krogoth

joined 2 years ago
MODERATOR OF
[–] [email protected] 5 points 2 weeks ago (1 children)

Yes. And you will have a good chance that the EDR wont flag the extractor since its not suspicious code per se.

[–] [email protected] 7 points 1 month ago (1 children)

«When they loaded this URL, the server responded with a Java heap dump, which is a roughly 150-MB file containing a snapshot of the server’s memory at the moment the URL was loaded.»

Comedy gold, the whole article…

[–] [email protected] 2 points 1 month ago

News or not. I like the fact that the pot is calling the kettle black…

[–] [email protected] 6 points 2 months ago* (last edited 2 months ago)

A tad late (the original story), but now there is an opinion piece on this topic now: https://www.theregister.com/2025/03/24/microsoft_opinion/

I like the part with "This a post-literate era, and we should expect the next demand for bughunters to express proof-of-concept as a TikTok dance short."

[–] [email protected] 2 points 5 months ago

OH: «by sending a malicious DNS packet to the target device», 👌🤭

[–] [email protected] 1 points 6 months ago

I lost count. How many vulns this year already?

[–] [email protected] 9 points 8 months ago (2 children)
[–] [email protected] 1 points 11 months ago

You mean like FIST but with a huge revolver? 😍

[–] [email protected] 1 points 11 months ago

Not sure if that is even the point. The article is all about memory unsafe programming!!1!. But there is no context at all.

Sure, there are vulnerabilities because of unsafe memory handling. But I looked for some statistic which would bring unsafe memory handling into context with say the high profile vulnerabilities from the last few weeks / months. I haven't spent too much time on research but looking at some lists containing vulns from the last few months it seems as if all those pre-auth, priv escalation, directory traversal and whatnot very based on much simpler failures like wrong error handling or logical errors or missing code than unsafe memory handling.

I might be wrong, then please show me the numbers, but shooting at C/C++ because unsafe!!1! sounds like a very biased story there.

And while we are at it. I'd also be interested in C vs. (somewhat modern) C++.

[–] [email protected] 0 points 1 year ago

Will have to look in the logs. Probably the pushing to Lemmy part.

 

cross-posted from: https://infosec.pub/post/4231412

Google Paid 6 Billion to Be Default Search Engine in 2021

view more: next ›