es
Feedback
Pseudorandom Thoughts

Pseudorandom Thoughts

Ir al canal en Telegram

我将开口,同时爽到爆。

Mostrar más
713
Suscriptores
+224 horas
+127 días
+16230 días
Archivo de publicaciones
最新指示:安全公司一定要搞好安全

最近配环境想找Fernflower的替代品,才发现Fernflower的作者 Stiver 已经于2024年10月去世了 https://blog.jetbrains.com/idea/2024/11/in-memory-of-stiver/

《「中文字体解秘组计划」第一阶段成果》 https://www.thetype.com/2025/04/27426/

美政钉说是

Repost from vx-underground
Drama++ The United States government is using a fork of Signal called "TM SGNL". TM SGNL is (likely) produced by an Israeli firm (Smarsh) which is (or related to in some capacity) the Israel Defense Forces' Intelligence unit. Although these claims are based on self-described biographies of the creators of TM SGNL and publicly available information. Various journalists and media outlets have reported differently. TM SGNL is a part of the Smarsh communication suite called TeleMessage hence TeleMessage Signal. TM SGNL is not publicly available for download. TM SGNL source code was leaked online May 3rd when an anonymous source tipped journalist Micah Flee about TM SGNL being available for download ... by accident. Smarsh left the source code to their application exposed because they used WordPress and misconfigured directory permissions which looked like so: /wp-content/uploads/2024/12/Signal-iOS-main.zip /wp-content/uploads/2024/12/Signal.zip Journalist Micah Flee has made the source code available on GitHub. The source code also includes hardcoded credentials (and got knows what else) You can read more about the leak, the contents of the leak, and you can find the link to the source code in the attached article below.

卷筒粉是不是也可以算一种玉米班戟/豆角班戟

https://www.kandji.io/blog/pasivrobber TLDR:恁美国OSINT又对着China哈气了,路边拾了个美亚的取证工具一通分析然后怪他主机信息收集太多 Meiya:什么叫我竟然收集信息了,我不收集信息我干嘛
:你们美国OSINT就不能至少要求一下,做中国威胁情报一定要懂汉语 :错了 做中国情报一定要不懂汉语( 不然就不好意思喊了

Repost from vx-underground
Hi, We've archived the MITRE CVE database. The CVE DB is free and open source on GitHub. However, we're providing a backup location for the data. We doubt it'll magically disintegrate in ash, but if it does we have a copy. https://vx-underground.org/Archive/CVE

看到有人管pointer叫“取件码”,我突然意识到自己已经老去,和新一代人有了代沟

哪个字体里的 I 最适合做工字钢? tl;dr: Courier New https://www.youtube.com/watch?v=azDaPm13CT8 论文: http://dx.doi.org/10.13140/RG.2.2.35453.88802

不知道是不是错觉,主观感受上,明明电子数据取证和(toC/toB的)数据恢复是同一类技术,但居然是完全两个赛道两拨儿不同的人在干活,后者难度高反而更牛马。或者说,DF的程序正义和证据识别的部分,学习成本其实远比拆盘、扫扇区、重建、仿真乃至在生dump里捡文件系统/文件尸块拼起来要低得多;但是前者toG领域的商业价值远比后者在C/B收的费用要贵,竞赛氛围也更浓厚——然而当代很多取证比赛甚至连“手动利用Android Nday/错误配置越权读/data”之类的都不敢考,还是停留在E01怼到一键仿真,或是Volatility嗯扫内存dump上。

为全面落实疫情防控工作,进一步阻断新冠肺炎病毒传播风险,今天电报街道疫情防控指挥部启动全员核酸检测,请广大居民做好个人防护,就近进行核酸检测,采样时间隔1米有序排队、遵守公共秩序,采样后迅速离开。检测时间为今天下午14时至16时30分,晚上18时30分至21时。

蓝队的一万道纵深防御都比不上开发的一次真情流露,我觉得安全开发在防护设备走得太远,却连开发跟你说“前端没有调这个接口,没有安全问题”的情况都解决不了。虽然业务逻辑漏洞是不可计算问题,但你们J2EE领域就不能出一点secure by default的框架和方案吗 悲报:这两年经济不好,业务缩水挤走了很多弱智开发,新上的应用少了,洞也就跟着少了 喜报:vibe coding这块给大伙送来了vibe exploiting