Markus Vervier 👾

@marver
274 Followers
101 Following
153 Posts
right here, right now.
#3227 - Creation
I’m looking forward for Claude and friends to finally end the never ending stream of same type of bugs being hyped up for CVE marketing klout!
Everyone’s all about how Claude Code’s source “leaked” via a map file, when that thing could just reimplement itself without any map file.

Finally got around to uploading my slides for Reflections on trusting Zero Trust (or why I have zero trust in Zero Trust) from BSides London 2021:

https://github.com/timb-machine/presentations/blob/main/Reflections%20on%20Trusting%20Zero%20Trust%20-%20Why%20I%20have%20Zero%20Trust%20in%20Zero%20Trust%20v3.pdf

#engineering, #architecture

presentations/Reflections on Trusting Zero Trust - Why I have Zero Trust in Zero Trust v3.pdf at main · timb-machine/presentations

Presentations from yours truely. Contribute to timb-machine/presentations development by creating an account on GitHub.

GitHub
Anyone else noticed that Claude models seem to hate using uv and sneak in pip all the time?

❤️RELEASE: The TEAM-TESO cvs:

https://thc.org/team-teso/

Exploits, advisories, teso-informational (never released), burneye ELF crypter, bscan mass scanner, …plus some rare pictures.

Which 7350 exploit was your favourite?

Enjoy & Keep hacking,

Yours Sincerely,
Team-Teso (via THC’s bsky account).

Does calling AI agents 'bots' make you a boomer in 2026?

Due to $reasons I came across this blogpost https://www.elttam.com/blog/env/ about turning ENV variables into code execution which is nice. But the Python vector is depending on Perl, I didn't like that :P.

Digging a bit deeper in the code often helps, so it did this time:

Looking at https://github.com/python/cpython/blob/d73634935cb9ce00a57dcacbd2e56371e4c18451/Lib/webbrowser.py#L51-L52 I could simplify the payload to:

PYTHONWARNINGS='module::antigravity.' BROWSER='sh -c id #%s' python whatever.py
Hacking with Environment Variables - elttam

elttam is a globally recognised, independent information security company, renowned for our advanced technical security assessments.

9 out of 10 vibe coded security tools should be an MCP server.
"Aus Datenschutzgrünen bitten wir Sie Ihre Postleitzahl anzugeben.“ - Datenschutz falsch verstanden!