Mr. Bitterness

3.9K Followers
564 Following
2.5K Posts
I play with vulnerabilities and exploits, but am forbidden to discuss such things publicly.
I used to be https://twitter.com/wdormann but Twitter has become unbearable, so here I am.
I can't explain why, but I get some amount of enjoyment knowing that there is a song out there titled Pale Vegan Hip Pain.
https://www.youtube.com/watch?v=2m_TJSvUZzM
Pale Vegan Hip Pain

YouTube

> builds a GRUB replacement in 2016
> spends 5 years breaking GRUB piece by piece
> strips LUKS encryption from /boot "for security"
> proposes to remove: btrfs, xfs, zfs
> keeps SquashFS, two CVEs, one rated 7.8 HIGH
> controls the signing keys for all of it
> Canonical promoted him.

https://www.sambent.com/canonicals-grub-saboteur-has-a-10-year-plan

@nzie0z
Hm, well that's something.
No, I haven't been in a casino for quite a while.
@rx13 @ftg @f4grx
Yeah, I looked at it briefly. It listens on 53/tcp.
I couldn't be bothered to dig deeper.
Gambling is illegal for kids.
Can anyone at FanDuel Casino say with a straight face that this ad is indeed targeting adults?

‼️H&R Block Business 2025 Backdoor‼️

I found a TLS backdoor in H&R Block software. They install a wildcard root CA (expiry 2049) into your trusted root certificate store and include the private key in the application DLL.

https://www.youtube.com/watch?v=5paxvYkz1QE

https://hrbackdoor.yifanlu.com

H&R Block Business 2025 Backdoor Exposed

YouTube
@f4grx
You have a unreasonable expectation of skills from the masses.
"Connect your phone device to a random/looking Wi-Fi and the launch your web browser and load "
Grandma ain't doing this. 😂
@f4grx
For less than $5. OK. 😂