the grinch  

149 Followers
292 Following
595 Posts

Programmer, Hacker, shit poster.
Powered by Arch linux 

Yes, I run @cve

Programming is funSo is hacking'; DROP TABLES posts#
CVE'snone yet, or ever probably I like my vulns
We've just published "Making desync attacks easy with TRACE" by new PortSwigger Research member Martin Doyenhard!
https://portswigger.net/research/trace-desync-attack
Making desync attacks easy with TRACE

Have you ever found an HTTP desync vulnerability that seemed impossible to exploit due to its complicated constraints? In this blogpost we will explore a new exploitation technique that can be used to

PortSwigger Research
GhostRace - Exploiting and Mitigating Speculative Race Conditions (CVE-2024-2193) https://www.vusec.net/projects/ghostrace/
GhostRace - vusec

Exploiting and Mitigating Speculative Race Conditions GhostRace: CVE-2024-2193 Race conditions arise when multiple threads attempt to access a shared resource without proper synchronization, often leading to vulnerabilities such as concurrent use-after-free. To mitigate their occurrence, operating systems rely on synchronization primitives such as mutexes, spinlocks, etc. In this work, we present GhostRace, the first security … Continue reading GhostRace →

vusec
So Long And Thanks For All The Flights: Ingenuity Permanently Grounded After 72 Flights

Just a few hours ago, NASA dropped some devastating news: Ingenuity will fly no more. Three years after dropping from the belly of the Perseverance rover and after 72 flights through the thin Marti…

Hackaday

the reason i am excited about WebAssembly is because it's the first interesting computer architecture designed in the last 30 to 40 years (unlike e.g. RISC-V)

people who have not looked at how Wasm works usually don't get it, which makes me sad

1Password, a popular password management platform used by over 100,000 businesses, suffered a security breach after hackers gained access to its Okta ID management tenant.

https://www.bleepingcomputer.com/news/security/1password-discloses-security-incident-linked-to-okta-breach/

1Password discloses security incident linked to Okta breach

1Password, a popular password management platform used by over 100,000 businesses, suffered a security incident after hackers gained access to its Okta ID management tenant.

BleepingComputer

Malachite #16D542
Outer Space #2F3C3A

(Contrast ratio: 5.8:1 | AA)

GPUs from all major suppliers are vulnerable to new pixel-stealing attack

A previously unknown compression side channel in GPUs can expose images thought to be private.

Ars Technica

Due to lack of time on my #OBTS talk, here's one of the bugs that didn't make the cut:
"unnamed app sandbox escape", aka CVE-2023-32364

https://gergelykalman.com/CVE-2023-32364-a-macOS-sandbox-escape-by-mounting.html

CVE-2023-32364 - a macOS sandbox escape by mounting

This post is a writeup of CVE-2023-32364, a macOS application sandbox escape bug I found. It was supposed to be unveiled in my upcoming talk: "Unexpected, Unreasonable, Unfixable: Filesystem Attacks on macOS" at OBTS v6, but I needed to cut some bugs out. This is one of them. macOS Sandboxing …

Gergely's hack blog
Hey, good job patching all your browsers for the latest WebP vulnerabilities (which, as of today, have a CVE).

Know what probably didn't get updated?

Yeah, all those Electron apps.

Hey y'all! I finished the first part of the SIM module series (where I review and test the cheapest LTE modules from #aliexpress).
This is about the cheapest module I could find, the 7€ FS800E.

Here's the link: https://tudbut.de/fs800e.html

In short: It connects to the network fine and seems to work in theory, but it seems to have issues with the APN setup, resulting in internet not being available. If I find a fix (which I've been searching for and asking the seller about for a few days now to no avail), I will update the article.

Please consider donating at https://paypal.me/tudbut to keep this series alive as I can't afford it otherwise (make sure to specify that its for the SIM module reviews). I already have 3 other modules being shipped to me right now, and some ideas for which to review next.

Whenever I review a module (including this one), I include documentation and any quirks I come across that got me stuck at first.

#arduino #mcu #microcontrollers #raspberrypi #lte #sim #iot #review