@cryptax@mastodon.social avatar

cryptax

@cryptax@mastodon.social

Anti-Virus Researcher (Mobile, IoT) and Lead organizer of Ph0wn CTF.
This account does not represent my employer.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

nixCraft, to linux
@nixCraft@mastodon.social avatar

or desktop from the 90s. Awesome aesthetic 🔥

cryptax,
@cryptax@mastodon.social avatar

@nixCraft I still use FVWM daily by the way. The look and feel is a bit more modern, but configuration file hasn't changed much.

cryptax, to random
@cryptax@mastodon.social avatar

This handy radare2 extra plugin is great to rename "anything" in radare2 output.

I'm using it to rename Dart registers to PP (Pool Pointer) and THR (Thread Pointer) :)

afen PP r15

https://github.com/radareorg/radare2-extras/tree/master/afen

cc: @radareorg

jjLitke, to random
@jjLitke@wandering.shop avatar

FYI if you use Medium it requires a sign-in to read posts. So I won’t ever read your posts because I don’t want to hand over my info to them.

Also I’m not interested enough to go through a bunch of extra clicks

And if a lot of other people aren’t in the first camp, you can bet a ton of them are in the second

cryptax,
@cryptax@mastodon.social avatar

@jjLitke no, Medium does not require a sign-in to read posts. It depends on how the author configured their articles. Mine are viewable without sign-in :)

nixCraft, to random
@nixCraft@mastodon.social avatar

C is now illegal. Future Software Should Be Memory Safe lang like Rust and others https://www.whitehouse.gov/oncd/briefing-room/2024/02/26/press-release-technical-report/

cryptax,
@cryptax@mastodon.social avatar

@nixCraft well that's not what the report says, is it ? ;P

root42, to random
@root42@chaos.social avatar

Successfully repaired the charging dock for my mother's phone. The micro USB socket had broken off. All legs were cleanly snapped off. Replaced it with a new one.

Backside of the charging cradle, reading "USE SPECIFIED Panasonic AC ADAPTOR ONLY" and showing the USB port.
The old 5 pin USB socket, with the legs only visible as little stumps.

cryptax,
@cryptax@mastodon.social avatar

@root42 nice because those micro USB aren't the easiest thing to remove and re-solder...

cryptax, to android
@cryptax@mastodon.social avatar

Just analyzed a spyware sample that bypasses Android 13 Restricted Settings so as to drop another malware with full access to Accessibility API.

  • use of malformed ZIP to break apktool and other tools.

https://cryptax.medium.com/android-spynote-bypasses-restricted-settings-breaks-many-re-tools-8791b3e6bf38

cryptax, to random
@cryptax@mastodon.social avatar

I will be speaking on how to reverse Flutter applications at Nullcon, mid March.

https://nullcon.net/berlin-2024/conference-speakers

cryptax, to android
@cryptax@mastodon.social avatar

Interesting. This is how an Android/MoneyMonger detects if ADB is enabled or not: it looks for development settings. This is not a new technique, but I rarely see it in malware.

it4sec, to random
@it4sec@mastodon.social avatar

Do you trust your car?

cryptax,
@cryptax@mastodon.social avatar

@it4sec depends for what :) also probably depends if you are around my car or not ;)

cryptax,
@cryptax@mastodon.social avatar

@it4sec

  • going from Point A to Point B with maximum safety: if we only consider car mechanics and not how well or bad I or others drive, yes, I do trust it. Not entirely blindly, and that's what the brake pedal is for ;)

  • minimal environment impact: no not really, I don't believe my car was really built for that, although it will try to lower consumption for example.

  • disclosing details of my trip: I don't think my car will disclose my trip, so yes, I trust it for that.

cryptax, to android
@cryptax@mastodon.social avatar
cryptax, to android
@cryptax@mastodon.social avatar

I've just published a blog post on a new sample of Android/BianLian botnet which uses (1) an intentionally bad formed ZIP, and (2) uses a new packer.

https://cryptax.medium.com/bad-zip-and-new-packer-for-android-bianlian-5bdad4b90aeb

By the way, this will be covered in my @ringzer0 training.

#android #malware #zip #packer #kavanoz #medusa #JEB

cryptax, to android
@cryptax@mastodon.social avatar

I like to have lots of exercises on recent & real Android malware in my @ringzer0 training.

There will be exercises on GodFather, Chameleon, Kamran (Firebase), AhRat, SpyLoan (Flutter), Hook, Xenomorph and my favorite BianLian ;)

Am I missing something of 2023 you'd like to see?

Register here: https://ringzer0.training/trainings/reverse-engineering-android-malware.html

cryptax, to random
@cryptax@mastodon.social avatar

Connaissez-vous des gens intéressés par les CTFs chez ST Microelectronics, Thalès, Amadeus?

On n'a pas de bon point d'entrée dans ces entreprises, résultat on a généralement personne de chez eux à @ph0wn alors que ça pourrait normalement les intéresser...

[Ph0wn CTF - 25 novembre 2023 - Sophia Antipolis]

cryptax, to random
@cryptax@mastodon.social avatar

You haven't ever played a CTF, and wonder what it is, and if it's some interest to you?

I've written a blog post on that: https://cryptax.medium.com/whats-a-ctf-is-it-interesting-will-i-enjoy-it-do-i-have-the-skills-for-a-ctf-e11c680df5b7

And if I've convinced you, I hope to see you at Ph0wn on Nov 25, in Sophia Antipolis, France. It's a local CTF, so you need to be physically on site to play. See https://ph0wn.org

cc: @ph0wn

cryptax, to random
@cryptax@mastodon.social avatar

Bonjour ! Y a-t-il qqun parmi mes followers qui travaille à la gendarmerie sur les arnaques phishing/bancaires ?

J'ai la fille d'un collègue qui s'est fait avoir par un truc très très bien monté, où l'arnaqueuse l'a contactée pendant des semaines avant, s'est arrangé pour devenir amie etc et finir par l'arnaquer de 10000 euros qd meme...

Il a deposé une plainte, évidemment, mais j'aimerais bien lui donner un petit coup de pouce.

cryptax, to random
@cryptax@mastodon.social avatar

This article on disinformation in computer science is really excellent, with lots of guidelines as how to deal with them at the end.

https://medium.com/@maldr0id/dismantling-spyware-disinformation-campaigns-2f4418500ef7

cc: @maldr0id

cryptax,
@cryptax@mastodon.social avatar

@maldr0id "Block and mute the trolls, but not disinformation agents." --> this is strange to me, why not block the disinformation agent? and how can you block the trolls without blocking the agent... ?

cryptax,
@cryptax@mastodon.social avatar

@maldr0id I entirely agree, but in practice, I don't see how you can block the troll accounts only... apart if you do it manually.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

deleted_by_author

  • Loading...
  • cryptax,
    @cryptax@mastodon.social avatar

    @GossiTheDog ouch!!!

    cryptax,
    @cryptax@mastodon.social avatar

    @GossiTheDog @briankrebs yes, AI just make up stories. The problem is that it looks real for someone who doesn't know.
    I remember he attributed some non existent IoT research to @threatresearch with wrong affiliation, and me. Lol...

    cryptax, to random
    @cryptax@mastodon.social avatar

    My slides for the keynote of BruCON 2023 are available on GitHub: https://github.com/cryptax/talks/tree/master/BruCON-2023

    albinowax, to random

    "How do you choose what topic to research?" This was the number one question I was asked at Nullcon. As it happens I've already published a post exploring this!

    Check it out here:
    https://portswigger.net/research/how-i-choose-a-security-research-topic

    cryptax,
    @cryptax@mastodon.social avatar

    @albinowax funny, I got the question too, and same I don't find picking up a topic difficult but rather not having time for all of them :)

    cryptax, to random
    @cryptax@mastodon.social avatar

    I'm not sure people tell you often @radareorg but I often laugh at radare's welcome message. I like it (to be honest, I haven't tested all messages, but this one made me laugh).

    DrH, to ageofsigmar
    @DrH@warhammer.social avatar

    The hobbits on Weathertop.

    These tiny figures are barely an inch tall, on the bases.
    They're not called halflings for nothing.

    Painted them up as they were dressed for the Weathertop scene in the film.
    And gave them custom-made flagstone bases to match.

    cryptax,
    @cryptax@mastodon.social avatar

    @DrH well done! They're really cute like this, and lots of details.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ethstaker
  • rosin
  • mdbf
  • DreamBathrooms
  • khanakhh
  • magazineikmin
  • GTA5RPClips
  • InstantRegret
  • everett
  • Youngstown
  • modclub
  • slotface
  • kavyap
  • normalnudes
  • ngwrru68w68
  • thenastyranch
  • osvaldo12
  • tacticalgear
  • cubers
  • tester
  • anitta
  • Leos
  • Durango
  • cisconetworking
  • provamag3
  • megavids
  • lostlight
  • All magazines