HNHacker News
TopNewBestAskShowJobs

turbografx16

65 karma · joined September 25, 2016

submissionscomments
turbografx16··on Phrack Magazine
Seconding this. I would vote matrix personally.
turbografx16··on Phrack Magazine
Sounds like fun! Ill check it out.
turbografx16··on Phrack Magazine
I'm also a younger hacker and I have the same issue. I've found 0x00sec.org is alright, and security CTF forums can be decent, but there's an awful lot of people just looking for easy answers and aren't interested in learning or sharing knowledge.
turbografx16··on Phrack Magazine
Where are the hackers hanging out these days? 5 or so years ago /r/netsec was pretty good, and 0x00sec seems a decent (if small) community.

I miss having a place to hang out with other people messing around with random security projects and CTFs...

turbografx16··on CV Compiler is a robot that fixes your resume to make you more competitive
Given how this thread is going I thought I'd mention a resume review robot I actually like.

I use Novoresume.com to build my resumes and I find it's resume suggestions to be pretty useful. It's free for one page resumes too. I am not associated with novoresume in any way, I just like the product.

turbografx16··on A file that’s both an acceptable HTML page and a JPEG (2012)
Don't forget the issue that was a PDF, a ZIP, and an NES ROM that would print its own MD5 when run in an emulator
turbografx16··on Valve Rolls Out Wine-Based “Proton” for Running Windows Games on Linux
A good deed done for selfish reasons is still a good deed done. Frankly I'm just happy to see Linux gaming getting any kind of attention as it's the only reason I still dual boot Windows.
turbografx16··on Introduction to Computer Organization with X86-64 Assembly Language and Linux
I have a few handwritten notebooks on CS and it was a mistake. You're right about the improved retention, but I cant search my notes or reorganize them very easily. I've started using cherrytree instead and having the ability to search through years worth of notes with regex is very handy.
turbografx16··on Newgrad: Post a job for new grads
There's nothing stopping someone from graduating at the age of 56.
turbografx16··on Yes, Amazon Is Tracking People
You shouldn't fucking have to. That just leads to social cooling.
turbografx16··on Ask HN: Old CS lecturer looking for advice from current and recent students
I just finished my Associates in CS, and my favourite classes were the ones that were really, really hard. Case in point, my digital systems design final project had only 6 students complete it, and of those projects only 4 actually worked perfectly.

The opportunity to actually struggle in a "safe" environment is extremely valuable as a learning aid.

Nothing demands a thorough understanding of the material like a fairly complex term project.

My databases class had a similar project, and my information security class had weekly long-form research essays. Doesn't matter, as long as it's hard enough to matter.

turbografx16··on Vigilante Hacks Government-Linked Cyberespionage Group
Probably this. I'm extremely left leaning but even I know vice is absolute dogshit. I used to work in the tar sands with my brother's, and once a year we have a tradition of watching the Vice tar sands "documentary" to laugh at how wildly inaccurate and ill-informed it is.
turbografx16··on Why New York City Stopped Building Subways
Vancouver too. The Canada line expansion killed the vast majority of cambie's family owned / small businesses.
turbografx16··on Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
This is so fishy to me, it's so unprofessional of a security researcher. My tinfoil hat is already rattling...
turbografx16··on Amazon admits Alexa is laughing at people and is working on a fix
That page is fucking gold, thank you so much for sharing.
turbografx16··on Most Important Penetration Testing Commands Cheat Sheet for Linux Machine
Yeah that was the general consensus when this was posted on Reddit, too.
turbografx16··on Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw
Everything you've said is right, but I'll expand a little more because ROP is fun.

ASLR, PIC (position independent code: chunks of the binary move around between executions), and RELRO (changing the order and epermissions of an ELF binaries headers: a common ROP pattern is to set up a fake stack frame and call a libc function in the ELFs Global offset table) are all mitigations against ROP, but none solve the underlying problem.

The reason ROP exists is that x86-64 use a Von Neumann architecture, which means that the stack necessarily mixes code (return addresses) and data. The only true solution is an architecture that keeps these stacks separate, such as Harvard architecture chips.

As for bypassing the aforementioned mitigations...

ASLR: Only guarantees that the base address changes. Relative offsets are the same. So to be able to call any libc function in a ROP chain, all you need is a copy of the binary (to find the offsets) and to leak any libc function address at runtime. There are a million ways for this data to be leaked, and they are often overlooked in QA. Once you have any libc address, you can use your regular offsets to calculate new addresses.

PIC: haven't yet dealt with it myself, but you can use the above technique to get addresses in any relocated chunk of code, but I think you'll need to leak two addresses to account for ASLR and PIC.

RELRO: This makes the function lookup table in the binary read only, which doesn't stop you from calling any function already called in the binary. Without RELRO, you can call anything in libc.so I think, but with RELRO you can only call functions that have been explicitly invoked. This is still super useful because the libc syscall wrappers like read() and write() are extremely powerful anyway. Full RELRO (as opposed to partial RELRO) makes the procedure linkage table read only as well, which makes things harder still.

If this is the kinda thing that interests you, I heartily recommend ropemporium.com which has a number or ROP challenge binaries of varying difficulty to solve. If you're not sure where to start, I also wrote a write-up for one of the simpler challenges [1] that is extremely detailed, and should be more than enough to get you started (even if you have me experience reversing or exploiting binaries)

Disclaimer: I'm just some dipshit that thinks this stuff is fun, if I've made a mistake in the above please let me know. I also haven't done any ROP since I wrote the linked article, so im probably forgetting stuff.

[1] https://medium.com/@iseethieves/intro-to-rop-rop-emporium-sp...

turbografx16··on Benefits of Napping in Healthy Adults (2009) [pdf]
I love coffee naps myself, and I've found that even if I don't fall asleep completely I still end up feeling extremely refreshed. If you have half an hour to experiment with it, I think you'll get a lot out of it.