HNHacker News
TopNewBestAskShowJobs

ebeip90

148 karma · joined June 5, 2014

submissionscomments
ebeip90··on Go's Tooling Is an Undervalued Technology
Setting breakpoints on CPython native code is a PITA and can’t be done (afaik) from PDB.
ebeip90··on Httpserver.h: Single header library for writing non-blocking HTTP servers in C
1100+ lines and barely a comment after the initial block.

It also defines some buffer size names that are likely also declared in other libraries, like `BUF_SIZE`, and will need to be `#undef`ed.

ebeip90··on Where do interrupts happen?
I’m not sure that this addresses your question directly, but the x86 MMU is turing complete.

http://beza1e1.tuxen.de/articles/accidentally_turing_complet...

ebeip90··on Hackers are stealing years of call records from hacked cell networks
There are likely more patients than doctors, so the inference is statistically correct.
ebeip90··on Vim/Neovim Arbitrary Code Execution via Modelines
Why not just set a shebang like

    $ cat foo.sh
    #!/usr/bin/env zsh
    echo $SHELL
Which most editors understand.

    $ file foo.sh
    foo.sh: a /usr/bin/env zsh script text executable, ASCII text
    $ vim --clean -c ':set filetype?' foo.sh
    ...
    filetype=zsh
This ALSO ensures that the correct shell is invoked on your script, instead of your current or default shell.

    $ ./foo.sh
    /usr/local/bin/zsh
ebeip90··on Google's remote work employee survey
Remote employee for 7 years, 4.5 at Google.

This pretty much sums it up — going into the office is great for collaboration and socializing but I’m always at a loss as to when anybody actually manages to get work done.

Working from home is amazing for getting things done because I can get deep into my work for a few days in a row with relatively few distractions or context switches.

Google uses Hangouts for video chat and it “just works” really well for one-on-one or even group video where all other participants are in one location.

I’ve also found that getting “face time” with other teams to be incredibly important for getting their buy-in for whatever I’m trying to convince them to do. Being a random guy on the other end of a chat or email isn’t as useful as verbal chat for just a few minutes — especially lacking the ability to just stop by someone’s desk for an impromptu chat.

ebeip90··on This is Your Brain on Exercise (2017)
The side closest to you should be higher. Microsoft’s ergonomic keyboards come with removable risers that achieve this.
ebeip90··on Google has added DuckDuckGo as a search engine option for Chrome users
Just put “!g” at the beginning of the query (or !s for startpage, which uses the Google search engine)
ebeip90··on Sidewalk Labs project means Toronto to have 'constitution-free zone,' CCLA warns
Sounds like the burbclaves in Snow Crash
ebeip90··on Linux Kernel Through 4.20.10 Found Vulnerable to Arbitrary Code Execution
More people are fuzzing the kernel publicly, and with better tools.

syzkaller.appspot.com should give you an idea how many THOUSANDS of these types of bugs exist in the current ToT kernel

ebeip90··on Problem solving with Unix commands
This will fail for any filenames that contain newlines
ebeip90··on CVE-2019-5736: runc container breakout
Probably only off by an order of magnitude. Check out Dmitry’s szykaller slides.

https://events.linuxfoundation.org/wp-content/uploads/2017/1...

Edit: I missed the “RCE” context. Most of these are just privescs or memory disclosures.

ebeip90··on The Case for Transmissible Alzheimer's Grows
Can confirm, am diabetic T1. Lancets don’t get changed much on my meter, but if anybody is curious I have a whole separate glucose meter/lancer device and brand new lancets to use.
ebeip90··on Musicmap: Genealogy and History of Popular Music Genres
Everybody talkin Riddim man but all it is Dubstep
ebeip90··on Security researcher cracks Google's Widevine DRM (L3 only)
(IIRC, unsubstantiated) Windows clients use Windows’ DRM implementation, not WideVine.
ebeip90··on Cloudflare 1.1.1.1 iOS app
It's implemented on iOS as a VPN, of which you can only have one active at a time.

Some Ad Blockers are implemented as VPNs. This is unfortunate, and they should use the Safari Content Blockers interface instead. Content Blockers cannot intercept or sell your content, since the code is sandboxed and doesn't get network access. NeverAds seems to work well for me.

ebeip90··on Investigating Implausible Bloomberg Supermicro Stories
As a former spook with absolutely no knowledge about this incident, the whole thing sounds like:

* The Chinese supply chain interdiction / implant installation is real

* Those companies ARE aware of such events

* Those companies DID report it to USGOV

* The investigation is classified and Bloomberg didn't know or doesn't care

* The government is doing its traditional "Deny, disavow, do not acknowledge" etc.

* The companies were probably threatened with legal action / gag order preventing them from acknowledging the event

When I started working for DOD, one of the things in training was that you were always to say "I can neither confirm nor deny X". Eventually they realized that this statement itself is revealing, and suggested you just STFU.

The whole thing sounds incredibly plausible, and nooooooooobody was supposed to know about it.

ebeip90··on GDB 8.1 Released
starti did not exist before, and specifically addresses a StackOverflow question of mine from ~3 years ago: https://reverseengineering.stackexchange.com/questions/8724

ptype already existed, but did not print out offsets. This is incredibly useful, and something Windbg does with dt. Pwndbg does this in GDB by adding new commands.

ebeip90··on Return to abort() – Using code introspection to prevent stack-smashing
This isn't very useful, and has some pretty obvious design flaws.

Given any routine which ends with the very common pattern:

    return foo();
Which is assembled to the very common sequence:

    call foo
    leave
    ret
This project will instrument it to now look like:

    call foo
    jmp $+2
    .byte DE, AD
    leave
    ret
Whatever return address I hijack, I can now just point it at this valid return site, and begin my ROP stack as per normal.

What's especially great is that the project guarantees this pattern for us. Now, every function has a path that looks like:

    call __stack_chk_fail
    jmp $+2
    .byte DE, AD
    < function frame cleanup >
    ret
This is effectively a no-op for security.

I cleaned up the author's code, added a sane makefile, and an example exploit here: https://github.com/zachriggle/return-to-abort

(Pull Request: https://github.com/cjdelisle/return-to-abort/pull/1)

← PreviousPage 2 of 2