Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tiraniddo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
tiraniddo
4y ago
The article also felt like Rust does it this way because all these other projects which came before it did it this way. Someone originated the technique and no one questions its validity, without seeing if there was an alternative method to
2.
▲
by
tiraniddo
5y ago
That dialog is only on Google websites, I'm not sure how that is abusing its power as you can choose not to use Google products (hard but doable). Regardless Microsoft are already doing that to push Edge as well, try going to microsoft
3.
▲
by
tiraniddo
6y ago
If you enabled the posix subsystem NTFS became case sensitive as well, although most API passed a flag to disable that for Win32 file calls. It’s interesting that Microsoft effectively added the reverse feature to NTFS [1] to support per-di
4.
▲
by
tiraniddo
6y ago
It’s an proof of concept exploit for a vulnerability in the sandbox used by FF which is a security boundary to reduce the impact of RCE. The reason for the injection is I don’t just have a working RCE lying around (we get them fixed) and us
5.
▲
by
tiraniddo
6y ago
In Chromium we do have integration tests for the sandbox functionality as a whole and unit testing but it doesn't cover things like this as we're testing Chromium's ability to sandbox not whether the OS's primitives have
6.
▲
by
tiraniddo
6y ago
Basically my PoC works exactly the same from Chrome GPU as FF Content Level 5 [1] there was no additional hardening. It was also easier to test as FF doesn't enable the Microsoft DLL signing mitigation should I could just do a direct C
7.
▲
by
tiraniddo
6y ago
Ah I see what you mean :-) We'll yes I left out the RCE as I'm not an RCE person, I look for sandbox escapes and privilege escalation bugs. The injection of a DLL is to test rather than as an exploit. I was originally going to wri
8.
▲
by
tiraniddo
6y ago
You can bet I'm salty. I do Windows research and I am a owner of the Chromium Windows sandbox code so I have a vested interest in this. The problem with dealing with Windows and by extension Microsoft is there's no way of inspecti
9.
▲
by
tiraniddo
6y ago
I'm not sure which critical parts I've left out unless you mean a full working POC? The fun is reimplementing :-)
10.
▲
by
tiraniddo
7y ago
I'm not sure why I'm replying to the proverbial as you seem to have made up your mind, but being the original author of the blog post I thought I'd at least try and correct some seeming misconceptions. First off, the reason i
11.
▲
by
tiraniddo
7y ago
The private symbols have in the past ended up on the public symbol server (and quickly taken down), they have ending up "shipping" in public symbol packs. I can't point to specific incidents as the links to them no longer exi
12.
▲
by
tiraniddo
7y ago
Well that's categorically untrue. Sure they don't release private symbols intentionally but they have done in the past accidentally. At that point it becomes a bit of a grey area, undoubtedly leaked/stolen source code is a no
13.
▲
by
tiraniddo
8y ago
No, blame the movie studios, record labels etc. They're the one which require asinine DRM support for web browsers. Google/Microsoft/Apple/Adobe want to support media content, but to do so requires towing the line with t
14.
▲
by
tiraniddo
8y ago
Yes it’s just as vulnerable (example [1]), but I think .net serialization is exposed less often to untrusted inputs than Java with its myriad of enterprise software. [1] https://googleprojectzero.blogspot.co.uk/2017/04&
15.
▲
by
tiraniddo
9y ago
It's worth noting that ALT+X gives you the default OEM code page for compatibility with DOS sigh whereas ALT+0X gives you Unicode. So typing ALT+0163 will give you £.
16.
▲
A Powershell Script Demonstrating Why Windows UAC Had Zero Security from Day 1
(gist.github.com)
2 points
by
tiraniddo
9y ago
|
0 comments
17.
▲
by
tiraniddo
10y ago
I'd take a guess that the save tricks might be more anti piracy. After all the gba had flash carts, perhaps these carts contained sram and eeprom so checking for it was to block it. No idea about the pipeline stuff though, perhaps chec
18.
▲
by
tiraniddo
10y ago
Well at least with hard links that's not strictly true. Using official win32 apis you need write permission on the file you're linking to so you can't link to say a system file as a non admin. Try mklink with the /H swit
19.
▲
by
tiraniddo
10y ago
That's exactly it. The contact had flash source but they get the DRM code shipped as a binary library so never see the source of it. A lot of companies, MS, Google, Adobe compartmentalise their drm team, effectively at the behest of th
20.
▲
by
tiraniddo
10y ago
I think you're also missing the point that adding mitigations into a platform is about reducing the number of exploitable bugs and ideally making the ones which are still exploitable take more time, are less reliable and cost more. I t
21.
▲
by
tiraniddo
10y ago
Not sure you can do it easily with SMB/CIFS (maybe some NAT tricks) but depending on the level of FS support you want it's pretty easy to do it with WebDav. You can mount a webdav share pointing to localhost on an arbitrary port (