
@raptor@infosec.exchange still missing the RCE :P
0
0
0
0
Open post
swapgs
~swapgs @swapgs@infosec.exchange · Jun 28, 2026
~swapgs
@swapgs@infosec.exchange

zigzagging my way through cursed code and bugs

infosec.exchange
RE: https://infosec.exchange/@wdormann/116819969049945466 Be more like @wdormann@infosec.exchange! It takes literally 5 minutes to see that all these so-called bugs are pure slop :(
Quoting
Will Dormann @wdormann@infosec.exchange
Somebody posted a bunch of exploits on GitHub that claim to be 0days. https://github.com/bikini/exploitarium Let's look at the first one: A 7-Zip MotW bypass. Problem #1: 7-Zip DOESN'T EVEN WRITE MOTW FOR EXTRACTED FILES BY DEFAULT. This doesn't have a CVE, because apparently CVE is difficult. Problem #2: If you are a security-conscious person who enabled writing MotW in 7-Zip extracted files (contratulations!), you might notice that the archive contains a :Zone.Identifier:$DATA (MotW ADS) file in it and recognize shenanigans. Problem #3: When you extract the file, you will be presented by the following dialog asking if you want to overwrite the ::DATA (primary data stream) of the file. And if you got this far, you're a security-conscious person, so you won't do this. If you get past all of those hurdles, and click Yes in the dialog, then yes, you'll have a file extracted from a RAR that came from the internet that contains an attacker-controlled MotW (that says it didn't come from the internet). Is this a vulnerability? Sure. But it both relies on a non-default 7-zip configuration, and it also relies on user interaction to succeed. As such, I can't say that I'm terribly interested in it. How about the other 22 exploits in the repo? I skimmed through a few, and some seem quite contrived (sort of like the 7-zip one), but some may be legit. But alas, I don't have the mental fortitude to sift through it all, based on what I've seen. Maybe somebody else here will.
Open quoted post
0
0
0
0
Open post
swapgs
~swapgs @swapgs@infosec.exchange · Feb 20, 2026
~swapgs
@swapgs@infosec.exchange

zigzagging my way through cursed code and bugs

infosec.exchange
Replying to @swapgs@infosec.exchange
@postmodern For the price question, you can already go pretty far with 2nd hand NUC / Mac minis. Google will also happily run your harness on their oss-fuzz infra (and pay bounties for good integrations in upstream projects)
0
0
0
0
Open post
swapgs
~swapgs @swapgs@infosec.exchange · Feb 20, 2026
~swapgs
@swapgs@infosec.exchange

zigzagging my way through cursed code and bugs

infosec.exchange
Replying to @postmodern@infosec.exchange
@postmodern Oh yeah in that case don’t worry, you will come across a few other bottlenecks before really maxing out your compute with meaningful operations :)
0
1
0
0
Open post
swapgs
~swapgs @swapgs@infosec.exchange · Feb 18, 2026
~swapgs
@swapgs@infosec.exchange

zigzagging my way through cursed code and bugs

infosec.exchange
Replying to @postmodern@infosec.exchange
@postmodern What are you fuzzing?
0
3
0
0
Open post
swapgs
~swapgs @swapgs@infosec.exchange · Dec 04, 2025
~swapgs
@swapgs@infosec.exchange

zigzagging my way through cursed code and bugs

infosec.exchange
Replying to @buherator@infosec.place
@buherator @kaitai @nlnet fuzzers go brrrr
1
0
0
0
Open post
swapgs
~swapgs @swapgs@infosec.exchange · Aug 19, 2025
~swapgs
@swapgs@infosec.exchange

zigzagging my way through cursed code and bugs

infosec.exchange
Replying to @ludicity@mastodon.sprawl.club
@ludicity@mastodon.sprawl.club "Huuum let me think about thaaaat" for 30 seconds and then proceeds to give a shallow encyclopedic definition of the keywords in the question while reading from another screen. To be fair, I’m not against Googling or LLMs _if_ they disclose it beforehand, but it shouldn’t be necessary on question about the achievements picked from their resume :)
0
3
0
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 13:48:12 UTC