Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

endrift 🏳️‍⚧️

@endrift@social.treehouse.systems
mastodon 4.6.7+glitch-th
  • Open on social.treehouse.systems

Professional Cyberentomologist, Hobbyist Emulator Developer. Purveyor of cursed technological information.

1120 Followers
49 Following
50 Posts
Joined February 09, 2023
Pronouns:
she/they
Primary dev on:
mGBA
Website:
https://endrift.com
GitHub:
https://github.com/endrift
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 1mo ago
Replying to
The point being: anyone claiming to fund Omarchy is effectively just directly bankrolling DHH with a plausible veneer of legitimacy.
29
1
8
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 1mo ago
Replying to
There are other repos on GitHub here that show he might have at least one further person working on it, but none of those repos are very large so I didn't dig further.
12
1
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
Vibe coding delenda est
54
2
32
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 3mo ago
Replying to
If the bot doesn't understand code that's changed in the last four years it's gonna have massive issues understanding the difference between the kernel now and the kernel next year too. Just fucking great work everyone, promotions all around
21
2
3
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago

I'm sooooooooo fucking tired of that new pattern that several sites I use have implemented where if you click on a link it doesn't open the link, it pops open a sidebar with a preview of the thing but narrow and on top of your page. GitHub does it, GitLab does it, Sentry does it. It makes the site harder to navigate. The browser HAS A BACK BUTTON FOR A REASON.

31
7
7
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago

I thiiiink I might have messed up the resistor value

17
1
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
Squall, for the record, has always been useless and is partially responsible for me deciding not to work on VBA and start mGBA instead. He speaks authoritatively but is so wrong so often.
13
0
1
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 2mo ago
Hey Apple what the fuck
4
0
1
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago

You ever have one of those days

13
0
1
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@0xabad1dea best response to IPv8 I've seen yet
10
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago

I like to say that Pokémon gen 1 is a hot mess, but if it's still hot after 30 years and hasn't cooled off yet, it's probably a hot, radioactive mess

9
0
1
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 3mo ago
Replying to
It reliably hallucinates that passing a negative value to ida_free will panic the kernel. They removed that check four years ago. This bot is a few months old.
3
0
1
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
It's a doubly-obfuscated Python program that I think is being used in the current Discord credential stealing campaign. It installs itself into AppData/Roaming/Google/Runtime/CLRHost/[hex garbage]/ and names the Python binary as ls_crashpad_handler.exe. The malicious script names itself node_modules.asar to attempt to blend in. It's a base85-encoded Python program which itself is a base64-encoded zlib compressed Python program that contains the actual Python program.
7
1
3
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@agturcz @ersatzmaus @0xabad1dea technically we have the ability to do that! But it's way more expensive than just mining gold the old fashioned way.
6
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@0xabad1dea oversimplifying, but only a bit. I have sometimes thought about how I would explain a smartphone to someone from several hundred years ago without it being just "magic". That said, I'm pretty sure historically "magic" was just things that lay people couldn't explain (and associated with witchcraft or trickery), so maybe they are magic.
6
5
1
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 4mo ago
Replying to
@jernej__s@infosec.exchange @matildalove@wetdry.world @valpackett@social.treehouse.systems mostly true, but one addendum: they cost way less than one cent (though a proper implementation requires two; one on each CC line). This is bottom of the barrel cheaping out, which makes it all the more disappointing when you find it on something that costs more than $5
3
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 3mo ago
Replying to
It's had me running around in circles trying to figure out concurrency issues that I'm pretty sure at this point are flat impossible, but I'm not intimately familiar enough with how USB IRQs work on Linux to be able to say otherwise!! I'm so exhausted from trying to fix things it dreams up that I'm making mistakes I wouldn't have otherwise
2
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 3mo ago
Replying to
Also like? It's not actually including the maintainers of the driver the patch is for or any of the other To: addresses when it sends the email, so when I tell it off so as to appear on the mailing list with my refutations, I'm apparently not sending the email to the HID maintainers since they never got the sashiko review in the first place!!!
2
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
Anyway yeah if a malware analyst follows me and wants any of the stages involved, from the raw Python script to the machine code payload lmk
5
2
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
The program itself is heavily Windows-specific to a degree I don't understand. It appears to inject a block of machine code (I see a nop sled at the beginning of the bytestring) into something but I'm out of my depth here. SHA-256 of the file is e86c0415e102c0e72265f7145b472e85e537135866e33e8d865d536f6e569c1c and I've uploaded it to VirusTotal: https://www.virustotal.com/gui/file/e86c0415e102c0e72265f7145b472e85e537135866e33e8d865d536f6e569c1c
virustotal.com
5
8
1
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@jcoglan @sven I instantly recognized it when I was scrolling through that page. Got a good chuckle out of me.
4
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
Ok, it looks like it starts the CLR...in the Python process I think? Some code is run next that I don't know exactly what that does, but it seems to monkeypatch the clr DLL in the current process, which I think specifically is to bypass the Anti-Malware Scan Interface by replacing a reference to amsi.dll with ansi.dll. And then it invokes the payload in the process itself using LdrCallEnclave, I think.
4
4
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
So to summarize: Disguised Python loader loads a base85 Python script, which itself loads a base64 zlib-compressed Python script, which injects some machine code into another process, which likely contains further obfuscations.
4
5
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@rachel@transitory.social probably some combination of that an unrealistic expectations from management via accelerated schedules. A disaster waiting to happen.
3
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
Had to make minor tweak to get it to repro on NetBSD but it was really, really minor. Anyway, I've sent it off to their security team. Really hoping I can close the book on this vuln after a fucking decade.
3
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
I don't think it actually injects this machine code as a payload actually, it just loads it into memory as a bytestring in Python, remaps the memory as executable, and then calls directly into it, with some malware-prevention bypass stuff in the middle.
3
3
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
I will provide the deobfuscated virus on request if any malware analysts want it.
3
7
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 3mo ago
Replying to
@gvenema@fairmove.net @lisamelton@mastodon.social From my experience working on the WebKit team at Apple (2011–2014), it always seemed like Google had an army of engineers working on Chrome and we had a dozen or so people working on WebKit. We just didn't have the workforce to keep up after they forked. There were other contributors but for the most part they were doing platform integrations, not core features. Was kinda depressing.
1
2
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 3mo ago
Replying to
@gvenema@fairmove.net @lisamelton@mastodon.social Meanwhile I was frustrated by how quickly Chrome kept throwing new shit at the wall and saying "this is now the way", as though the old way to do something was completely useless now. It felt like an anti-competitive attempt to railroad the market onto using Chrome when the web devs kept gobbling it up. And now everything is Chrome...
1
1
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@mjdxp@labyrinth.zone I didn't care too much before (hence the "not that bad" and I'd sometimes tell people to knock off making fun of it in the mGBA discord) but the vibe coding is going to make it even worse. I expect brand new security bugs if I try to audit it again in a year.
2
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@alsvha@sunny.garden I remember when everyone said "we need to do MapReduce"...
2
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@davidgerard @dysfun ...this option said +$489.00 a week ago. They're gonna steal my RAM, aren't they?
2
2
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
I suspect this stage is just a payload injector that is installed into something else. The payload itself is a 781579 byte blob of x86 machine code. I suspect that payload isn't even the main payload but instead an encrypted blob and decryption stage for the final payload. But I really don't feel like tossing the blob into ghidra. SHA-256 of the machine code blob is 64f70a4cfdf24b817c795ea28b90cad23af92f640c616464bbea365d4c1c89aa.
2
1
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 4mo ago
Replying to
@0xabad1dea@infosec.exchange I've seen them. They aren't that rare anymore, apparently. I only started seeing them once I moved to Washington though; I think their range is kind of limited. Hawks are a lot more common though.
1
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@Ashmire @0xabad1dea I'm familiar with the Mechanical Turk. I still cannot believe Amazon decided to name a service after it.
1
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@davidgerard @dysfun Laptop has been returned. My RAM was not stolen. This is US service though, not UK.
1
1
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@mjg59@nondeterministic.computer there's a joke here about what UTF stands for
1
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@rednikki @cr1901 the sarcastic remarks in the trailer about that whole situation are so good
1
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@flacs clearly I should send you the most obfuscated version then and you can work your way inwards
1
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 5mo ago
Replying to
@0xabad1dea (I thought about approaching him and telling him how much I loved the Game of Life and cellular automata when I was a kid, but I reasoned he'd probably heard enough about that for one lifetime and it was likely one of the less interesting things he'd worked on...)
0
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 3mo ago
Replying to
@mjg59@nondeterministic.computer man, PCMCIA cards were so cool. Now everything's a USB dongle with a cable that stops working properly after 2 years and you need to buy a replacement
0
0
0
0
Open post
endrift 🏳️‍⚧️ @endrift@social.treehouse.systems
· 2mo ago
Boosted by @GroupNebula563@mastodon.social
Damn, the assembled case I printed for the BC-250 (cut down PS5 board designed for cryptomining but decent at gaming) is really big. Steam Machine for scale.
0
0
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 11:23:43 UTC