@Rairii@haqueers.com
@Rairii@haqueers.com avatar

Rairii

@Rairii@haqueers.com

Reversing (malware and otherwise); appsec and websec; embedded security; exploit dev; software preservationist; knows how not to use cryptography.

Currently finding bugs in Windows bootloaders.

You may also know me from capcom.sys.

#nobot

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Rairii, to random
@Rairii@haqueers.com avatar

This string was found by https://wetdry.world/@w - I have confirmed its presence in the Threads APK from apkcombo, "Threads, an Instagram app_289.0.0.68.109_apkcombo.com.apk", sha256 83a1f270aa2447f4e7310072b4d3217f9af8a03b7679b7760db03ff0bbf8e432, valid signature by "C=US, ST=California, L=Menlo Park, O=Meta Platforms Inc., OU=Meta Mobile, CN=Meta Platforms Inc." (rsa-4096 + sha-256, cert expires in 2053)

at offset 0xB7AE in assets/strings/en_GB.frsc

"Soon, you'll be able to follow and interact with people on other fediverse platforms, such as Mastodon. They can also find people on Threads using full usernames, such as <b>@%1$s</b>."

cc @FediPact

Rairii, to random
@Rairii@haqueers.com avatar

i don't think i've ever been so happy to see INACCESSIBLE_BOOT_DEVICE

Rairii, to random
@Rairii@haqueers.com avatar

if i had a nickel for every anti-cheat vendor whom implemented functionality in their driver to elevate the calling usermode process to PP/PPL, i would have two nickels. which isn't a lot, but it's weird that it happened twice

kernel-mode anticheat is malware.

Rairii, to random
@Rairii@haqueers.com avatar

stop disrupting adfraud operations

the adtech industry was never supposed to survive

years of programmatic auctions yet no real world use found for virtualising obfuscators IN JAVASCRIPT

wanted to watch numbers go up anyway for a laugh? we had a tool for that: it was called access logs

all the biggest adtech companies themselves do ad fraud, so you can't stop it, why bother taking down the obvious chinese botnets?

Rairii, to random
@Rairii@haqueers.com avatar

just attempted to run linux in my dolphin build

the ancient gc-linux-alpha seems to finish boot!

Rairii, to random
@Rairii@haqueers.com avatar

thedonald@sh.itjust.works

activitypub group on lemmy server, do I have to spell it out any further?

also the group's creator trump2020@sh.itjust.works

Rairii, to random
@Rairii@haqueers.com avatar

very close now!

Rairii, to random
@Rairii@haqueers.com avatar

so a set of interesting microsoft confidential media got dumped today

including a bunch of their anti-LAMP/anti-Linux propaganda from circa 2005

iso download: https://archive.org/download/ms-evangelism-rhythms-fy06rel01/Lamp101.iso

iso browse: https://archive.org/download/ms-evangelism-rhythms-fy06rel01/Lamp101.iso/

one of the powerpoint slides actually uses the term "Micro$oft", huh.

Rairii, to random
@Rairii@haqueers.com avatar

SYSSETUP RUNS NOW

Rairii, to random
@Rairii@haqueers.com avatar

progress is progress, the entire bugcheck text shows now

(oh, and I fixed the HAL text printing lol)

Rairii, to random
@Rairii@haqueers.com avatar
Rairii, to random
@Rairii@haqueers.com avatar

modified the registry HKLM\SYSTEM\Setup!CmdLine to get this

I had to add an extra kernel hook on dolphin to wipe the jit cache on every process switch, because the two really aren't compatible... which tanks performance even more!

and yes, the default name/org before syssetup changes it is Bill Gates.

Rairii, to random
@Rairii@haqueers.com avatar

still not sure how stable iossdmc.sys is; but after some refactoring and bug fixing it's stable enough to get here:

Rairii, to random
@Rairii@haqueers.com avatar

win32k lives!

Rairii, to random
@Rairii@haqueers.com avatar

turns out that MmInit* was failing hard because I had a bug in the ARC firmware when setting up the memory map lol

now it's getting as far as showing the version number before bugchecking

Rairii, to random
@Rairii@haqueers.com avatar

v5 = (void ******************)*v5;

no, hex-rays, this is a singly linked list

Rairii, to random
@Rairii@haqueers.com avatar

we all know NT really stands for NinTendo

Rairii, to random
@Rairii@haqueers.com avatar

usb mass storage support is working enough under emulation such that the passed-through USB flash storage can be at least accesed and sectors read(?)

unknown keyboard/mouse due to how I shoved the entire USB stack into one driver which was loaded as a mass storage driver

Rairii, to random
@Rairii@haqueers.com avatar

lol

so after @dangoodin mentioned a certain website that tried to block right click

I noticed it was done by a wordpress plugin

long story short I noticed another wordpress plugin by the same publisher

and basically rediscovered CVE-2023-51484 lol (the paid pro version is also vuln)

Rairii, to random
@Rairii@haqueers.com avatar

USETUP RUNS

I REPEAT: USETUP RUNS

this is STATUS_OBJECT_NAME_NOT_FOUND trying to open \Device\Video0

Rairii, to random
@Rairii@haqueers.com avatar

how long will it take for eurostar to go supernova

Rairii, to random
@Rairii@haqueers.com avatar

rebased kernel32, user32, ole32 to different hardcoded addresses (giving the first two 1MB of address space and the last one as much as it needs, it's over 1MB when mapped anyway)

and taskmgr comes up

winmsd still doesn't want to, though.

Rairii, to random
@Rairii@haqueers.com avatar

https://uefi.org/sites/default/files/resources/Evolving%20the%20Secure%20Boot%20Ecosystem_Flick%20and%20Sutherland.pdf

"some OEMs have lost their PK private keys"

"some OEMs shipped broken db-update implementations, that in some cases cause an outright brick"

why am I not surprised

Rairii, to random
@Rairii@haqueers.com avatar

big social media have algorithms focusing on engagement

but i don't see people getting rings when they go viral

rysiek, to random
@rysiek@mstdn.social avatar

existence of prime ministers implies the existence of composite ministers.

also note: prime ministers often divide.

Rairii,
@Rairii@haqueers.com avatar

@rysiek multiply prime ministers together and you get public servant cryptography

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • megavids
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • provamag3
  • tester
  • Leos
  • JUstTest
  • All magazines