larsborn

@larsborn@infosec.exchange
94 Followers
128 Following
105 Posts
Malware Analyst, Reverse Engineer, Software Developer, Mathematician, Teacher, Podcaster, send cat pics
Websitehttps://www.wallenborn.net
Podcasthttps://armchairinvestigators.de
Reversing Classeshttps://mal.re
So #BinaryRefinery 0.8.25 is out with support for the latest Inno Setup installer files, but more importantly the repo has 4000 commits!!

Yes, a file full of zero bits transfers faster over USB2.0 than a file full of one bits.

I've known this forever but it still feels ridiculous when you actually test it and it's true!

USB truly is cursed.

You don't see toys like this around anymore. The Atomic Energy Lab set was available from 1951 to 1952 and sold for a whopping $50.

"The set came with four types of uranium ore, a beta-alpha source, a pure beta source, a gamma source, a spinthariscope, a cloud chamber, an electroscope, a geiger counter, and a manual."

More here 🤯:
https://interestingengineering.com/culture/radioactive-toy-deemed-world-most-dangerous

#Science #Toys

The #homeautomation protocol is named #Thread, perhaps that is a typo as #Threat is more apt and accurate. If you roll your own device you might very well experience the full force of their blood thirsty lawyers.

What the actual F.

Thread - the tech we can't use or teach - Dennis Schubert

Random thoughts, articles and projects by a chronic overengineer.

0011882: A perfectly normal dwarf baron from a dwarf civ threw one of their 1 year infant child into a beast pit.

🚨 RIFT Update:
We’ve boosted our compiler detection! 🛠️
Now with sharper insights into binaries built using GNU, MinGW, and MSVC toolchains.
More enhancements are on the way—stay tuned! 🔍✨
#ReverseEngineering #MalwareAnalysis #RIFT #malware #msft

https://github.com/microsoft/RIFT

GitHub - microsoft/RIFT: Rust Library Recognition Project for Rust Malware by the MSTIC-MIRAGE Team

Rust Library Recognition Project for Rust Malware by the MSTIC-MIRAGE Team - microsoft/RIFT

GitHub

Did you know that new #Emoji can be proposed by anyone, simply by following some guidelines laid out by the #Unicode consortium? There's a time window each year where they accept proposals, and a select few might make it into future sets.

This year I turned one in: "Circuit Board", which I was surprised to find 1. didn't exist and 2. had not been proposed before (though CPU and Microchip have both been submitted and declined in the last 5 years)

You can read my proposal here:
https://storage.googleapis.com/greg-kennedy.com/Proposal%20for%20Emoji%20%E2%80%9CCircuit%20Board%E2%80%9D.pdf

and you can see the Unicode emoji proposal guidelines here:
https://www.unicode.org/emoji/proposals.html

Anyway, the odds aren't great of getting accepted, but if it IS then you can say "hey! I know the guy who submitted that one!"

Attached are the sample images I drew up for the proposal - which, incidentally, are now Public Domain as well. Enjoy!

@SebastianWalla, Steffen Haas, @tillmannwerner, and myself will present a .NET instrumentation framework tomorrow at @recon 2025 in Montreal. Here's a humble brag sneak peek demo-ing how easy it is to write a function tracer!

For "all my new followers" here: if you are able to understand German, I'm podcasting since a couple of years now. Throughput is limited but we are at 10 episodes now (and counting). Chris' and my format is somewhere in between "two guys just talking" and "reading a lecture script". Hence the limited throughput: we just need a bit of time to prepare each episode.

Anyway, here's the URL: https://armchairinvestigators.de/ you can listen to it directly on the site or just search for "Armchair Investigators" on your favorite Podcast platform (how to actually get your self-hosted Podcast distributed is also a funny story, but more for a blag post, I think).

Oh yeah: our goal is to make cyber accessible to everyone (even your parents) while still being interesting for the average nerd. Topics for example are the Triton/Trisis case, cyber operations by the GRU, Olympic Destroyer, etc.

If you can't understand German but might have people who do, I'd very much appreciate a forward or mention 🙇

Armchair Investigators – Ein Dialog über Malware, Cybercrime und Cyberspionage

Ein Dialog zu Malware, Cybercrime, und Cyberspionage in Podcast-Form von Christian Dietrich und Lars Wallenborn

RULECOMPILE - Undocumented Ghidra decompiler rule language

https://msm.lt/re/ghidra/rulecompile/

#Ghidra #Decompiler

RULECOMPILE - Undocumented Ghidra decompiler rule language

Or “How I got annoyed by a poor decompilation so I unearthed a hidden Ghidra feature” TLDR: there is a (undocumented and disabled by default) feature in the Ghidra decompiler that lets you create your own decompiler passes, using a custom DSL. I leverage it to write a deobfuscation rule for a simple obfuscation technique. Story Setup - introduction and problem statement Decompiler 101 - building and using Ghidra decompiler directly RULECOMPILE - a curious #define flag from the decompiler source A forgotten language of dragons - reverse-engineering a forgotten code pattern matching DSL How to train your dragon - how to write a rule that is actually useful Conclusion - parting thoughts Story setup It all started with this one missed deobfuscation:

msm's home
×

Did you know that new #Emoji can be proposed by anyone, simply by following some guidelines laid out by the #Unicode consortium? There's a time window each year where they accept proposals, and a select few might make it into future sets.

This year I turned one in: "Circuit Board", which I was surprised to find 1. didn't exist and 2. had not been proposed before (though CPU and Microchip have both been submitted and declined in the last 5 years)

You can read my proposal here:
https://storage.googleapis.com/greg-kennedy.com/Proposal%20for%20Emoji%20%E2%80%9CCircuit%20Board%E2%80%9D.pdf

and you can see the Unicode emoji proposal guidelines here:
https://www.unicode.org/emoji/proposals.html

Anyway, the odds aren't great of getting accepted, but if it IS then you can say "hey! I know the guy who submitted that one!"

Attached are the sample images I drew up for the proposal - which, incidentally, are now Public Domain as well. Enjoy!

@greg
Good #emoji proposal!

I always worry how they’ll “read” at 18 px

If someone has to pick them out of a lineup the colour is great, but such things may need some perfect design for people to see what they are

See FAX MACHINE 📠? ROLODEX 📇? PAGER 📟?

(Thank you 2000s emoji developers)

We just did PHONOGRAPH but got denied too 😔

Tried to simplify the image

Maybe they didn’t like the trademark Grammy/RCA confusion?

Or our comparing w/ other emoji
https://www.dropbox.com/scl/fi/an0z2lff1106uav3fhhat/Proposal-for-Emoji_-PHONOGRAPH-RECORD-PLAYER-July-30.pdf?rlkey=gbh7mz16ylwac71nm8cqb1al7&st=27pzloxj&dl=0

@AccordionBruce Ah that's unfortunate! I reviewed the big list of denied proposals and there's quite a lot in there, so I don't have much hope in this one getting through. But at least I can say I tried :)

@greg
Pretty sure the 🪗 will be the most widely seen accomplishment of my life

Until/unless my kids do something fabulously famous/infamous

@greg
Totally worth doing the proposals either way. I love the genre combination of “Serious academic research grant” and “Please let billions of people use my tiny cartoon” 🙏🏼
#emoji

@greg it’s disappointing that a microchip was not approved.

I’m surprised there’s no Easter egg

@greg I was literally looking for a circuit board emoji three days ago - great timing!
@greg my favorite line from that proposal:
"Circuit Board is its own character."
yes! be independent! don't let the other characters tell you what you are! be yourself as you always were meant to be!
@greg @anthropy I love it! I was shocked there wasn’t even a CPU emoji. Any black IC with legs would do. It’s very symbolic and suitable for use as emoji.
@greg it's so weird seeing all those emojis in such an official proposal, even though it is literally an emoji proposal 😁
Instant approval
@greg There’s a surprising amount that haven’t been submitted