Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @taviso
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @taviso
-
Pinned Tweet
I finally wrote a small tool I've wanted for a long time: A parallel testcase minimizer. It's called halfempty, and I'm already finding it useful as part of my fuzzing workflow. /cc
@lcamtuf https://github.com/googleprojectzero/halfempty …pic.twitter.com/qleqrRbTDy
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
If you've tried using fancy semantic search tools for C, but gave up and stuck with grep... trust me, the tool you've been looking for is weggli. No setup or config needed, and it's not formal or heavyweight.
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Here's the prototype if anyone wants to help lol, send me PRs
https://github.com/taviso/katamascii …Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
I had a stupid idea for a game, "Katamascii" - like Katamari, but you roll around in your terminal collecting ascii art objects lol... I wasted my weekend on this
pic.twitter.com/2OTct8mkULShow this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
I needed to know the biggest possible size expansion from charset conversion to UTF-8 for an audit. I think the best is 12x, the single byte 0x82 in TSCII (Tamil Script) needs 4 3-byte UTF-8 codepoints. $ printf "\x82" | iconv -f tscii -t utf8 | wc -c 12
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Someone posted this pure-awk demoscene video to comp.lang.awk lolhttps://www.youtube.com/watch?v=j5aEjfBSQRI …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Yikes, we now have a working reproducer for Z_DEFAULT_STRATEGY.
https://www.openwall.com/lists/oss-security/2022/03/28/1 …https://twitter.com/taviso/status/1507781911023742976 …Thanks. Twitter will use this info to make your timeline better. UndoUndo -
If you didn't know, zlib is everywhere. You probably used zlib twenty times reading this tweet lol.
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Soo...there's this zlib bug that can cause errors for certain inputs. How bad is it? It depends on whether it affects all or only non-default configurations, but we don't know yet
If you're a data compression expert, you should help! https://www.openwall.com/lists/oss-security/2022/03/26/1 …Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Tavis Ormandy Retweeted
Up your security research skills: This Windows LoadLibrary port for Linux by
@taviso is a great project to contribute to. You'll learn how *both* OS's work internally. Use it to fuzz Win binaries faster on Linuxhttps://github.com/taviso/loadlibrary …Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Tavis Ormandy Retweeted
“We were not hacked.” “There was a hacking attempt.” “We were hacked, but it doesn't matter.” “2.5% of you were hacked.” “Getting hacked is actually good.” “I’m glad we were hacked.”
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Tavis Ormandy Retweeted
Thanks to
@___wr___ &@taviso, just played with CVE-2022-0778 against vulnerable (web) servers Just few tweaks, and ready to scan servers accepting certificates... 🫤 If it is not done yet: patch...pic.twitter.com/N86rbjlzNKShow this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
I genuinely have no idea how this managed to evade fuzzers for over a decade, something like p=697 a=1 b=1 x=696 would have found it...
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Haha, nice. I did it differently, but EC_POINT_set_compressed_coordinates() does call BN_mod_sqrt(p, (x^3 + ax + b) mod p), so you just need to solve for x with a composite p. AFAIK you can use any curve (even a=1 b=1 works). Also, der-ascii > asn1parse
https://twitter.com/___wr___/status/1505515632686735364 …Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Tavis Ormandy Retweeted
Picking parameters: https://www.imperialviolet.org/2022/03/15/pickingparameters.html …. (It was too long for Twitter.)
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
This was a fun one to work on,
@davidben__ helped track it down to a bug in the Tonelli-Shanks implementation in OpenSSL.https://twitter.com/RandoriAttack/status/1503770214638440454 …Thanks. Twitter will use this info to make your timeline better. UndoUndo -
I think build reproducibility is mostly useless, a big boondoggle. It's particularly annoying when proponents make big crazy security claims to justify it (e.g. "it will disincentivize violence against developers" wat..?), then when challenged switch to boring subjective claims
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
I got a Google alert this morning that someone had trademarked my name lol. What do you think, coincidence or elaborate troll?
https://trademarks.ipo.gov.uk/ipo-tmcase/page/Results/1/UK00003665189 …Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Tavis Ormandy RetweetedThanks. Twitter will use this info to make your timeline better. UndoUndo
-
Tavis Ormandy Retweeted
The guy who posts screenshots of strings in a dex file decompiled as x86 with little red arrows drawn on them would be really, really funny if he wasn’t getting retweets from thousands of genuinely concerned people with no ability to detect it’s nonsense
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Tavis Ormandy Retweeted
Has OMB been talking to
@taviso?
https://twitter.com/boblord/status/1486408717239160832 …Thanks. Twitter will use this info to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
