@Rairii@haqueers.com
@Rairii@haqueers.com avatar

Rairii

@Rairii@haqueers.com

Reversing (malware and otherwise); appsec and websec; embedded security; exploit dev; software preservationist; knows how not to use cryptography.

Currently finding bugs in Windows bootloaders.

You may also know me from capcom.sys.

#nobot

This profile is from a federated server and may be incomplete. Browse more on the original instance.

CobaltVelvet, to random

dude i havz like a hundred reports to process now . fuck u website boy close your god damn instance

Rairii,
@Rairii@haqueers.com avatar

@CobaltVelvet he said he's actually thinking about turning registration approval on

i replied to ask him to keep it on permanently

Rairii, to random
@Rairii@haqueers.com avatar

So that cryptocurrency DM spam is indeed a phish.

The "promotion code" "gives" you 5 figures in USD worth of bitcoin but to "enable withdrawals" you need to "deposit" 0.01 btc

In other words, literally an advance fee fraud scam

lol.

Gargron, to random
@Gargron@mastodon.social avatar

We're aware of the spam attack hitting mastodon.social right now and our full moderation and DevOps teams are on the case mitigating any way we can (incl. switching to approval-mode registrations)

Rairii,
@Rairii@haqueers.com avatar

@Gargron good. please consider switching to approval mode registrations permanently.

Rairii,
@Rairii@haqueers.com avatar

@fuomag9 how would it?

thegibson, to random

I love waking up to a report shitstorm in the morning.

Still Langoliers folks...be cautious.

Rairii,
@Rairii@haqueers.com avatar

@thegibson @dustin looks like a cryptocurrency related PHISH too

i'm not sure of the actual scam here, could be anything, but i checked the site to see what the next phase of the phish was and cloudflare had put a phish warning in front of it

I didn't even realise cloudflare did that!

Rairii,
@Rairii@haqueers.com avatar

@thegibson @dustin anyway, I figured out the phish

the "promotion code" "gives" you 5 figures in USD worth of bitcoin but to "enable withdrawals" you need to "deposit" 0.01 btc

so, a literal advance fee fraud scam

daeken, to random

I stg, mastodon.social is the most poorly-moderated cesspool. If this was just my own instance, I would defederate at this point.

Rairii,
@Rairii@haqueers.com avatar

@daeken exhibit number whatever why completely open registration is a bad idea

Rairii,
@Rairii@haqueers.com avatar

@daeken the message looks phishy to me too and the website did also get reported as phish enough that cloudflare put a warning in front of it.

given how shitty cloudflare is i'm amazed they even do that

Rairii, to infosec
@Rairii@haqueers.com avatar

thanks @winload_exe for mirroring a 2016 build of Windows (x86) with private symbols

it's not 100% private symbols (there's a few public symbols only in there afaik), but the majority of them have full type/locals/params info, most of which is still relevant today depending on what components you are looking at.

having private symbols definitely helped with my windows bootloader research, for example.

https://archive.org/details/10.0.14361.1000.rs1_release_prs.160603-2123_x86PlusPrivateSyms

#infosec #reversing #ReverseEngineering #windows

asie, to random

Discord's "Username#ABCD" concept was one of the ideas I liked about the platform, and I'm sad to see them walk it back.

In my opinion, it was a decent solution for the inevitable problem of "the amount of people with Internet accounts will only ever go up", while still giving a way for people to flaunt seniority - by paying for Nitro to have an account, that is. In a business sense, that feels like a win-win-win to me: users get to have the same username even if they weren't on the Internet in 2015, seniority wannabes get to flaunt their status, and Discord gets paid.

WIth the new system, I'm worried about them seeing the same type of problem I saw on Twitter: younger nicknames start geting obvious status indicators ("John Numbers"-style) and thus have a lesser social status from the get-go...

Rairii,
@Rairii@haqueers.com avatar

@asie the funniest thing is i set up a new xbox live account in about 2020 and ms had moved new gamertags to using "Username#ABCD" style tags, at least in the ui (internally as far as i could tell they just added the numbers to the end of the username)

so it was such a good idea that MS copied it!

ipg, to random
@ipg@wetdry.world avatar

Discord's username system is objectively the worst change they've made in years, they have good intentions but they should know that this kind of change will only cause more issues for their (already terrible) account hijacking problem

Rairii,
@Rairii@haqueers.com avatar

@ipg what exactly have they done lol

campuscodi, to random
@campuscodi@mastodon.social avatar

Russian technology experts are apparently working on new networking protocols to replace "the use of the American TCP/IP network protocol stack"

http://kremlin.ru/events/president/news/71015

Rairii,
@Rairii@haqueers.com avatar

@campuscodi lol. lmao.

Viss, to random
@Viss@mastodon.social avatar

huh. my notifications column on the web version of masto only lets me go back 44 minutes. thats not great. if i wait too long to reply to someone it makes it super hard to deal with. having "dms" in a separate column would be super helpful

Rairii,
@Rairii@haqueers.com avatar

@Viss there is, it's just under the menu (for advanced web interface)

Rairii, to random
@Rairii@haqueers.com avatar

time to bindiff CVE-2022-41099 i guess, I've been interested in this one for a while.

Rairii,
@Rairii@haqueers.com avatar

...oh lol is this as stupid as i think this is

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Fantastic reporting by @kimzetter here - a year long report into what went down with .

I'd like to highlight this bit. Zero trust, my arse. Lots of new details in this report. https://www.wired.com/story/the-untold-story-of-solarwinds-the-boldest-supply-chain-hack-ever/

Rairii,
@Rairii@haqueers.com avatar

@GossiTheDog I wonder why: because MS got hit too, or because it made US gov look bad? :)

ShinyQuagsire, to random
@ShinyQuagsire@mastodon.social avatar

the Wii U's clocks are so weird bc it's like, they'll have like 6 configurable PLLs for the IO, but then you get to the CPUs and all you get is a 2x syspll bit for ARM and a 3x/5x syspll bit for PPC. must be something weird with the memory bus I guess.

Rairii,
@Rairii@haqueers.com avatar

@ShinyQuagsire slightly offtopic but

i wonder what IOS for netcard would have been called, had it actually released

dubudavid, to random

I'm not commenting on whether it's right or wrong, but the new Zelda game leaking 11 days early is most DEFINITELY karma for Nintendo destroying the life of a man literally named Bowser after giving him a $10m debt after he had served jail time for selling hacked Switches

Rairii,
@Rairii@haqueers.com avatar

@dubudavid "L is real"

to be clear, i'm talking about tx here. fuck brickway.

Sterophonick, to random

the mf who leaked ToTK uploaded it to their community college email and we literally just have their email address in the download link i cannot even 😭

Rairii,
@Rairii@haqueers.com avatar

@Sterophonick that's really the original upload? i know people have mirrored "stuff" to such places before lol

cadey, to random
@cadey@pony.social avatar

I feel so bad for the yuzu and Ryujinx devs

Rairii,
@Rairii@haqueers.com avatar

@cadey ...wait, does the rtm of tears of the kingdom actually have denuvo anti-emulator or something stupid like that?

Rairii,
@Rairii@haqueers.com avatar

@cadey weren't the devs of one of those so optimistic about it hopefully working on release? haha

it's still an emulator inaccuracy, so I wonder if someone will find and submit certain "failing test cases" during the next 12 days

Rairii, to infosec
@Rairii@haqueers.com avatar

decided to put all public bitlocker attack research I know of (including mine and others) in one place https://github.com/Wack0/bitlocker-attacks

CobaltVelvet, to random

the opposite of dog is wog

Rairii,
@Rairii@haqueers.com avatar

@CobaltVelvet the opposite of dog is god

MrL314, to random
@MrL314@peoplemaking.games avatar

It’s pretty funny that full leaks of big Nintendo games always seem to happen exactly either 12 or 5 days before release.

Yes this is your notification that TOTK has been fully leaked now so if you don’t want spoilers you should start taking measures to avoid spoilers for the next 12 days :\

Rairii,
@Rairii@haqueers.com avatar

@MrL314 12 days? now you're making me remember when i had access to switch lotcheck and games 2-3 months in advance

rysiek, to random
@rysiek@mstdn.social avatar

I had a thought recently that is not yet entirely formed — but I'll put it out here anyway.

When the :birdsite: migration started in November, among many pieces written about it, I remember somebody (can't remember who!) making a point that the main product of a social network is moderation. And it made a lot of sense then and continues to do so in the context of fedi.

But looking at changes on :birdsite: and at BlueSky, it seems to me there is another possible product: reach.

Rairii,
@Rairii@haqueers.com avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines