HNHacker News
TopNewBestAskShowJobs

nullpt_rs

236 karma · joined October 12, 2021

blog: nullpt.rs
submissionscomments
nullpt_rs··on Reverse engineering my ADHD test
I actually wanted to make a YouTube video for this as well! I also have a few more web fingerprinting blog posts in the backlog T_T
nullpt_rs··on Reverse engineering my ADHD test
I do not! Other than when clicking a section from the table of contents. Is it distracting?
nullpt_rs··on Reverse engineering my ADHD test
Why assume malicious intent? I am well aware that the test isn’t just some Math.random() and even includes quotes from the official site that talk more about how their scoring engine works.

I don’t think I was trying to “outsmart” anything, I’m just a naturally curious person

nullpt_rs··on Reverse engineering my ADHD test
Sure! However, I think at that point I just felt trapped and overwhelmed that I no longer cared about the test or its results.
nullpt_rs··on Reverse engineering my ADHD test
Trust, this blog post was in the works for weeks and was actually supposed to have a YouTube video accompanying it that I never finished T_T
nullpt_rs··on Reverse engineering my ADHD test
Agree with original commenter but +1 to reframing the language. I was very afraid to begin medication because I would always hear about how addicting this medication can be. But like you say, you wouldn't tell someone with diabetes that they're addicted to insulin.
nullpt_rs··on Reverse engineering my ADHD test
this method works more often than not :P
nullpt_rs··on Reverse engineering my ADHD test
this sounds interesting! would love to hear more about this
nullpt_rs··on Reverse engineering my ADHD test
hi! author here, please let me know if you have any questions :-)
nullpt_rs··on Reverse engineering my ADHD test
I didn't think of this until after haha
nullpt_rs··on Show HN: I'm building a browser for reverse engineers
I actually wrote a separate blog post about this! Changing the debugger keyword :) see: https://nullpt.rs/evading-anti-debugging-techniques
nullpt_rs··on Show HN: I'm building a browser for reverse engineers
D'oh! You are correct :-) Good catch and thanks for teaching me something!
nullpt_rs··on Show HN: I'm building a browser for reverse engineers
Someone mentioned this as well in another comment. Turns out most of this could’ve been done as an extension after all :-)

edit: actually, wouldn’t you still need to override the global you’d like to instrument? At that point, the toString of the modified function would leak your hook.

see: https://gist.github.com/voidstar0/179990efe918d1028b72f292cf...

Regardless, I do have some interesting ideas that should hopefully make my pain of compiling Chromium for 3 hours worth it though :p

Cheat Engine for site scripts? Who knows. Mostly just using this as an opportunity to learn some browser internals so id say it still paid off :)

nullpt_rs··on Show HN: I'm building a browser for reverse engineers
Thanks for sharing some examples! Someone shared a similar project in the other thread. I didn’t realize this at the time of writing haha.

FWIW I still think modifying the browser has some positives wrt stealth and hooking out of process frames (could be wrong on the second part, haven’t actually tested!)

Still good to know though will leave a note in the article :-)

nullpt_rs··on Show HN: I'm building a browser for reverse engineers
Ooh nice, I haven’t seen this project! I actually tried attempting this as an extension at first but wasn’t able to override page window functions. I’m curious to know how they accomplished this. (edit: I see that I missed the chrome.scripting API facepalm)

Thank you for sharing :)

FWIW I still think a custom browser approach has some benefits (stealth and executing in out of process iframes. could be wrong on the second part, haven’t actually tested!)

nullpt_rs··on Reverse Engineering Vercel's BotID
Sadly, spoofing GPU vendor & renderer can be an even larger flag since they can hash the resulting image of the canvas to compare it with a database of collected fingerprints[0]

[0]: https://research.google/pubs/picasso-lightweight-device-clas...

nullpt_rs··on Breaking WebAuthn, FIDO2, and Forging Passkeys
"breaking" might've been a strong verb here. updated post title to better reflect the intentions of the post :)
nullpt_rs··on Cloudflare blocking Pale Moon and other browsers
Most anti-bots will send other browser characteristics as well and can detect if one is lying about which browser, and even which version they're using based on which APIs and properties are/aren't available.

see: https://blog.castle.io/anti-detect-browser-analysis-how-to-d...

nullpt_rs··on Breaking the 4Chan CAPTCHA
yep, but it can get tricky.

some projects worth checking out: https://github.com/refraction-networking/utls https://github.com/berstend/puppeteer-extra

nullpt_rs··on Breaking the 4Chan CAPTCHA
I (veritas) run the blog but accept contributions from anyone. The blog itself is open source :-) https://github.com/nullpt-rs/blog
nullpt_rs··on Ask HN: Happy 404 Day. Whats your favorite 404 error page?
I used to frequent a site titled "The Best 404 Page Ever" that played a random flash file on refresh.

Seems like someone's recreated it here https://thebest404pageeverredux.com/

nullpt_rs··on The /unblock API from Browserless: dodging bot detection as a service
They have a similar feature labelled "Friendly Bots" https://blog.cloudflare.com/friendly-bots/
nullpt_rs··on Hacking GTA V RP Servers Using Web Exploitation Techniques
I can sorta share this sentiment. Luckily (for us) tech seems to be moving in the direction of embedding Chromium everywhere which always leads to some fun exploits :)
nullpt_rs··on Hacking GTA V RP Servers Using Web Exploitation Techniques
Thank you! Hope to publish more like it soon :)
nullpt_rs··on Evading JavaScript anti-debugging techniques
I knew I forgot to mention something :) I do love this option but I wasn't able to get it to work with this obfuscation technique either.
nullpt_rs··on Better code highlighting on the web: rehype-tree-sitter
Definitely considering switching over my blog to Astro since I write my posts in MDX and using this plugin to avoid doing this work on the client at all (currently use highlight.js and Next).

Lovely work by my friend Haze :)

nullpt_rs··on Reverse Engineering TikTok's VM Obfuscation (Part 2)
Nice work. I was going to basically cover the same topics in my second part but it looks like you beat me to it. If you'd like to collaborate with me on the next portion feel free to contact me on Discord (veritas#0001) or email (f@nullpt.rs)
nullpt_rs··on Devirtualizing nike.com's bot protection
Love these suggestions. Definitely makes dynamic analysis heaps easier. A lot of our blog posts tend to focus on static analysis but it may be worth mentioning these techniques going forward.
nullpt_rs··on Devirtualizing nike.com's bot protection
This isn't the first time I've gotten this comment so I'm looking to change the font stack. Any suggestions? :)
nullpt_rs··on Reverse Engineering TikTok's VM Obfuscation
Thanks for the PR! You should now be able to access the feeds :)

https://www.nullpt.rs/feed.atom https://www.nullpt.rs/feed.rss https://www.nullpt.rs/feed.json

Page 1 of 2Next →