RAPLPOSOW's profile picture. Running Around Parking Lot Pants Off Shooting Out Windows

Ian Spiro

@RAPLPOSOW

Running Around Parking Lot Pants Off Shooting Out Windows

Woodcoin IS!!! @realWoodcoin @WoodCoinWorld Rt if u know wtf Swan is talking about @Hermesus_us @funkenmeisterthedwarf @LukasSaul2 @jimmysong


0x04fc16FB5362DFCA661222AEE0140D3b822b987F


Ian Spiro reposted

One week after launch and we've clocked 1,681 clones/downloads from the #golang community. Busy on enhancements, thanks for all the feedback, support, and getting the word out! #praetorianlabs github.com/praetorian-inc…


Logic to swap BTC addresses is "Spray & Pray" at best. #InsecureByDesign crew recommends reading @nedos of @walletfail for increased attacker joy Or @BTCchellingPt finds #malextensions using the @Ledgernanos2 Javascript rewriting technique Cc:@hon1nbo @CryptoGangsta @tbiehn

Over 700 Ruby Gems contain BTC stealing malware! Discovery & analysis by @ap0x of @ReversingLabs bit.ly/34F2yui +1 Self-extracting executables crafted w/ github.com/larsch/ocra are disguised as aaa.png extension file and triggered by use extconfig.rb -1 target logic

RAPLPOSOW's tweet image. Over 700 Ruby Gems contain BTC stealing malware!  Discovery & analysis by @ap0x of @ReversingLabs bit.ly/34F2yui

+1 Self-extracting executables crafted w/ github.com/larsch/ocra are disguised as aaa.png extension file and triggered by use extconfig.rb

-1 target logic


Over 700 Ruby Gems contain BTC stealing malware! Discovery & analysis by @ap0x of @ReversingLabs bit.ly/34F2yui +1 Self-extracting executables crafted w/ github.com/larsch/ocra are disguised as aaa.png extension file and triggered by use extconfig.rb -1 target logic

RAPLPOSOW's tweet image. Over 700 Ruby Gems contain BTC stealing malware!  Discovery & analysis by @ap0x of @ReversingLabs bit.ly/34F2yui

+1 Self-extracting executables crafted w/ github.com/larsch/ocra are disguised as aaa.png extension file and triggered by use extconfig.rb

-1 target logic

Ian Spiro reposted

False. Real security comes from giving me a board position #truefact


Outstanding research & excellent writeup (explanation, technical details, POCs)! Last mitigation strategy's Irony is strong as post is about abuse of HP Support Assistant to exploit Windows. "Another method of updating is to install the latest Assistant from HP’s website" LOL

Several Critical Vulnerabilities on most HP machines running Windows, d4stiny.github.io/Several-Critic…



Ian Spiro reposted

My report for the bug is now public: bugs.chromium.org/p/project-zero…. This PoC directly turns the bug into type confusions, the exploit technique is then basically phrack.org/papers/jit_exp…


#NSO #pegasus #mobiletracking #AllYourMetadata #TotalInformationAwareness Why wait for US citizens to Opt-In to Google / Apple contact tracing to destroy privacy? @moxie @cigitalgem @Snowden bit.ly/3esxTVQ from @infosectutorial Defense Minister shows off NSO tool;

RAPLPOSOW's tweet image. #NSO #pegasus #mobiletracking #AllYourMetadata #TotalInformationAwareness 
Why wait for US citizens to Opt-In to Google / Apple contact tracing to destroy privacy? @moxie @cigitalgem @Snowden 

bit.ly/3esxTVQ from @infosectutorial 

Defense Minister shows off NSO tool;

Ian Spiro reposted

Here is Bart Preneel himself on Silver Bullet apothecaryshed.files.wordpress.com/2018/10/silver…


Ian Spiro reposted

Spent 4 hours reverseengineering how an application encrypts its log files. Uses mt19937 with a specific seed and then uses the largest byte of the generated numbers as the key in a stream XOR cipher. Then I found out you can pass `debug` to the app to get plaintext log files.🤦🏾‍♂️


Yo #appsec dudes. Out of the shadows again, seems the streets are clear, want to share some artifacts dug out of #rabbitholes like Prof. Preneel interviews @SecAppDev @CosicBe bit.ly/34vFfTE Cc: @CryptoGangsta @hon1nbo @moxie @cryptosense @cryptopathe @cigitalgem


United States Trends

Loading...

Something went wrong.


Something went wrong.