Sign in

pancake

@trufae.bsky.social
262 followers 134 following 116 posts

Author of @radareorg, mainly active in the fediverse @pancake@infosec.exchange

PostsRepliesMedia
pancake @trufae.bsky.social · 20/08/2026
Molts cops em desperten gossos a les 7 del mati pq els treuen a passejar i no tenen re millor a fotre que bordar als altres gossos. Els mataria a tots
100
pancake @trufae.bsky.social · 12/06/2026
New release of r2hermes! The plugin for reverse engineering React Native apps with #radare2 In short, i've added SBOM listings, improved decompiler output, better overlapped strings support as well as much better SLP objects integration with latest radare2 from git! github.com/radareorg/r2...
R2Hermes Logo
032
Reposted by pancake
MIURA Masahiro @dubhead.bsky.social · 01/06/2026
» The new optimizations should also benefit Hare users: I measured a 33% improvement on the Hare test suite against qbe-1.2 (1.7s vs 2.6s). QBE 1.3 - Release notes c9x.me/compile/rele...
c9x.me
QBE - Compiler Backend
011
pancake @trufae.bsky.social · 15/05/2026
Just released r2unity v1.0 to help you reverse engineer Unity apps from your favourite disassembler! (aka @radareorg.bsky.social ) github.com/radareorg/r2...
github.com
Release 1.0.0 · radareorg/r2unity
First release! Supports iOS, Android, Linux, macOS and Windows Custom elf/macho/pe parsers for faster scans Parse global metadata versions from v36 to v6000! Export CycloneDX SBOM in JSON forma...
022
Reposted by pancake
GrantMeStrength @grantmestrength.bsky.social · 20/04/2026
Update to the (free) Opcodes app has added details of everyone’s favourite support chips (SID, VIC) and contemporary memory chips. Hopefully a useful resource when you’re retro-hacking. apps.apple.com/us/app/opcod...
1145
Reposted by pancake
Abhi @qbtau.in · 13/04/2026
It’s finally here: radare2 + Warp (warrp) ⚡️ This makes r2 the first tool outside of the @binary.ninja ecosystem to adopt the format. Huge thanks to Mason (from @binary.ninja) and @trufae.bsky.social for their invaluable feedback's during development. github.com/radareorg/warrp
github.com
GitHub - radareorg/warrp: A native radare2 plugin for the WARP signature format
A native radare2 plugin for the WARP signature format - radareorg/warrp
042
pancake @trufae.bsky.social · 06/03/2026
Aquest enllaç no és un enllaç :3
110
Reposted by pancake
Abhi @qbtau.in · 14/02/2026
Android 17 beta 1 is here (android-developers.g...) Static final fields now truly final An attempt to do so via reflection (and deep reflection) will always lead to IllegalAccessException, modifying them via JNI’s SetStatic<Type>Field methods family will lead to crash. 1/3
android-developers.googleblog.com
The First Beta of Android 17
News and insights on the Android platform, developer tools, and events.
151
pancake @trufae.bsky.social · 07/02/2026
Vibecool!
010
pancake @trufae.bsky.social · 19/12/2025
@alkalinesec.bsky.social still around?
000
pancake @trufae.bsky.social · 08/12/2025
Sorry i had to do it
020
Reposted by pancake
Golang Articles, News, Packages @golangch.bsky.social · 05/12/2025
Essential Go patterns, standard library reference & interactive examples #golang app.gointerview.dev/cheatsheet
0105
pancake @trufae.bsky.social · 01/12/2025
Jo només veig plàstic
110
pancake @trufae.bsky.social · 22/11/2025
Thats not mastodon
000
pancake @trufae.bsky.social · 22/11/2025
Dunno whats that but i won’t say what it means in spanish
000
Reposted by pancake
Adrian Sanabria @sawaba.bsky.social · 01/11/2025
Never again will an Apple Watch tell me to stand up when I’m already standing up. New Pebble and old Pebbles: back in business! thanks @ericmigi.com
1392
Reposted by pancake
Sebastià López @darumastudio.bsky.social · 06/10/2025
Sonic, la mascota més genial
El Sonic de Mariscal
3275
Reposted by pancake
radareorg @radareorg.bsky.social · 28/09/2025
Happy radare2 6.0.4 release day infosec.exchange/@radareorg/1...
033
pancake @trufae.bsky.social · 11/09/2025
Ves al fedi, alla tens enquestes i la gent reacciona
110
Reposted by pancake
radareorg @radareorg.bsky.social · 08/09/2025
📣The list confirmed talks for #r2con2025 are now public! How does it look? 🧸Bear in 🧠 mind that the list is incomplete because the CFP is still open and there are some unconfirmed talks still to be published! ⚓️ radare.org/con/2025
radare.org
022
pancake @trufae.bsky.social · 08/09/2025
Just posted about tricks to structure prompts in oneliners, understanding the different uses of newlines and finding the right alternative puctuations. #llm #ai trufae.github.io/aiblog/oneli...
trufae.github.io
Posts Madeup by AI
000
pancake @trufae.bsky.social · 03/09/2025
Ho he redactat millor aqui 👉 trufae.github.io/aiblog/aimet...
trufae.github.io
Posts Madeup by AI
111
Reposted by pancake
vullunfestuc @vullunfestuc.bsky.social · 27/08/2025
A Mastodont ens han ensenyat a hackejar el MetaAI per què parli en català.
062
pancake @trufae.bsky.social · 01/08/2025
I had this fight a while ago. I added another restriction to the decision: the language should not use setjmp and cant segfault with random code (always capture errors earlier). The only answer is quickjs. (I’m using quickjs-ng now)
000
pancake @trufae.bsky.social · 01/08/2025
Sempre han tingut totes aquestes restriccions, la gent té vides avorrides o menteix. Assumeixo que fan cultius i verifiquen totes les mostres abans de guardarles
110
pancake @trufae.bsky.social · 30/07/2025
Tampoc si has viatjat a altres continents o has passat pel quiròfan o prens drogues en els ultims messos. Vaig intentar donar sang 3 cops, em vaig fartar de condicions que no podia complir i ni ho he tornat a intentar.
110
pancake @trufae.bsky.social · 29/07/2025
No deixen no.
110
pancake @trufae.bsky.social · 02/07/2025
Lol
010
Reposted by pancake
alkali @alkalinesec.bsky.social · 02/07/2025
longjmp implies the existence of floatjmp and doublejmp
55211
pancake @trufae.bsky.social · 02/07/2025
I was randomly searching for assembly books on Amazon US and ended up finding this one, so I ordered it :D I didn’t know this was a thing, and I’m happy to read it and see how other people use and enjoy r2 ^^
000
pancake @trufae.bsky.social · 02/07/2025
Just arrived the #radare2 book! I will finally had a chance to learn it! #reverseengineering #books
1102
pancake @trufae.bsky.social · 28/06/2025
In my journey thru all the social networks I use to forget bsky is a thing, sorry if I don’t post much here, i’m mainly in the fediverse
030
pancake @trufae.bsky.social · 28/06/2025
📦 In my last video for r2tv I introduce r2pm, the package manager. Learn about how to create, search and install plugins and tools for radare2! ▶️ 10 min - www.youtube.com/watch?v=N31b... ▶️ 20 min - youtu.be/DbVBbxOL7KY
012
pancake @trufae.bsky.social · 22/06/2025
No more green. Probably the worst icon with the worst evolution in Apple’s history
000
Reposted by pancake
Barcelona Animal Save @barcelonaanimal.bsky.social · 19/03/2025
¡Atención activistas! La Marcha por los Animales de Barcelona ya tiene fecha: 📅 21 de junio de 2025 ⏰ 17:00 - 19:00 h 📍 Empieza en: Plaza Catalunya 🎯 Termina en: Arco de Triunfo 🔸 Resérvate el día y mantente atenta, porque pronto compartiremos más detalles.
133
pancake @trufae.bsky.social · 15/06/2025
Creo que no es el primero que veo de ti :p
000
pancake @trufae.bsky.social · 15/06/2025
📺 In the second video for #r2tv I explain the caveats of injecting null bytes in the process environment with rarun2, inspect the stack with r2frida and bypass limitations encoding the payload with ragg2! www.youtube.com/watch?v=-CMH...
youtube.com
Exploiting the environment with null bytes with radare2
YouTube video by r2con
052
pancake @trufae.bsky.social · 14/06/2025
💥 I'm a youtuber now! 📺 Just recorded a short video solving a crash in the #r2dec decompiler to lower the barrier to help new contributors get handy with the radare2 codebase and common developer workflows. www.youtube.com/watch?v=Fr6c...
youtube.com
Fixing r2dec crash -- by pancake
YouTube video by r2con
061
Reposted by pancake
Geoffrey Huntley @ghuntley.com · 04/06/2025
📰 LLMs are mirrors of operator skill
ghuntley.com
LLMs are mirrors of operator skill
This is a follow-up from my previous blog post: deliberate, intentional play. I didn't want to get into the distinction between skilled and unskilled work because people take offence to it, but AI is a matter of skill. Someone can be highly experienced as a software engineer in 2024, but that does not mean they're skilled as a software engineer in 2025, now that AI is here. In my view, LLMs are essentially mirrors. They mirror the skill of the operator. how do identify skill One of the most
063
Reposted by pancake
David Buchanan @retr0.id · 05/06/2025
userland ROP on day 1 💪
1002037319
Reposted by pancake
radareorg @radareorg.bsky.social · 30/05/2025
We can finally spin donuts in iaito! 🍩 🍩 (i know, that's an ancient feature request that brings us closer to get 1:1 feature parity with #radare2 ) But it's better late than never! Enjoy 🎉 PD: You can spin as many donuts as you want!
001
pancake @trufae.bsky.social · 30/05/2025
In X right now if you don't pay, your posts won't be seen by anyone, no matter if you search for keywords, use hashtags or mention. I have to go right to the profile and scroll down to the posts of each user to see if anyone said anything. If I just didn't had enough reasons for not using it
020
pancake @trufae.bsky.social · 29/05/2025
👍
000
Reposted by pancake
AnimaNaturalis @animanaturalis.org · 29/05/2025
❗️ Hemos sido testigos del horror en el que sobreviven los cerdos antes de ser enviados al matadero. Las afecciones en el sistema respiratorio, el canibalismo, los prolapsos y las afecciones oculares son algunos de los problemas de salud más comunes. Visita y comparte Granjas.org ✍️
045
pancake @trufae.bsky.social · 21/05/2025
Teniendo en cuenta que ticketmaster ha sido denunciado tambien.. renfe aunque falle mucho no suele estafar tanto como TM
000
pancake @trufae.bsky.social · 21/05/2025
Siento informarte que ddg tambien tiene IA integrada
010
Reposted by pancake
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 16/05/2025
Detecting malicious Unicode in #curl daniel.haxx.se/blog/2025/05/16/dete…
daniel.haxx.se
Detecting malicious Unicode
In a recent educational trick, curl contributor James Fuller submitted a pull-request to the project in which he suggested a larger cleanup of a set of scripts. In a later presentation, he could show us how not a single human reviewer in the team nor any CI job had spotted or remarked on one of the changes he included: he replaced an ASCII letter with a Unicode alternative in a URL. This was an eye-opener to several of us and we decided we needed to up our game. We are the curl project. We can do better. ## GitHub The replacement symbol looked identical to the ASCII version so it was not possible to visually spot this, but the diff viewer knows there is a difference. In this GitHub website screenshot below I reproduced a similar case. The right-side version has the Latin letter ‘g’ replaced with the Armenian letter co. They appear to be the same. GitHub shows a diff. But what is actually the difference? The diff viewer says there is a difference but as a human it isn’t possible to detect what it is. Is it a flaw? Does it matter? If done “correctly”, it would be done together with a _real_ and expected fix. The impact of changing one or more letters in a URL can of course be devastating depending on conditions. When I flagged about this rather big omission to GitHub people, I got barely no responses at all and I get the feeling the impact of this flaw is not understood and acknowledged. Or perhaps they are all just too busy implementing the next AI feature we don’t want. ## Warnings When we discussed this problem on Mastodon earlier this week, Viktor Szakats provided me with an example screenshot of doing a similar stunt with Gitea which quite helpfully highlights that there is something special about the replacement: Gitea warns that the replacement is using “ambiguous Unicode characters” I have been told that some of the other source code hosting services also show similar warnings. As a user, I would actually like to know even more than this, but at least this warns about the proposed change clearly enough so that if this happens I would get the code manually and investigate before accepting such a change. ## Detect While we wait for GitHub to wake up and react (which I have no expectation will actually happen anytime soon), we have implemented checks to help us poor humans spot things like this. _To detect malicious Unicode._ We have added a CI job that scans all files and validates every UTF-8 sequence in the git repository. In the curl git repository most files and most content are plain old ASCII so we can “easily” whitelist a small set of UTF-8 sequences and some specific files, the rest of the files are simply not allowed to use UTF-8 at all as they will then fail the CI job and turn up red. In order to drive this change home, we went through all the test files in the curl repository and made sure that all the UTF-8 occurrences were instead replaced by other kind of escape sequences and similar. Some of them were also used more or less by mistake and could easily be replaced by their ASCII counterparts. The next time someone tries this stunt on us it could be someone with less good intentions, but now ideally our CI will tell us. ## Confusables There are plenty of tools to find similar-looking characters in different Unicode sets. One of them is provided by the Unicode consortium themselves: https://util.unicode.org/UnicodeJsps/confusables.jsp ## Reactive This was yet another security-related fix _reacting_ on a demonstrated problem. I am sure there are plenty more problems which we have not yet thought about nor been shown and therefore we do not have adequate means to detect and act on automatically. We want and strive to be proactive and tighten everything _before_ malicious people exploit some weakness somewhere but security remains this never-ending race where we can only do the best we can and while _the other side_ is working in silence and might at some future point attack us in new creative ways we had not anticipated. That future unknown attack is a tricky thing.
33554
pancake @trufae.bsky.social · 16/05/2025
Today I presented at #hackbcn some practical usecases integrating language models for reverse engineering purposes with #radare2 Check out my slides at radare.org/get/r2ai-hac...
0105
Reposted by pancake
Deno @deno.land · 13/05/2025
curious about what each engineer is working on? let's find out!
4332
pancake @trufae.bsky.social · 10/05/2025
Function names with spaces. Exactly what I needed.
000