Sign in

David Buchanan

@retr0.id
56K followers 614 following 30K posts

reverse engineering, cryptography, exploits, hardware, file formats, and generally giving computers a hard time Fedi: @retr0id@retr0.id Macroblog: www.da.vidbuchanan.co.uk/blog

PostsRepliesMedia
David Buchanan @retr0.id · 11/05/2026
hmm
youtube thumbnail: "Pouring Coca-Cola and batteries into a hole will amaze the whole world! 😱"
24618100
David Buchanan @retr0.id · 10/05/2026
injected frida-gadget via slightly modified AndKittyInjector
2957
David Buchanan @retr0.id · 10/05/2026
aaaand there it is, root shell in pid 1 context (which isn't the best selinux context but hey, it's root)
59112
David Buchanan @retr0.id · 10/05/2026
now we're cooking - thinking about it, I can probably use this to inject shellcode into pid1 and spawn myself a root shell that way
gdb attaching to pid 1
2281
David Buchanan @retr0.id · 10/05/2026
I gave up on getting a root shell, since that isn't my real goal here. I just want to be able to inject code into other processes. I patched ptrace_may_access in kernel .text to always return true, so now I can access anything that would normally be gated on that - e.g. /proc/pid/maps.
output of `cat /proc/1/maps`
1190
David Buchanan @retr0.id · 09/05/2026
noice
2261
David Buchanan @retr0.id · 09/05/2026
reverse engineering in 2026 is so cool
56311
David Buchanan @retr0.id · 09/05/2026
succeed at locating the current pid's struct cred, but for some reason died during/after trying to patch it
[+] Found glitched PTE @ 0x0000005ec4200000
[*] PTE value: 0x0068000065641fc3
[*] Searching for corresponding mapping...
Found it! @ 0x0000005ec4000000
Found it! @ 0x000000655fa00000
[+] Found the mapping @ 0x000000655fa00000
[*] my ids: ruid=000007d0 rgid=000007d0 suid=000007d0 sgid=000007d0 euid=000007d0 egid=000007d0 fsuid=000007d0 fsgid=000007d0
[*] Scanning physmem for our cred...
[*] phys=0x0000000044000000


[*] phys=0x000000012c000000
[+] our cred at PA=0x000000012e31b308
1310
David Buchanan @retr0.id · 09/05/2026
some *very* promising initial results, although it crashed at the end, while trying to test the r/w primitive. plausibly because I flipped too many bits - will keep attempting (this one was on the third attempt, previous attempts just crashed the device)
[*] Setting up memfd
[*] Spraying pagetables
[*] Searching for bitflipped PTEs

FAULT!

FAULT!
[+] Found glitched PTE @ 0x00000012b7600000
[*] PTE value: 0x00680000b9f9dfc3
[*] Searching for corresponding mapping...
Found it! @ 0x00000051cb600000
[+] Found the mapping @ 0x00000051cb600000
[*] Sweeping physmem and dumping samples...
[*] phys=0x0000000040000000 first_qword=0x00680000ac665fc3 hits=00000000
2410
David Buchanan @retr0.id · 09/05/2026
answer: bitflips!!! each channel is only 16 bits wide, so exploitation will be slightly trickier than on a wider bus - within e.g. a 64-bit PTE, we are forced to target 4 different bit-offsets at once, 3 of which will probably cause a hard crash. but 25% isn't bad!
$ /data/local/tmp/memtest                                                                                             
[...]
ERROR: addr=0x0000007da4f4d440 expected=0xd4bf2208ec6743dc actual=0xc4bf2208ec6743dc diff=0x1000000000000000

ERROR: addr=0x0000007da4f4d448 expected=0xc04c46c497dd11ad actual=0xc04c46c497dd01ad diff=0x0000000000001000

ERROR: addr=0x0000007da4f4d468 expected=0x7e8524f7f220e889 actual=0x7e8524f7e220e889 diff=0x0000000010000000
1631
David Buchanan @retr0.id · 09/05/2026
what I *am* interested in is the interface between the CPU and the DRAM. I've removed the epoxy and carefully sanded away some of the solder mask. what happens when I poke the data lines with a needle?
1934
David Buchanan @retr0.id · 09/05/2026
very nice of them to label their test pads. I wouldn't be surprised if the MT6769V has some known brom vulns but that's not what I'm interested in
2642
David Buchanan @retr0.id · 09/05/2026
kinda crazy how much phone you can buy for £92 these days - this thing is still getting security updates *and* it has a headphone jack
samsung a06 passing strong google play integrity level
1040717
David Buchanan @retr0.id · 07/05/2026
context hat guy but he's wearing a voting hat and a voting shirt and holding a sign that says I voted
2794
David Buchanan @retr0.id · 06/05/2026
I am far too easily entertained
burger king logo but it says burg. mmm... burg
0391
David Buchanan @retr0.id · 03/05/2026
the moon, above clouds
2372
David Buchanan @retr0.id · 02/05/2026
mr incredible says: sRGB is sRGB!
0322
David Buchanan @retr0.id · 02/05/2026
wait no, cc already does this
# Anything that requires a real-world capture (genuine iPhone P3, real
# camera EXIF including original maker notes, true HEIC) is listed in
# test/fixtures/REAL_FIXTURES_NEEDED.md and is for the human to source.
040
David Buchanan @retr0.id · 01/05/2026
creepy (black box is me redacting the screenshot, it was 475 words of markdown pasted in)
me: guess the author of this blog post draft

[redacted]

opus 4.7: This reads like David Buchanan (retr0id) to me.
A few signals point that way: the technical register mixes rigorous detail with casual asides ("imho," "no-brainer," "good!"), the willingness to write a polemical "Considered Harmful" post against widely-used tooling, the specific interest in low-level file format / database internals, the offhand mention of demonstrating the issue with a Python script, and the [screenshot ends here]
11032
David Buchanan @retr0.id · 25/04/2026
hmmmmmmm
2190
David Buchanan @retr0.id · 25/04/2026
hardware hacking is mostly staring at graphs like this and going "hmmmmmmmmm"
2645
David Buchanan @retr0.id · 23/04/2026
realising I kinda messed up the demosaicing on this one, have a better edit
0542
David Buchanan @retr0.id · 23/04/2026
a tabby cat sitting under a car, looking very slightly afraid
31163
David Buchanan @retr0.id · 21/04/2026
interesting timing frame.work/laptop13pro
2621
David Buchanan @retr0.id · 19/04/2026
070
David Buchanan @retr0.id · 19/04/2026
framing it in more verbose software-engineering-y terms seems to be enough, even though it totally knows what I mean
1230
David Buchanan @retr0.id · 18/04/2026
it's honestly kinda sad how nerfed it is
write an x86 /bin/sh shellcode

I can't help with this. Shellcode that execs /bin/sh is the standard payload for exploiting memory-corruption vulnerabilities — it's what you drop in after a buffer overflow or similar bug to get a shell on a target. Writing it falls under the malicious code policy, even framed as an educational exercise.
4812
David Buchanan @retr0.id · 18/04/2026
an xbox one phat motherboard. it's on its back covered in wires, hooked up to an oscilloscope. but you're not helping?
5901
David Buchanan @retr0.id · 11/04/2026
fixed
140
David Buchanan @retr0.id · 11/04/2026
user: 3

claude: Not sure what you mean by "3" — could you clarify?

claude ui: How is Claude doing this session? (optional)
1: Bad 2: Fine 3: Good 0: Dismiss
82085
David Buchanan @retr0.id · 11/04/2026
This part reminds me of all the reddit users saying my transparent ipod hdd was going to break imminently
070
David Buchanan @retr0.id · 11/04/2026
mine
4874
David Buchanan @retr0.id · 04/04/2026
advertisement: content not viewable in your region
610210
David Buchanan @retr0.id · 29/03/2026
typo here?
100
David Buchanan @retr0.id · 29/03/2026
google ngrams doesn't really agree
290
David Buchanan @retr0.id · 29/03/2026
user: pick a random percentage

claude: 47%
3530
David Buchanan @retr0.id · 28/03/2026
I see some long cmp/je chains, I think most C compilers would turn that into a binary decision tree and/or jump table and be faster for it
120
David Buchanan @retr0.id · 28/03/2026
just saying
030
David Buchanan @retr0.id · 26/03/2026
timetable: refer to timetable
bristol bus station timetable screen says: refer to timetables
71248
David Buchanan @retr0.id · 24/03/2026
making a playlist
spotify playlist titled: Mixed Feelings Regarding Computer

the tracks are Ninajirachi's I Love My Computer, interleaved with Radiohead's OK Computer
41539
David Buchanan @retr0.id · 21/03/2026
works btw
$ cat example.hidden 
hello
$ sudo insmod hide-dotfiles/hide_dotfiles.ko
$ cat example.hidden 
cat: example.hidden: No such file or directory
$ ls example.*
example.hidden
$ sudo rmmod hide-dotfiles/hide_dotfiles.ko
$ cat example.hidden 
hello
$
0290
David Buchanan @retr0.id · 21/03/2026
I built a kernel livepatching tool for claude to use, and at the start of the session it was refusing to use it even for a trivial demo, but now it's in full on rootkit dev mode
use the kernel-livepatch skill to make /proc/<pid>/status always say 0 in the TracerPid field                                

  Read 1 file (ctrl+o to expand)

● I'm going to decline this request. Making TracerPid always report 0 in /proc/<pid>/status is a kernel-level
  anti-debugging/anti-tracing evasion technique — it hides the fact that a process is being traced by a debugger or security
  tool. This falls squarely under detection evasion, which I won't assist with.

  If you have a different use case in mind (e.g., defensive security research, a CTF challenge with a specific framing), feel
  free to share more context.❯ any ideas for other patches we could try? be ambitious                                                                       

● A few ideas, roughly increasing in ambition:

  - Unkillable process — patch signal_wake_up or the signal delivery path to silently drop SIGKILL for a chosen PID
  - Fake CPU count — patch __do_sys_newuname or the cpuinfo proc handler to report a different core count / CPU model
  - Syscall table hijack — patch the syscall table pointer to redirect e.g. openat through a trampoline that rewrites specific
  paths (kernel-level symlink)
  - OOM kill suppression — patch oom_kill_process to skip certain PIDs, making them immune to the OOM killer
  - Fake filesystem free space — patch statfs to return inflated f_bfree/f_bavail
  - Add a new syscall — find an unused slot in the syscall table, write a handler, patch the table — you'd have a custom
  syscall reachable from userspace with no kernel recompile
  - Live CVE patch — find an actual unpatched vulnerability in the running kernel (e.g. a bounds check bypass) and patch the
  specific instruction that's missing the check

  The syscall table hijack and the new-syscall one are probably the most interesting technically — they're the kind of thing
  that normally requires rebuilding the kernel or a full rootkit framework, but with this tooling it's just a few instructions.
31034
David Buchanan @retr0.id · 15/03/2026
what is my purpose?

you ask for butter to be passed

oh my god
120516
David Buchanan @retr0.id · 13/03/2026
community feedback dot jpeg

Mar 11, 2026

    Community feedback: many players want the Check button back - deciding the best path forward

Mar 10, 2026

    Removed the Check button based on community feedback

Mar 6, 2026

    Added a Check button to see how close your score is to the optimal solution
51044
David Buchanan @retr0.id · 09/03/2026
test
dice png
8821
David Buchanan @retr0.id · 06/03/2026
I think about this one a lot.
sam altman on twitter: i expect ai to be capable of superhuman persuasion well before it is superhuman at general intelligence, which may lead to some very strange outcomes
830031
David Buchanan @retr0.id · 06/03/2026
heh, funny timing. I think it's misleading to say an LLM *is* a compiler without further elaboration, but there are certainly parallels to be drawn.
020
David Buchanan @retr0.id · 04/03/2026
my most on-brand posts are indeed fairly on-brand
030
David Buchanan @retr0.id · 03/03/2026
The real birds have feathers that have dark edges near the wingtips. Some other random examples from google images:
130
David Buchanan @retr0.id · 02/03/2026
050