i didn’t think it was physically possible, but there’s finally something worse than curl | sh
Remote
Rairii

@Rairii@labyrinth.zone
akkoma 3.20.1
some people port doom to things, I port NT to things
Reversing (malware and otherwise); appsec and websec; embedded security; exploit dev; software preservationist; knows how not to use cryptography.
Currently finding bugs in Windows bootloaders.
You may also know me from capcom.sys.
#nobot
Reversing (malware and otherwise); appsec and websec; embedded security; exploit dev; software preservationist; knows how not to use cryptography.
Currently finding bugs in Windows bootloaders.
You may also know me from capcom.sys.
#nobot
3103 Followers
521 Following
50 Posts
he:
him
github:
Open post
what the fuck is this, a weather underground fedi server where they're testing stuff???
https://social-md.wunderground.com
7
2
1
0
Open post
Open post
Replying to
@c0dec0dec0de@hachyderm.io @ciaranmak@mastodon.ie i agree with you, i reverse stuff to learn first and foremost, and would never even think about attaching an llm "agent" to my reversing workflow
6
0
0
0
Open post
Replying to
@GossiTheDog@cyberplace.social at this point it could be all of them at the same time and it would seem like nothing out of the ordinary
12
0
1
0
Open post
Replying to
(apparently 16bpp on classic mac os systems always means rgb555?)
2
0
1
0
Open post
Replying to
and for bios bootmgr specifically some features are out in separate dlls to keep bootmgr.exe smaller
2
0
0
0
Open post
Replying to
@jernej__s@infosec.exchange ok, 0x800f0991 is PSFX_E_MISSING_PAYLOAD_FILE, seems for the first attempt it tries to get files from the downloaded updates(?) which aren't present, then on the second attempt it realises those files are already there(?)
the later errors are because "neither forward delta or null delta exists", i think for all those files that were missing in the first place
I assume dism /online /cleanup-image /restorehealth fixes it?
cc @winload_exe@wetdry.world - any idea how this staging fuckup happened?
1
13
0
0
Open post
Replying to
@jernej__s@infosec.exchange no idea, but given how MS has basically forgotten about CoreN/ProfessionalN i wouldn't be surprised if there was some weird servicing stack interaction happening here
1
16
0
0
Open post
Replying to
@jernej__s@infosec.exchange @GossiTheDog@cyberplace.social
>curl -ik https://fe3.delivery.mp.microsoft.com/ClientWebService/client.asmx
HTTP/1.1 503 Service Unavailable
Content-Type: text/html
X-Content-Type-Options: nosniff
Date: Thu, 23 Jul 2026 17:29:46 GMT
Content-Length: 27
The service is unavailable.
1
20
0
0
Open post
Replying to
@GossiTheDog@cyberplace.social @agowa338@chaos.social well technically the existing poc would work if you knew the pin but not the recovery key, ie insider threat kind of deal
1
8
0
0
Open post
Replying to
@mjg59@nondeterministic.computer slack what???
is this a silly electron thing or something
1
0
0
0
Open post
windows vista install (computer name contains FUCK%) (TAS)
0
2
0
0
Open post
Replying to
lol, i downloaded their nextcloud client fork for windows, it’s an nsis installer with a 7z, and the 7z is called nextcloud-client-refactor_replace-link-server-and-disable-button-master-windows-cl-msvc2022-x86_64.7z
0
4
0
0
Open post
Replying to
@GossiTheDog@cyberplace.social @agowa338@chaos.social in that case, i wouldn't be surprised if "i have a tpm+pin exploit" is just a way to get attention, they certainly got more attention by calling it a backdoor
it would be interesting to be proven wrong though!
0
0
0
0
Open post
Replying to
@errno_fail@infosec.exchange but why would a malformed fat image pointing the data inside the FAT area matter when an attacker could just change the directory entry directly?
0
2
0
0
Open post
oh look, wormable prompt injection https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/
0
4
0
0
Open post
Replying to
@errno_fail@infosec.exchange they say CVE-2026-6682 results in a buffer overflow, but i looked at the code and i don't see that at all
0
1
0
0
Open post
i've been meaning to release bcdeditmod for ages, so here, ahve a tool for researching the windows boot environment, this helped me discover/exploit several bugs so enjoy https://github.com/Wack0/bcdeditmod
this was done in preparation for dropping my own bitlocker 0day (a 20+ year old bug) given MSRC said they were unable to reproduce this one and others are happily dropping bitlocker 0days. having written all the documentation i'm now unsure about committing though...
this was done in preparation for dropping my own bitlocker 0day (a 20+ year old bug) given MSRC said they were unable to reproduce this one and others are happily dropping bitlocker 0days. having written all the documentation i'm now unsure about committing though...
0
4
0
0
Open post
there's a very simple solution to prompt injection, and it's called "don't use large language models"
0
3
0
0
Open post
Replying to
@GossiTheDog@cyberplace.social @jernej__s@infosec.exchange update catalog is up and searches work but it can't actually get any update download links, lol
0
19
0
0
Open post
one ai agent to rule them all, one ai agent to find them, one ai agent to bring them all, and in the darkness bind them
0
2
0
0
Open post
Boosted by @scarlet@chaos.social
there's supposedly a lot of NT people around but i think most of them are faking it because i don't see them porting Windows NT to things
0
2
2
0
Open post
Replying to
@jernej__s@infosec.exchange @GossiTheDog@cyberplace.social for windows update, fe3 is down showing 503 (which means microsoft store downloads are also down lol) but fe2 is still up
0
21
0
0
Open post
Replying to
@agowa338@chaos.social @GossiTheDog@cyberplace.social i swear i remember them fixing that at some point? maybe i'm confused.
if i wasn't wrong then yeah, you'd wait for that which would change settings to tpm-only and then run the exploit on the winpe that gets booted into for upgrade, thats the *only* thing i can think of for a tpm+pin exploit, and that would work if one could cause an upgrade from previous version to germanium too...
i should set up a cobalt vm with bitlocker and check what happens on an upgrade to germanium.
0
0
0
0
Open post
Replying to
@agowa338@chaos.social @GossiTheDog@cyberplace.social the pin+tpm poc if it exists, would be waiting for or somehow causing an event like a major build upgrade that would change bitlocker settings
0
4
0
0
Open post
Replying to
@ariadne@social.treehouse.systems @atax1a@infosec.exchange thats why it's slop, nobody really cared
0
3
0
0
Open post
i saw that MIPS CE on N64 thing. was excited until i realised they used claude (claude is on one of the commits and "a blocked user has committed to this repo" doesn't show up?! i ended up realising something was up because there was an em-dash in a comment).
at least the repo has documentation for interesting little endian mode hardware issues. including an unaligned uncached write thing that's eerily similar to what happens on GC/Wii.
at least the repo has documentation for interesting little endian mode hardware issues. including an unaligned uncached write thing that's eerily similar to what happens on GC/Wii.
0
2
0
0
Open post
Replying to
sudden thought that nitrogen could have done the funniest thing and threatened foxconn with a license audit
0
0
0
0
Open post
Replying to
@GossiTheDog@cyberplace.social @agowa338@chaos.social but yeah, it wouldn't bypass the pin entirely, some bitlocker key dumping issues could be implanted by an evil cleaner as they get arbitrary code execution with the volume keys derived, this one isn't that case it just pops a shell
when i saw the thing with "it can bypass the pin" i was thinking they got confused between the bitlocker pin and the logon pin.
0
1
0
0
Open post
ok that’s really funny
so IBM used Apple’s Open Firmware on the 43p-150 (seems to be a derivative of the one used on motorola viper, the 43p-150 chipset is almost a motorola viper fwiw)
and it turns out they left this in there:
: bye
" boot /AAPL,ROM"
eval
;
this is a leftover from old world macs, even the dumped motorola viper bootrom image changed it to “boot macos”
0
0
0
0
Open post
Replying to
@AsahiLinux@social.treehouse.systems macOS 27 🤝 Old World PowerPC Mac OS
figuring out how to make a partition visible in Startup Disk
0
1
1
0
Open post
Replying to
@gudenau@hachyderm.io several filesystems supported; bitlocker; several boot device types including ramdisk, file, vhd; nt kernel debug protocol for debugging as well as several transports for that (serial, network, usb)
in more recent times they added support for refs and something called "cimfs" which added a good chunk of code
0
1
0
0
Open post
looking at that pile of fatfs bugs, i don't see how CVE-2026-6682 is exploitable? given the value is just used to calculate the start of actual cluster data (the end of the root directory)
as for the rest:
CVE-2026-6687 is real, a length arg should have been added with exfat support, but let's be honest, who uses f_getlabel anyway?
CVE-2026-6688 is arguably something that modern compilers should be warning on when lfn support is enabled (given that extends the 12 byte static buffer to a 256 byte static buffer) but embedded development can be a pain so yeah
CVE-2026-6685 is something that absolutely sounds like a bug that needs fixing but not a security issue, unless you're going by the linux kernel's "every bug is a CVE now" posture
any crash bug like CVE-2026-6683 or CVE-2026-6684 sounds like "eject this media and try again"
CVE-2026-6686 is literally mentioned in the documentation lol how is this a bug if you don't read the documentation of the library you're using that's just a skill issue
my conclusion: someone let an LLM loose on fatfs and asked it to find vulns didn't they
0
6
1
0
Open post
just noticed that last month (2026-06-12) Microsoft changed Copilot terms of use to remove the “for entertainment purposes only” part
old (https://www.microsoft.com/en-gb/microsoft-copilot/for-individuals/termsofuse/archives - “October 2025”):
Copilot is for entertainment purposes only. It can make mistakes and it may not work as intended. Don’t rely on Copilot for important advice. Use Copilot at your own risk.
new (https://www.microsoft.com/en-gb/microsoft-copilot/for-individuals/termsofuse)
Copilot can make mistakes and it may not work as intended. Do not use Copilot as a substitute for professional advice. Always verify the accuracy of information presented by Copilot before you rely on it. We are not responsible for any consequences that arise from your use of or reliance on Copilot.
0
2
0
0
Open post
Replying to
also their mastodon fork seems to have been forked from a random main commit instead of an actual release, given that it reports itself as version 4.4.0-alpha.4
0
2
0
0
Open post
it appears that a lot of the stuff in the currently released foxconn leaks relates to Foxconn Industrial Internet (albeit i haven't downloaded the biggest tarball yet)
so if you're interested in the internals of server hardware used by and in some cases specifically commissioned for cloud hosting vendors/etc, you're in luck
so if you're interested in the internals of server hardware used by and in some cases specifically commissioned for cloud hosting vendors/etc, you're in luck
0
0
0
0
Open post
Replying to
the two smaller files contain a bunch of pdfs
started to download the 10gb file, it has at least: one git repo containing some verilog for some cpld, which appears to be from google
0
0
0
0
Open post
Replying to
@errno_fail@infosec.exchange like, if something trusts the file size like this, why bother pointing the directory entry inside the FAT? you can just write out a larger file to a correctly formed FAT image???
0
0
0
0
Open post
Replying to
@GossiTheDog@cyberplace.social yeah that mitigation should work given my own research, not sure if it'll break future winre updates though
should be scriptable though.
bios password wouldn't mitigate this as it's a thing with booting into winre which can be done by just poweroff during boot a couple of times
and it wouldn't mitigate most other bitlocker related issues for the same reason considering winre has functionality equivalent to the uefi boot menu.
0
0
0
0
Open post
fixed a bug in my cuda driver code thanks to MAME LLEing it, i was setting the gpio direction to input at the wrong state transition, which appears to have had the effect of forcing some bits of the final transferred byte high
(needed to fix an unaligned access i missed in the hal too)
(needed to fix an unaligned access i missed in the hal too)
0
0
0
0
Open post
Replying to
@jernej__s@infosec.exchange (basically i'd need dism/cbs logs to figure out more about what's going on here)
0
15
0
0
Open post
OH: to err is human, to really screw things up requires a techbro
0
0
0
0