Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @FidgetingBits
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @FidgetingBits
-
fidgeting bits proslijedio/la je Tweet
Remote shell metacharacter injection and command-execution as root in an SMTP server... what year is it again?https://twitter.com/window/status/1222345450629423104 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
Any tips for dealing with inlined functions in ghidra? E.g., I’d like to say “this group of blocks is definitely its own function. Please treat that as scope for variable names, etc.”
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Anyone know of a way to suppress Windbg Preview spitting out the function name when it is run via 'dx @$scriptContents.method()'. The only suggestion I found here https://stackoverflow.com/questions/57316025/can-i-suppress-windbg-dx-behavior-of-echoing-the-command … doesn't work
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
Any interest for a new Windows kernel exploitation training on Windows 10 focusing on methodology and hands on exploitation? Analyzing one bug step-by-step from patch diffing up to exploitation, with a focus on generically targeting a previously unknown kernel component.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
From the Captain himself.. some clarity about the Ghidra Version Tracking design goalshttps://twitter.com/ArrrCaptain/status/1197270105182363650 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
Used lib2to3 to migrate my IDA Python code away from the older IDC APIs. It's really gross and has issues, but maybe it'll help others too:https://gist.github.com/WanderingGlitch/a033beb47fe8676e91aaff810c363d46 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The more in depth blog series is currently undergoing technical review, so we hope to start posting it relatively soon, but still not sure exactly when.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Here are my slides from
#POC2019 about exploiting CVE-2018-8611: https://www.nccgroup.trust/globalassets/poc2019/cve_2018_8611_windows_ktm_exploitation_poc2019.pdf … Super fun bug to exploit imo. Most common question was if the inc primitive is really practical. The answer is yes. Use a series of 8 single byte increments at different addr alignments.Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
1903 use the delta compression API, maybe 1809 also moved to that. msdelta.dll is your friend for applying it (remove the first fourth bytes it is a CRC )
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
Hey followers, are MSUs for Windows 10 1809 not containing the actual patched PE files anymore? Seem they contain .exe, etc. files but they are small like 90kb and don't contain the MZ header, etc. Or am I doing it wrong?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I had a great time at POC2019. Thanks
@POC_Crew@vangelis_at_POC for letting me present. You do a great job running the con. Seoul is a beautiful city and I will definitely return!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
Released to go with my
#POC2019 talk, a project which contains a C# client for almost every ALPC RPC server on Windows 7 through Windows 10 1909. Could be useful for EoP research, fuzzing etc.https://github.com/tyranid/WindowsRpcClients …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
Microsoft symbol server is experiencing an outage. No ETA to a fix yet.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
I am writing a new method for
#Diaphora to be able to write scripts for the diffing process. The idea is that, sometimes, there are some rules that can be used to match functions when diffing that, however, aren't generic and don't make sense to add as generic heuristics.Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
#Ghidra Version Tracking Correlator for Patch Diffing Blog: https://blog.threatrack.de/2019/10/10/ghidra-correlator/ … Github (pre-alpha prototype!): https://github.com/threatrack/ghidra-patchdiff-correlator … Unlike the included binary-only Correlators, the Similarity Score of this ranges from 0 to 1. So you see how much a function changed.https://twitter.com/0x6d696368/status/1181992202202963968 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
What would you use to debug a native library loaded by a closed-source Android APK? It seems gdb segfaults after setting a bp. Any thought?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
Someone are maintaining a version of VirtualKD (called VirtualKD-Redux) that supports (among other things) VMware Workstation 15.5.0. https://github.com/4d61726b/VirtualKD-Redux …https://twitter.com/hjy79425575/status/1176458340815163392 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
Is there any open source grammar based fuzzer for Windows kernel APIs (similar to what domato is for browser)? Please RT
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
For structures, the technique of recompiling the PDB works great:https://twitter.com/windbgtips/status/1090132030111637504 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
fidgeting bits proslijedio/la je Tweet
Does anyone know an IDA Pro plugin to create .pdb files based on function names and other symbols in the .idb? I've only found https://github.com/Mixaill/FakePDB but nothing beyond that.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.