Profile_bird

Hey there! alexsotirov is using Twitter.

Twitter is a free service that lets you keep in touch with people through the exchange of quick, frequent answers to one simple question: What are you doing? Join today to start receiving alexsotirov's tweets.

Already using Twitter
from your phone? Click here.

alexsotirov

  1. Me: hi! Girl: hi, I'm a Playboy model. Me: WTF do I say to that?
  2. I could use NtAddAtom, but I am not sure adding thousands of random atoms is safe if you want to keep the process running after exploitation
  3. 156 bytes: resolve IsBadReadPtr, search for a 16-byte egg, copy the shellcode following the egg to a RWX page and execute it
  4. @halvarflake I wonder what they mean by "more aggressive ASLR". If the compiler DLLs have /dynamicbase:no, they shouldn't be rebased, no?
  5. @nicowaisman Yeah, the egghunter will have to be pretty big. But that's the only way to make it both reliable and portable.
  6. @dm557 The NtDisplayString syscall number is not constant across OS's, NtAddAtom has sideeffects. IsBadReadPtr is the best egghunter option.
  7. If you read Schneier you're already familiar with all these arguments, but this essay summarizes his ideas very well: http://bit.ly/4pC55
  8. Pro tip: to fix broken drag and drop in Fusion 3, completely remove the old VMware Tools and reinstall instead of doing an upgrade.
  9. I forgot that you can't have SEH handlers outside of image sections on Vista and now I have to rewrite my egghunter :-(
  10. Is Georgi Guninski coming out of retirement? Here's a Mozilla bug he found recently: http://bit.ly/29LBT7
  11. @drraid No, I work in complete silence.
  12. @postmodern_mod3 I agree that LLVM is a much better compiler system, but their FAQ said it was too large and slow for their needs.
  13. @drraid I think the runtime is in C, the compiler is a GCC frontend
  14. Is full disclosure so bad? The recent flaw in SSL was disclosed before the coordinated patch release was ready and yet the sky didn't fall.
  15. The design of Google's new language solves many of the problems of C and C++. Let's hope it's more successful than Plan9: http://golang.org
  16. @dinodaizovi We need to co-opt the PETA campaign against the senseless slaughter of sheep: http://bit.ly/4zNavt
  17. Microsoft should be ashamed of using legal threats to block the disclosure of the Bing cashback flaw: http://bit.ly/O7xY7 (cached blog post)
  18. Planning a trip to the Korean Demilitarized Zone tomorrow. It will be interesting to see the last remaining Cold War border in the world.
  19. @hdmoore Last night I drank with @beist until he fell asleep on the table!
  20. I think that we're well past the point where you could measure application security by the number of *reported* vulns: http://bit.ly/3S2t6D