Sign in

dhulliger

@ruheabteil.ch
34 followers 122 following 30 posts

dad, screaming at computers and climbing rocks

PostsRepliesMedia
Reposted by dhulliger
c t @whatulysses.bsky.social · 18/06/2026
can't argue with this.
screenshot from a pop-up window received after downloading Microsoft Office. It features a yellow triangle with an exclamation point and the text, "'Microsoft Teams' is damaged and can't be opened. You should move it to the Trash."
39116032406
dhulliger @ruheabteil.ch · 08/06/2026
Shoutout to Mole, our @binary.ninja plugin that made these findings possible. Mole finds interesting execution paths in binaries by performing backward slicing on variables in MLIL SSA form, enabling static taint analysis. Mole: github.com/cyber-defenc... Advisory: certvde.com/en/advisorie...
certvde.com
MBS: Several security vulnerabilities in the UGW web GUI
032
dhulliger @ruheabteil.ch · 05/06/2026
finally seen some real good use of ai www.youtube.com/watch?v=z3pV...
youtube.com
VibeOS - Fully Hallucinated Operating System
YouTube video by Zev.3R
010
Reposted by dhulliger
Del-Raiser Cenobite @shrecknet.com · 09/04/2026
53107682882
Reposted by dhulliger
AltYellostoneNatPar @altyellonatpark.org · 17/03/2026
Life is actually pretty simple
Meme says
I don't want a city on mars
I don't want AI in every app
I don't want date centers in space
I want clean water
I want affordable healthcare
And I want bees to survive 

It shows snoopy fishing and dreaming of the day ;-)
12881231
dhulliger @ruheabteil.ch · 02/03/2026
Sad truth youtu.be/T4Upf_B9RLQ?...
youtu.be
A Day in the Life of an Ensh*ttificator
YouTube video by Forbrukerrådet - Norwegian Consumer Council
000
dhulliger @ruheabteil.ch · 28/01/2026
Worth watching! youtu.be/3C1Gnxhfok0?...
youtu.be
39C3 - A post-American, enshittification-resistant internet
YouTube video by media.ccc.de
000
Reposted by dhulliger
Ukraine Advocate 🇺🇦 @eugenemcparland.eurosky.social · 24/01/2026
Are you concerned about your privacy and the power abuse by American tech companies? This website helps you switch to European and open-source alternatives. switch-to.eu/en/
switch-to.eu
Switch-to.eu - EU alternatives to global services
A guide to help you switch from non-EU to EU-based digital services and products.
38148
dhulliger @ruheabteil.ch · 25/01/2026
Nothing new, but the current political situation in the US just makes it way more of an issue!
001
Reposted by dhulliger
heiseonline @heise.de · 23/01/2026
In Minnesota wurden Aktivistinnen festgenommen, die Proteste gegen ICE organisiert haben sollen. Von einer hat das Weiße Haus ein Foto manipulieren lassen. #Bildbearbeitung
heise.de
Weißes Haus verbreitet KI-manipulierte Aufnahme von festgenommener Aktivistin
In Minnesota wurden Aktivistinnen festgenommen, die Proteste gegen ICE organisiert haben sollen. Von einer hat das Weiße Haus ein Foto manipulieren lassen.
713865
Reposted by dhulliger
Marco Arrigoni / Seichnungen @marcoarrigoni.bsky.social · 18/01/2026
Wie jedes Jahr: Hoffen auf Weltverbesserung am @worldeconomicforum.bsky.social
021
Reposted by dhulliger
Paige Bailey (webpaige.dev) @dynamicwebpaige.bsky.social · 12/01/2026
🧵 Thread on beautiful data centers: MareNostrum 4 (Barcelona SCC): Often called "the most beautiful data center in the world," this facility is housed inside the Torre Girona Chapel, a deconsecrated 19th-century church. When fully installed, it will have a peak performance of 13.9 Petaflops.
715048
Reposted by dhulliger
Ink Radio @inkradio.bsky.social · 26/12/2025
Usually I can’t wait for a sequel but…
10265061354
Reposted by dhulliger
Damian Pfammatter @damianpfammatter.bsky.social · 10/12/2025
First two unauthenticated RCE CVEs published - Discovered with the help of our #Binja plugin #Mole! 🔗 Advisory: certvde.com/en/advisorie... @ruheabteil.ch 🔗 Mole: github.com/cyber-defenc... More vulnerabilities have been reported - stay tuned for upcoming advisories.
certvde.com
WAGO: Vulnerabilities in WAGO Industrial-Managed Switches
022
Reposted by dhulliger
Socket @socket.dev · 31/10/2025
🧯The security community is pushing back against new claims that 80% of #ransomware attacks are AI-driven, a figure from a recent MIT-linked report now drawing widespread criticism. → socket.dev/blog/securit...
socket.dev
Security Community Slams MIT-linked Report Claiming AI Power...
Experts push back on new claims about AI-driven ransomware, warning that hype and sponsored research are distorting how the threat is understood.
0188
Reposted by dhulliger
Spelling Mistakes Cost Lives @darrencullen.bsky.social · 07/08/2025
Did a new one
Government style ad in watercolour. Image of a burglar stealing a painting from the wall of a home. Tagline: "It's not theft... if you say you're using it to train your AI algorithm". Body text: "Theft is now legal, so we can boost the economy by eliminating jobs. If that doesn't make any sense, ask a chatbot to explain it to you." HM government logo in the corner.
3777072730
dhulliger @ruheabteil.ch · 22/10/2025
Earlier that year @damianpfammatter.bsky.social and me had time to play with domotics equipment. Finally the patches and advisories were released: www.certvde.com/en/advisorie...
certvde.com
Sauter: Multiple vulnerabilities in SAUTER modulo 6
011
Reposted by dhulliger
Hacker Memes @i0null.infosec.exchange.ap.brid.gy · 25/09/2025
Grim Reaper (Oracle) Knocking Door Meme 

Doors: OpenSolaris, OpenOffice & TikTok
631103
Reposted by dhulliger
Phrack Zine @phrack.org · 12/09/2025
Thanks for the excellent writeup @intel471.bsky.social www.intel471.com/blog/the-phr...
intel471.com
The Phrack leak: Examining an APT’s workstation
In August 2025, two anonymous researchers released 9 GB of data from a workstation of a likely advanced persistent threat (APT) group. Here’s an analysis of the data by Intel 471’s Cyber Geopolitical ...
0195
Reposted by dhulliger
Micah Lee @micahflee.com · 19/08/2025
My DEFCON talk "We are currently clean on OPSEC" now has over 30k views on YouTube, so now more people watched my talk than attended DEFCON itself. If you haven't seen it, please do! The Trump admin's incompetence is mindbogglingly BONKERS www.youtube.com/watch?v=KFYy...
youtube.com
"We are currently clean on OPSEC": The Signalgate Saga (DEFCON 33)
YouTube video by Micah Lee
410535
Reposted by dhulliger
Binary Ninja @binary.ninja · 14/08/2025
Check out our latest blog post on modeling complex control flow with function-level basic block analysis in Binary Ninja 5.1. From DSPs to Brain***k, this update makes it easier to develop plugins for tricky architectures. binary.ninja/2025/08/12/f...
073
Reposted by dhulliger
Olaf Hartong @olafhartong.nl · 06/08/2025
During my #BHUSA talk I've released many ETW research tools, of which the most notable is BamboozlEDR. This tool allows you to inject events into ETW, allowing you to generate fake alerts and blind EDRs. github.com/olafhartong/... Slides available here: github.com/olafhartong/...
github.com
GitHub - olafhartong/BamboozlEDR: A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.
A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes. - olafhartong/BamboozlEDR
02515
Reposted by dhulliger
David Buchanan @retr0.id · 31/05/2025
cut my heap into pieces, this is my crash report: allocation, no alignment don't give a fuck if it faults on assignment this is fatal abort()
643975
Reposted by dhulliger
Just Jack @just-jack-1.bsky.social · 07/05/2025
Linda McMahon, Secretary of Education, sent Harvard a letter. They graded it. Bwahahaha.
21724494312894
Reposted by dhulliger
sixtyvividtails @sixtyvividtails.bsky.social · 06/05/2025
Heard of #ContextJail? It's a nasty new technique: puts target thread into ⓪ deadloop, for as long as you can afford. Requires THREAD_GET_CONTEXT right. The gist? Just spam NtGetContextThread(tgt).😸 Target will be jailed, running nt!PspGetSetContextSpecialApc 🔁. Src & binary in [ALT]. Usecases: ⤵️
Screenshot of contextjail.exe running with default arguments.


Highlighted:

* prisoner thread (latched to CPU1 with priority 15) couldn't run for the entire test duration (30 seconds).

* 99 jailer threads (latched to 6/8 processors, CPU2..CPU7) were using 20% of total CPU time.


Overlay: pseudo-ASSCII art with prisoner thread and 6 jailer threads (guards), spamming NtGetContextThread to block the prisoner.


Source and compiled binary:
https://pastebin.com/pBJcGp1y
176
dhulliger @ruheabteil.ch · 09/04/2025
Someone please show to the orange man.. xkcd.com/3073
xkcd.com
Tariffs
010
Reposted by dhulliger
Ange @angealbertini.bsky.social · 01/04/2025
The craziest file I made & visualized recently was combining the Doom PDF with a DOS & Windows (EXE & PE) polyglot. It runs Doom on OS from 1993 until today, and Chrome-based PDF viewers! You can make it an HTML/JS polyglot too to run on most browsers! (3/3)
The ultimate Doom polyglot, dissected: DOS executable, Windows Portable Executable, and PDF for Chrome via JavaScript! With offsets, explanations and snippets from the file.
0226
dhulliger @ruheabteil.ch · 30/03/2025
Frühling ☀️🎉
010
Reposted by dhulliger
Jared Rizzi @jaredrizzi.bsky.social · 26/03/2025
quick guide to Signal's disappearing messages settings
screenshot of Signal disappearing messages settings annotated with "lunch plans" for off/four weeks, "war plans" for 1 week/1 day, "nudes" for 1 hour/5 minutes, and "plans to lie about sending war plans" for 30 seconds
10587136
dhulliger @ruheabteil.ch · 25/03/2025
10 years ago🫣 Still one of my favorite places
010
Reposted by dhulliger
Wietze @wietzebeukema.nl · 24/03/2025
By making minor changes to command-line arguments, it is possible to bypass EDR/AV detections. My research, comprising ~70 Windows executables, found that all of them were vulnerable to this, to varying degrees. Here’s what I found and why it matters 👉 wietze.github.io/blog/bypassi...
13619
Reposted by dhulliger
David Buchanan @retr0.id · 19/03/2025
the most important aspect of kernel development is to make sure your driver freaks the fuck out whenever the system resumes from sleep
3396769
Reposted by dhulliger
RastaMouse @rastamouse.me · 05/03/2025
[BLOG] I had a series in mind like "Rubeus' Hidden Secrets" or something like that. Basically, highlighting features of the tool that seem less well known. I'm starting off with a basic one for getting crackable hashes from cached service tickets. rastamouse.me/kerberoastin...
rastamouse.me
Kerberoasting w/o the TGS-REQ
Kerberoasting is a technique that allows an attacker to extract the encrypted part of a TGS-REP and brute force it offline to recover the plaintext password of the associated service account. The most...
0186
Reposted by dhulliger
halvarflake.bsky.social @halvarflake.bsky.social · 22/02/2025
I gave a day 1 closing keynote at DistrictCon yesterday. Surprisingly, it was a security talk about memory safety. Slides are here: docs.google.com/presentation...
docs.google.com
Memory Safety
Is this memory safety here in the room with us? Halvar Flake / Thomas Dullien DistrictCon 0 2025
512029
dhulliger @ruheabteil.ch · 13/02/2025
Why making responsible disclosure as cumbersome as possible? Did I miss a hidden agenda to go back to full disclosure vulns in random mailing lists?
000
dhulliger @ruheabteil.ch · 10/02/2025
Literally todays struggle
000
dhulliger @ruheabteil.ch · 02/02/2025
youtu.be/6ad4MH7fMLs?...
youtu.be
Prophets of Rage - Unfuck The World (Music Video)
YouTube video by ProphetsOfRageVEVO
000
Reposted by dhulliger
mthcht @mthcht.bsky.social · 31/01/2025
Say goodnight to the bad GUIDs ! badguids.github.io
186
Reposted by dhulliger
James Forshaw @tiraniddo.dev · 30/01/2025
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...
googleprojectzero.blogspot.com
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
26541
Reposted by dhulliger
dmnk @dmnk.bsky.social · 28/01/2025
Paper is here: www.usenix.org/conference/u... Code at github.com/pr0me/SAFIRE...
usenix.org
Forming Faster Firmware Fuzzers | USENIXusenix_logo_notag_white
012
Reposted by dhulliger
hasherezade.bsky.social @hasherezade.bsky.social · 26/01/2025
In case if you wonder what broke #ProcessHollowing on Windows 11 24H2, I have something for you: hshrzd.wordpress.com/2025/01/27/p...
hshrzd.wordpress.com
Process Hollowing on Windows 11 24H2
Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is us…
05838
dhulliger @ruheabteil.ch · 27/01/2025
A vulnerability reported in September 2022 to Poly apparently got a CVE in 2024 (CVE-2024-27460). Never was informed. After reporting I did countless requests for updates and as the company being bought by HP i lost hope they would publish anything. support.hp.com/us-en/docume...
000
dhulliger @ruheabteil.ch · 22/01/2025
State of world politics in one picture 😂
000
dhulliger @ruheabteil.ch · 21/01/2025
000
dhulliger @ruheabteil.ch · 20/01/2025
Beautiful landscapes, terrible politics 🤮
000
dhulliger @ruheabteil.ch · 16/12/2024
Monday tunes youtu.be/vBrazzkIeLA?...
youtu.be
Whiskey and Gin
YouTube video by The Killigans - Topic
000
Reposted by dhulliger
beercow.bsky.social @beercow.bsky.social · 14/12/2024
Python tool that converts Microsoft Defender Antivirus Signatures (VDM) into YARA rules. github.com/t-tani/defender2yara
github.com
GitHub - t-tani/defender2yara: Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules
Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules - t-tani/defender2yara
096