148 karma · joined June 5, 2014
It also defines some buffer size names that are likely also declared in other libraries, like `BUF_SIZE`, and will need to be `#undef`ed.
http://beza1e1.tuxen.de/articles/accidentally_turing_complet...
$ cat foo.sh
#!/usr/bin/env zsh
echo $SHELL
Which most editors understand. $ file foo.sh
foo.sh: a /usr/bin/env zsh script text executable, ASCII text
$ vim --clean -c ':set filetype?' foo.sh
...
filetype=zsh
This ALSO ensures that the correct shell is invoked on your script, instead of your current or default shell. $ ./foo.sh
/usr/local/bin/zshThis pretty much sums it up — going into the office is great for collaboration and socializing but I’m always at a loss as to when anybody actually manages to get work done.
Working from home is amazing for getting things done because I can get deep into my work for a few days in a row with relatively few distractions or context switches.
Google uses Hangouts for video chat and it “just works” really well for one-on-one or even group video where all other participants are in one location.
I’ve also found that getting “face time” with other teams to be incredibly important for getting their buy-in for whatever I’m trying to convince them to do. Being a random guy on the other end of a chat or email isn’t as useful as verbal chat for just a few minutes — especially lacking the ability to just stop by someone’s desk for an impromptu chat.
syzkaller.appspot.com should give you an idea how many THOUSANDS of these types of bugs exist in the current ToT kernel
https://events.linuxfoundation.org/wp-content/uploads/2017/1...
Edit: I missed the “RCE” context. Most of these are just privescs or memory disclosures.
Some Ad Blockers are implemented as VPNs. This is unfortunate, and they should use the Safari Content Blockers interface instead. Content Blockers cannot intercept or sell your content, since the code is sandboxed and doesn't get network access. NeverAds seems to work well for me.
* The Chinese supply chain interdiction / implant installation is real
* Those companies ARE aware of such events
* Those companies DID report it to USGOV
* The investigation is classified and Bloomberg didn't know or doesn't care
* The government is doing its traditional "Deny, disavow, do not acknowledge" etc.
* The companies were probably threatened with legal action / gag order preventing them from acknowledging the event
When I started working for DOD, one of the things in training was that you were always to say "I can neither confirm nor deny X". Eventually they realized that this statement itself is revealing, and suggested you just STFU.
The whole thing sounds incredibly plausible, and nooooooooobody was supposed to know about it.
ptype already existed, but did not print out offsets. This is incredibly useful, and something Windbg does with dt. Pwndbg does this in GDB by adding new commands.
Given any routine which ends with the very common pattern:
return foo();
Which is assembled to the very common sequence: call foo
leave
ret
This project will instrument it to now look like: call foo
jmp $+2
.byte DE, AD
leave
ret
Whatever return address I hijack, I can now just point it at this valid return site, and begin my ROP stack as per normal.What's especially great is that the project guarantees this pattern for us. Now, every function has a path that looks like:
call __stack_chk_fail
jmp $+2
.byte DE, AD
< function frame cleanup >
ret
This is effectively a no-op for security.I cleaned up the author's code, added a sane makefile, and an example exploit here: https://github.com/zachriggle/return-to-abort
(Pull Request: https://github.com/cjdelisle/return-to-abort/pull/1)