Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Zhuowei Zhang

@zhuowei@notnow.dev
pleroma 2.10.2
  • Open on notnow.dev
Mostly bad puns. It's pronounced "joe-way". Happy to explain jokes.
he/him, opinions are my own. https://zhuoweizhang.net
2737 Followers
0 Following
50 Posts
Joined January 17, 2021
Bluesky:
https://bsky.app/profile/zhuowei.notnow.dev
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago
The `left-pad` incident was 10 years ago today.

https://en.wikipedia.org/wiki/Npm_left-pad_incident

Thankfully, we've completely solved software supply chains in the years since.
en.wikipedia.org
310
27
209
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 2mo ago
Figma runs a local server with a valid *signed* SSL certificate for https://figmadaemon.com:44960 (resolves to 127.0.0.1) ?!

https://gist.github.com/Willamin/dedc1de2d1d5d4e8db4e49b25007a34c

I thought this was not allowed?
(https://groups.google.com/g/mozilla.dev.security.policy/c/eV89JXcsBC0/m/wsj5zpbbAQAJ?pli=1)

What certificate authority allowed this?!

> Comodo

Ah
figmadaemon.com
25
10
6
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 5mo ago

At long last, we have stolen the macOS from classic kernel extension Dont Steal Mac OS.kext

42
4
11
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 5mo ago
Want to tell a salesperson and an engineer apart?
Ask them to pronounce "codesign"
23
7
4
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago
James Bond's "License to Kill" approved by Debian as a Free Software license
28
0
11
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago

A Windows @0xabad1dea@infosec.exchange in transactional NTFS?

usb stick says trans writes

arstechnica.com
14
2
8
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 5mo ago

Kaspersky researchers just found and presented a Snapdragon 410/210/617 bootrom exploit - CVE-2026-25262 in this month’s Qualcomm security bulletin.

It’s well known that every forensics tool supported exploiting those SoCs from the bootrom, but for 9 years, nobody knew how they were doing it.

This is some amazing research that finally solves the mystery..

I’m sure the BananaHackers community of Snapdragon 210 flip phone modders will find a use for this.

i.blackhat.com
14
0
7
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago
MacBook Neo · Geo

MAX 8192 MEGA
PRO–GEAR SPEC
21
0
7
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago
Just bought $1.4 trillion of GPUs from OpenAI after they shut down Sora.
I can finally run Crysis on Medium settings.
21
2
7
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 2mo ago
Rapid7 got a stack smash on... a Brother laser printer
https://www.rapid7.com/blog/post/multiple-brother-devices-multiple-vulnerabilities-fixed/
https://www.rapid7.com/cdn/assets/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf
https://bsky.app/profile/stephenfewer.bsky.social/post/3lsg7ubf3ek2h
rapid7.com
3
0
2
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 5mo ago
If our universe is a computer simulation, then all those "Can it run Doom?" demos actually all ran on the same computer
11
8
9
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 3mo ago

Still reading through gracecondition’s DirtySlide writeup (https://gracecondition.github.io/posts/dirtyslide/).

The writeup says it’s only usable in a macOS virtual machine - not a physical macOS/iOS device. Has anyone looked further into this?

The writeup gives two reasons:

Triggering 536 in the vulnerable context needs an application sandbox bypass.

iOS does support residing shared caches:

  • https://projectzero.google/2021/01/a-look-at-imessage-in-ios-14.html#:~:text=for%203rd%20party%20apps%20this%20means says that if an app crashes inside the shared region, launchd will re-launch the process next time with _POSIX_SPAWN_RESLIDE.

And the shared_region_map_and_slide_2_np syscall exists iOS should allow the syscall, at any rate: https://github.com/Lessica/iOS-Sandbox-Profiles/blob/9bf1164cee918fcbf09bb918ef277d2dccfe8078/profiles/23C55__iPhone12%2C1/builtin_collection/container/container.sb#L9789 (unless you’re in lockdown mode in WebKit?) https://github.com/WebKit/WebKit/blob/30dcf5d1c9402dea5a26158e103f7e4333a7eac2/Source/WebKit/WebProcess/com.apple.WebProcess.sb.in#L1241

It also needs an SPTM (Secure Page Table Monitor) bypass

Do you have to spray page tables or can you spray something else that also lands in the physmap?

I mean, I doubt anyone will actually look into this, since a kernel r/w isn’t enough for a jailbreak. It can only do kfd-style mods, and we already have those on iOS 26.0 via Darksword.

gracecondition.github.io
4
3
2
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 1mo ago
Had a go at making koiTerminal build in Android Studio, since I want to play with Android Virtualization Framework but don't want to build AOSP.
1
2
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 2mo ago
It-It's not like I like you or '1'='1'
2
0
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago

Sunday is the 10-year anniversary of the npm left-pad incident.

en.wikipedia.org
10
0
10
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago
Premultiplied Alpha Male
8
0
3
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
When did Ghidra start supporting reading DWARF debug data for macOS kernels?
I got a surprise when Ghidra started showing decompiles with variable names.
4
0
1
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 5mo ago
Broadcom acquires the virtualization platform simulating our universe
4
2
3
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago
The "S" in "Vibe coding" stands for "Security"
6
0
1
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 2mo ago

32 GB of RAM?

We're going to need a miracle.

██ENG███
█OOMSDAY
1
0
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 2mo ago
Replying to
@Aissen@social.treehouse.systems I enabled DoH in Firefox and tried https://figmadaemon.com:44960 ; it seems to open still.
figmadaemon.com
1
2
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 2mo ago
Replying to

@AlesandroOrtiz@infosec.exchange Yes. (Every time I run netstat -a -n on my computer, I see this port, and every time I go on the internet and search for it.)

1
0
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago
I'm still amused that the Linux distro for Gamers is a Fedora remix.
You'd expect, like, Gentoo, or at least Arch like SteamOS - but no, Bazzite is a Fedora Atomic distro.
4
5
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 3mo ago
Replying to
@siguza@infosec.space Starting an app from Xcode lets you break on entry, before dyld runs. However, I don't know if starting an app from Xcode goes through launchd and the reslide path.
1
2
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 3mo ago
Replying to
I’m guessing the vm_shared_region_slide_page_v5 change is one of the kernel memory corruption CVEs (CVE-2026-39868 or CVE-2026-43724, can’t tell) I don’t see how the vm_map_msync issues can cause kernel memory corruption, so it’s probably not the cvevm_shared_region_map_file: an LLM thinks it might lead to read out of bounds and a denial-of-service, but no memory corruption (https://gist.github.com/zhuowei/5a78638228263e02697e43d24c8f63b7) I don’t have enough experience to tell if that’s truevm_shared_region_slide_page_v5: seems like you could get some memory corruption - if you manage to map a shared region with a page_starts that points past a page, and have your corruption target on the very next page of physical memory. Can you do that?
output.md
Gist

output.md

GitHub Gist: instantly share code, notes, and snippets.

1
4
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago

There is no electro-motive division

2
0
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
Replying to
Tried diffing 15.7.5 without DWARF on Ghidra 12.0.4: BinDiff gave me "Error: AttachFlowGraph: couldn't find call graph node for flow graph 00000000". Will go back to an older Ghidra version and try again. (... how do you all patch diff stuff?! Do you go through this every time?)
1
2
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 5mo ago
Replying to
@tihmstar@infosec.exchange You're not reading the right press releases: https://www.google.com/search?q=site%3Anvidia.com+codesign
google.com

Google Search

1
3
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago
Mastodon-Bluesky crossposter (pair-o'-social relationship)
1
4
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
Replying to
At any rate, the LLM’s suggestion msgctl(IPC_SET) + msgctl(IPC_RMID) only seems to be callable as root.
0
0
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 6mo ago
This piece of code I'm researching is well-written enough and small enough that, after an hour of fuzzing, it reached full coverage with only a few harmless 1-byte over-reads detected.

So I guess all those commenters are right after all: you can write secure C code.
0
0
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
Replying to
In the end I couldn't get this to work on Ghidra 12.0.4 since it gave me a "Storage does not have a stack varnode" error: https://github.com/NationalSecurityAgency/ghidra/issues/9131 Will try with an older Ghidra.
GitHub

CodeUnitFormat.getOperandRepresentationString() throws UnsupportedOperationException on ARM/AArch64 · Issue #9131 · NationalSecurityAgency/ghidra

Describe the bug CodeUnitFormat.getOperandRepresentationString() throws an unchecked UnsupportedOperationException ("Storage does not have a stack varnode") on an instruction that Ghidra's own anal...

0
4
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
Replying to
My Little Pony: Equestria Girls
OK, so my theory doesn’t survive the most minimal scrutiny. In the first movie, the portal specifically only opens every 30 months, not 4 years Sunset’s crowns are more likely for Grade 9 Spring Prom, Grade 10 Fall Homecoming, and Grade 10 Spring Prom, not 3 Homecoming dances. This lines up with the 30 months/2.5 years timeline, and matches the fandom’s consensus, which states the first film takes place in the fall of Grade 11. … but while it doesn’t fit our Sunset Shimmer, it might explain what happened to the human counterpart of Sunset Shimmer…
0
0
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 3mo ago
Replying to

@65GHz@toots.nu curses, I missed the "A file descriptor of -1 is used to indicate that the data to be put in the shared region for this mapping comes directly from the processes address space." branch in shared_region_map_and_slide_setup.

Make the neighbour a page table Could you put something else there?

0
1
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
Replying to
Ah. Ghidra docs: "NOTE: ExtensionPoint logistics have changed! It is no longer sufficient to implement ExtensionPoint in order for the ClassSearcher to dynamically pick up your class." https://ghidra.re/ghidra_docs/api/ghidra/util/classfinder/ExtensionPoint.html BinExport now provides a Ghidra script instead to start the export process instead.
ghidra.re

ExtensionPoint

declaration: package: ghidra.util.classfinder, interface: ExtensionPoint

0
5
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
Replying to
OK, I’m not smart enough to figure out if the msgctl(IPC_SET) is exploitable: an LLM outputs one plausible-sounding vector (https://gist.github.com/zhuowei/390b9e171641561f88ceb2119d984bc1) but I am not knowledgable to say whether it’s doable or if it matches CVE-2026-28986.
msgctl_Analyzing XNU IPC Security.md
Gist

msgctl_Analyzing XNU IPC Security.md

GitHub Gist: instantly share code, notes, and snippets.

0
1
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 2mo ago

wint @dril

every generation deserves at least 5 ponies named "Twilight Sparkle"

wint (@dril) on X
X (formerly Twitter)

wint (@dril) on X

every generation deserves at least 5 movies named "Spider Man 2"

0
0
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
Replying to
(I did shove xnu's NFS server and NFS client kext into an LLM, and it didn't find any bugs. So the actual bug might not be in NFS - maybe they're just using NFS as part of the exploit?)
0
0
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
Replying to
Same "Storage does not have a stack varnode" error on Ghidra 11.4.2. Per the comments in that issue, I'm going to try importing the kernels without DWARF and see if that fixes it.
0
3
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 5mo ago
Replying to
@tihmstar@infosec.exchange https://www.merriam-webster.com/dictionary/codesign https://developer.apple.com/videos/play/wwdc2023/10061/?time=872
merriam-webster.com
0
5
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 5mo ago
Replying to
@tihmstar@infosec.exchange Then you're looking for this: https://www.bleepingcomputer.com/news/security/malware-now-using-nvidias-stolen-code-signing-certificates/
Malware now using NVIDIA's stolen code signing certificates
BleepingComputer

Malware now using NVIDIA's stolen code signing certificates

Threat actors are using stolen NVIDIA code signing certificates to sign malware to appear trustworthy and allow malicious drivers to be loaded in Windows.

0
2
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago
Replying to
More macOS 15.7.7 diffs: msgget, instead of doing /* Make sure that the returned msqid is unique */ msqptr->u.msg_perm._seq++; (seq is a short) Now does something fancier: (decompiled:) int uVar1 = msqptr->u.msg_perm._seq; msqptr->u.msg_perm._seq = uVar1 & ((short)uVar1 >> 0xf ^ 0xffffU); https://github.com/apple-oss-distributions/xnu/blob/5c306bec31e314fa4d8bbdafb2f6f5a6b7e7b291/bsd/kern/sysv_msg.c#L670
GitHub

xnu/bsd/kern/sysv_msg.c at 5c306bec31e314fa4d8bbdafb2f6f5a6b7e7b291 · apple-oss-distributions/xnu

Contribute to apple-oss-distributions/xnu development by creating an account on GitHub.

0
3
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 4mo ago

Huh, macOS 15.7.7 removes MACH_VOUCHER_ATTR_KEY_TEST from the kernel. https://github.com/apple-oss-distributions/xnu/blob/5c306bec31e314fa4d8bbdafb2f6f5a6b7e7b291/osfmk/ipc/ipc_voucher.c#L2761 According to the comments, iOS already removed the whole voucher subsystem, anyways, so it’s not interesting - but I wonder why they had something named _TEST compiled into a production kernel…

GitHub

xnu/osfmk/ipc/ipc_voucher.c at 5c306bec31e314fa4d8bbdafb2f6f5a6b7e7b291 · apple-oss-distributions/xnu

Contribute to apple-oss-distributions/xnu development by creating an account on GitHub.

0
3
0
0
Open post
Zhuowei Zhang @zhuowei@notnow.dev
· 3mo ago
Replying to
I don't think the vm_shared_region_slide_page_v5 is exploitable in practice since he kernel checks dyld caches must be owned by root and on a SIP-protected volume. So I don't think you can even reach this code?)
0
3
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:23:05 UTC