Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gquere
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Getting into EMFI for 30€ thanks to globalization
(errno.fr)
3 points
by
gquere
2d ago
|
0 comments
2.
▲
by
gquere
7mo ago
RDP2 has been cracked by glitching. You first need to downgrade RDP2 to RDP1 then do the RDP1 bootloader glitch. It's not exactly easy but it's well documented and can be done given enough time. Though the STM32F4 targets do have
3.
▲
by
gquere
7mo ago
First I'd like to point out that "Decryptor" is an ill-chosen term: there's no encryption mechanism here, RDP is a software lock based on an internal flash state. This dongle is very likely to be this original attack ht
4.
▲
by
gquere
8mo ago
I've tried this locally on a known-vulnerable piece of software using the hugginface Q8 model + llama. It did find the vuln when given the entrypoint in the lib and user-controlled buffer. Otherwise it produced false positives.
5.
▲
VulnLLM-R: Specialized Reasoning LLM with Agent Scaffold for Vuln Detection
(arxiv.org)
1 points
by
gquere
8mo ago
|
1 comments
6.
▲
by
gquere
11mo ago
AFAIK you don't need a credit card linked to the account, you can get in-store credit from selling the guaranteed drop items from playing a few matches, this is enough to get you started trading.
7.
▲
by
gquere
11mo ago
Read up on the story, look at the influencers promoting it and the ecosystem that grew around it. Valve is willfully running a casino for underage and have bypassed local laws that protect against this using technicalities. It's fright
8.
▲
by
gquere
11mo ago
I didn't downvote you (my account is low reputation) but your argument is weak: that some skins go for absurd amount of money says nothing of the rest of the ecosystem. There can both be children and drug dealers (ab)using the same &
9.
▲
by
gquere
11mo ago
They're running an online casino directed at children and have made specific adaptations to bypass legal regulations in several countries.
10.
▲
by
gquere
11mo ago
They did this to take a bigger cut of the market because most trades happened off-platform. This new update ensures that they will sell more of their new items through their shop (contract cases) because it's going to be the only way t
11.
▲
by
gquere
11mo ago
Look at the "meta-"game mechanics: you play a few games, you get a guaranteed case drop. This circa $3 case could contain anything, a $0.2 skin or a rare $2500 knife. When you open it a casino-like wheel goes over all the items an
12.
▲
by
gquere
11mo ago
I doubt it's going to change anything, this manipulated market will adapt and continue to extract money from kids. The cynic in me could even say that this change was pushed by Valve to take a bigger cut of the skin market (most trades
13.
▲
by
gquere
11mo ago
It doesn't "feel" like gambling, it's straight 100% the exact same thing but it's designed in a way that bypasses the legal words.
14.
▲
by
gquere
2y ago
On company laptops this isn't always true, for instance here's the spec sheet of the ThinkPad T14 (this seems to be true for all ThinkPad models): https://www.lenovo.com/fr/fr/p/laptops/thinkpad
15.
▲
Breaking Down Multipart Parsers: File upload validation bypass
(blog.sicuranext.com)
1 points
by
gquere
2y ago
|
0 comments
16.
▲
by
gquere
2y ago
Technically bcrypt isn't a KDF.
17.
▲
by
gquere
2y ago
There are already a bunch of studies showing that the ozempic causes massive muscle loss and lessens bone density. And before anyone remarks "just do resistance training", I doubt the people that take the easy solution will do it
18.
▲
by
gquere
2y ago
On RHEL it's installed but it's not enabled by default.
19.
▲
by
gquere
2y ago
The article advocates for even more market fragmentation? Even though that isn't the issue at all?
20.
▲
by
gquere
2y ago
There's supposedly a fix being deployed ( https://x.com/George_Kurtz/status/1814235001745027317 ). Since it's a channel update I'm assuming that it would be downloaded automatically? Has anyone receiv
21.
▲
by
gquere
2y ago
Was there a way to not enable these channel updates? If so, would you still check all the mandatory security measures when being audited?
22.
▲
by
gquere
2y ago
There totally is authenticated RCE, for instance a PHP page that contains a RCE but needs a prior authentication to access the resource. All RCEs are classified in either unauthenticated or authenticated, the former being the worst (or best
23.
▲
by
gquere
2y ago
This will never be accepted by the community.
24.
▲
A case of missing bytes: bruteforcing your way through Jenkins' CVE-2024-23897
(errno.fr)
1 points
by
gquere
3y ago
|
0 comments
25.
▲
Dependency Confusions in Docker
(errno.fr)
1 points
by
gquere
3y ago
|
0 comments
26.
▲
by
gquere
3y ago
Semi off-topic, I've coded a ncurses-frontend to navigate and filter grep-like results which might be of interest to some of you: https://github.com/gquere/ngp2
27.
▲
by
gquere
3y ago
Only DMA comes to mind but it requires a non-hardened configuration which isn't that common on recent laptops + OS.
28.
▲
by
gquere
3y ago
Well that's what I described. The drive was encrypted but there was no PIN so I just snooped the key, decrypted the drive and mounted it on another machine where I replaced sethc with cmd.
29.
▲
by
gquere
3y ago
Can't do this attack if BitLocker is protected by PIN/passphrase, which is rarely the case.
30.
▲
by
gquere
3y ago
OTOH they can be patched and to exploit them locally you either need software code exec or do a physical side-channel attack which is miles beyond a simple bus snooping.
More ›