- The Grugq's Newsletter
- Posts
- Jan 24, 2023
Jan 24, 2023
Always a good time to rewatch Mickens
-
Fascinating story from @MarshallProj about how some prisoners in the U.S. use contraband cell phones to better their lives.
— Runa Sandvik (@runasand)
3:12 PM • Jan 23, 2023
-
-
-
Report from Ukraine on how the Russian cyber offensive is integrated into the “special military operation.”
And an article on the report:
-
WiFi Routers Used to Produce 3D Images of Humans
-
Heyyy... wasn't there something about the NY FBI office personnel being engaged in some weird stuff during the 2016 election? I vaguely remember something about that. twitter.com/lachlan/status…
— Michael von Herff (@vonHerff)
4:04 PM • Jan 23, 2023
-
People have been asking me about Bitwarden ever since LastPass has been breached. While I never took an in-depth look, I now at least evaluated the claims regarding their encryption:
https://palant.info/2023/01/23/bitwarden-design-flaw-server-side-iterations/
While the password manager being completely open-source with the option to self-host is great, otherwise I’m not too impressed.
-
Pwning Google phone using a bug in Mali
-
Activation Context Cache Poisoning: ZDI Sr Vuln Research Simon Zuckerbraun details this new class of privilege escalation vulnerabilities that has already been used in the wild. He also looks at the code changes #Microsoft has introduced in response. https://www.zerodayinitiative.com/blog/2023/1/23/activation-context-cache-poisoning-exploiting-csrss-for-privilege-escalation
…
@[email protected] @[email protected] though I'd argue it wasn't entirely new in 2022 ;-)
https://bugs.chromium.org/p/project-zero/issues/detail?id=1749
-
Folks, it's time once again to spin the Wheel of News:
🎰 Miami man
🎰 injured
🎰 by falling iguana
🎰 during outdoor yoga class— pourmecoffee (@pourmecoffee)
12:36 AM • Jan 24, 2023
-
Announcing Perplexity Ask, a new search interface that uses OpenAI GPT 3.5 and Microsoft Bing to directly answer any question you ask.
perplexity.ai
discord.com/invite/kWJZsxP…— Perplexity AI (@perplexity_ai)
6:04 PM • Dec 7, 2022
-
A thought provoking thread.
Some security thoughts on a super strange topic: how rationalists and nihilists have it wrong, and why the infosec community is ahead of the curve.
This is going to be a weird thread tying together an epic James Mickens USENIX Security keynote, Ken Thompson's classic Turing Award speech, Chapman's insights on the failure of modernity and rationalism and postmodernity, and more. So, let's begin.
-
Paper on undefined behavior in C.
-
did you know you can infer what version of Windows an executable was built on (or at least what version of the Windows SDK was targeted) by how many fields its load configuration directory has?
the structure remained unchanged from WinXP, until Win8.1 Update 3 when they added new fields for Control Flow Guard support. the same fields were used in the initial Win10 release (version 1507)
the structure was iteratively expanded in versions 1511, 1607, 1703, 1709, 1803, 1809, 21H1, 21H2, and 22H2.
-
China is inviting experts to come to China and provide consultations to the gov. Apparently it was consultations with foreigners that led to the removal of all Covid restrictions in December.
If you want a full or part time contract with China they prefer STEM academics in Health, International Relations, and Security. Meetings take place face to face in China. Oh, and no US persons.
Xi invites foreign experts into closed-door meetings on China's challenges ($, Jan 24)
^^ CCP uses LinkedIn to build network of foreign experts; prefers Europeans & 'no US experts should be involved'; STEM bckgrnd; re: health, int'l relations & security.
— Matthijs R. Koot (@mrkoot)
7:37 AM • Jan 24, 2023
-
Correction: my tweet about NSA's IPv6 guidance incorrectly stated "no NAT64, 464XLAT".
NSA's recommendation is to not use NAT *except* NAT64/DNS64 or 464XLAT for IPv6-only networks.
Ty for correcting me, @noIPv6 🙏.
/c @thegrugq
— Matthijs R. Koot (@mrkoot)
5:19 PM • Jan 23, 2023
-
The post looks into the stuff you could “theoretically” do with expired domains and the likes. thecontractor.io/blog/malinheri…
— Daniel Cuthbert (@dcuthbert)
9:35 AM • Jan 24, 2023
Reply