Sign in

buherator

@buherator.bsky.social
538 followers 269 following 3.8K posts

"I'm interested in all kinds of astronomy." scrapco.de Mostly cross-posting from Fediverse: @buherator@infosec.place

PostsRepliesMedia
buherator @buherator.bsky.social · 15h
[RSS] How can undefined opcodes ud0 and ud1 have parameters? How undefined were they? devblogs.microsoft.com -> Original->
000
buherator @buherator.bsky.social · 15h
[RSS] X41 Audited vLLM x41-dsec.de -> Original->
000
buherator @buherator.bsky.social · 15h
[RSS] Lessons from using sanitizers as an oracle for LLM vulnerability triage joshua.hu -> Original->
000
buherator @buherator.bsky.social · 17h
Stock trading would be much easier if apps allowed you to scroll the graphs right. #UX Original->
010
buherator @buherator.bsky.social · 07/10/2026
This is also a meme about WinDbg scripting Original->
Alt text TBD, sorry!
000
buherator @buherator.bsky.social · 07/10/2026
I can't wrap my head around why people keep choosing #JavaScript as their embedded language. #Frida #WinDbg #ReverseEngineering Original->
Alt text TBD, sorry!
000
buherator @buherator.bsky.social · 07/10/2026
[RSS] Chromium: WebGPU Security Technical Report chromium.googlesource.com -> Original->
010
buherator @buherator.bsky.social · 07/10/2026
[RSS] Why does the compiler sometimes use ud2 and sometimes int 3 for code that shouldn't execute? devblogs.microsoft.com -> Original->
000
buherator @buherator.bsky.social · 07/10/2026
[RSS] Reversing Engineering a Captive Portal binary.ninja -> Original->
000
buherator @buherator.bsky.social · 06/10/2026
[RSS] Inside the Windows I/O Manager : Deep dive into how read I/O requests are initialized. winware31.blogspot.com -> Original->
000
buherator @buherator.bsky.social · 06/10/2026
Why nothing looks cool anymore? www.youtube.com -> I've been following this guy for a while now, but this turned out exceptionally good and important! I won't spoil the conclusion, you should watch it. (And the next one will be about Flock cameras!) Original->
000
buherator @buherator.bsky.social · 06/10/2026
Happy CSAM for those who celebrate! Original->
000
buherator @buherator.bsky.social · 06/10/2026
Humble suggestion: add WinDbg's scripting language to the EsoLang wiki Original->
000
buherator @buherator.bsky.social · 06/10/2026
click things to do stuff with them (and not their closest neighbor) was all the rage... 3/3 Original->
000
buherator @buherator.bsky.social · 06/10/2026
etc. underneath are still clearly visible. Guess what happens when you click on an icon visible on the desktop, not one of the little windows? That's right, the little window closest to the click gets the focus! I remember, when the intuitive #UI of Windows 3.1 where you could 2/3
100
buherator @buherator.bsky.social · 06/10/2026
#Windows 11 has this nifty "desktop" icon on the taskbar. It's impossible to figure out what the icon is for unless you click it but I digress. When you click the thing, the minified versions of the windows on the current desktop are arranged on top of the desktop, but the icons 1/3
100
buherator @buherator.bsky.social · 06/10/2026
[RSS] Technical Analysis of WhatsApp Zero-Click Exploit www.courtlistener.com -> From court documents Original->
000
buherator @buherator.bsky.social · 06/10/2026
from some even more obscure manga with unreasonably detailed fan wiki pages. 2/2 Original->
000
buherator @buherator.bsky.social · 06/10/2026
Back in the day when I found an string during #reverseengineering that looked like some trademark, I could use a search engine and find the statically linked library, some API docs, etc. Now I either get results from some obscure "AI" company SEO spamming or a random character 1/2
100
buherator @buherator.bsky.social · 05/10/2026
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5 ptswarm.com -> Original->
000
buherator @buherator.bsky.social · 05/10/2026
[RSS] A Mere Mortal's Introduction to JIT Vulnerabilities in JavaScript Engines trustfoundry.net -> Original->
000
buherator @buherator.bsky.social · 05/10/2026
[RSS] From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities sec-consult.com -> Original->
000
buherator @buherator.bsky.social · 05/10/2026
[RSS] Probabilistic analysis of MTE tagging schemes dustri.org -> Original->
000
buherator @buherator.bsky.social · 05/10/2026
[RSS] Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739) blog.quarkslab.com -> Original->
000
buherator @buherator.bsky.social · 04/10/2026
I recently learned to distinguish rabbits from hares (from a shitpost ofc) and now I feel slightly offended because my emoji keyboard shows a rabbit but it clearly renders as a hare in the app. 🐇 Original->
000
buherator @buherator.bsky.social · 04/10/2026
content from my friends, now in Budapest: macosvuln.training -> 2/2 Original->
000
buherator @buherator.bsky.social · 04/10/2026
"This 3-day training focuses on macOS Vulnerability Research (VR) for beginner to intermediate students. While intermediate topics will be discussed, the course focuses on bringing security researchers up to speed with macOS’s unique protections and vulnerabilities" Great 1/2
100
buherator @buherator.bsky.social · 30/09/2026
FlyDubai crew is pretty badass! Original->
000
buherator @buherator.bsky.social · 30/09/2026
[RSS] As a general rule, calling product support while drunk is not recommended devblogs.microsoft.com -> I don't endorse this message: most support calls require at lest a shot and a few cigarettes to maintain sanity. Original->
000
buherator @buherator.bsky.social · 30/09/2026
Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries www.vusec.net -> Original->
010
buherator @buherator.bsky.social · 29/09/2026
[RSS] Paint It Blue: Reversing Win32k's Callbacks idov31.github.io -> Original->
000
buherator @buherator.bsky.social · 29/09/2026
I read an article about sleep schedules and thought it would be good idea to put on some of those very neutral YT background music channels. Then I got recommended hate5six on the sidebar so Escuela Grind it is: www.youtube.com -> Original->
010
buherator @buherator.bsky.social · 29/09/2026
[RSS] Sender spoofing in Proton Mail via display-name homograph alonsovidales.github.io -> Original->
000
buherator @buherator.bsky.social · 29/09/2026
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5 ptswarm.com -> Original->
000
buherator @buherator.bsky.social · 29/09/2026
disarmament with my toy soldiers. 2/2 Original->
000
buherator @buherator.bsky.social · 29/09/2026
OpenAI delaying its model launch (and IPO) due to security concerns reminds me of 8yo me delaying the launch of my nerve gas rocket (made of paper and stuff I found in the kitchen, probably inspired by The Rock with Nicholas Cage) for similar reasons. Later we agreed in mutual 1/2
100
buherator @buherator.bsky.social · 28/09/2026
It's that time of the year again... Original->
Alt text TBD, sorry!
001
buherator @buherator.bsky.social · 28/09/2026
[RSS] RCE in OpenCode (GHSA-632h-h47v-g4x4) securitylabs.datadoghq.com -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] Cryptographic mass murder www.bfswa.blog -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] Aarch64 Rop Cheatsheet binaryru.in -> Original->
010
buherator @buherator.bsky.social · 28/09/2026
[RSS] Dirty Cert: Cisco Smart Software Manager's Silently Patched RCE starlabs.sg -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] Dell BOSS-N1 S-MCU Firmware Integrity and Cryptographic Verification Bypass github.com -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 www.safateam.com -> Original->
000
buherator @buherator.bsky.social · 28/09/2026
[RSS] CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018 daubois.dev -> Original->
000
buherator @buherator.bsky.social · 27/09/2026
RIP Sexecutioner :,( www.rollingstone.com -> Original->
000
buherator @buherator.bsky.social · 27/09/2026
Original->
Alt text TBD, sorry!
000
buherator @buherator.bsky.social · 26/09/2026
DNS errors again. systemd-resolved once again reports 0 errors (in fact, 0 log messages). Now I know this means the network is probably fucked. It was. But why is it so hard to put `error("network if fucket");` in #systemd? Original->
020
buherator @buherator.bsky.social · 26/09/2026
An old friend is ashamed of speaking English with people but want to practice. Any pro/cons of using an educational chatbot for this? At first I find this a pretty good use case for language models. Original->
000
buherator @buherator.bsky.social · 26/09/2026
just click the address bar, but start to type in it, there is no selection to remove. infosec.place -> 2/2 Original->
000
buherator @buherator.bsky.social · 26/09/2026
That's right, the right answer for this questions is: 3! By first pressing the down arrow you remove the selection (which you didn't put there) from the address bar text. The two downs are needed to reach C:\Users\Public. "2 or 3" would be also acceptable, because if you don't 1/2
Alt text TBD, sorry!
100