Viewing profile — bahorn
bahorn
HN member- Joined
- Tue, Apr 04, 2017, 7:59 AM UTC
- HN karma
- 63
- Public activity
- 17 items
- HN profile
- View on Hacker News ↗
About bahorn
Recent public activity
-
comment
Comment #43358672
Stack Clashing is pretty neat, something you should really pay attention to in embedded spaces (its often exploitable in UEFI land as most EDK2 builds lack guard pages). I got to w…
-
comment
Comment #40804195
Bit confused on how this group got access to the rabbit codebase, as this sounds closer to backend code and not jadx'ing the APK. Are there any details on that?
-
comment
Comment #40256762
I understand the issue, I have checked /dev/pts/ and seen systemd-run create a user readable pts there. I'm not adverse to that one getting chown()'d, but there really isn't any im…
-
comment
Comment #40254646
This is not a systemd-run specific issue either. I reproduced this targeting sudo (just `cat` the parent tty), in fact able to capture my password as I type it in, and capture comm…
-
comment
Comment #40249493
I put a bit further thought into this. The claim is that because the pty has user permissions its possible to hijack it, but that really hasn't been true for years which is why the…
-
comment
Comment #40230409
This is not a real bug and the trick is possible with sudo if you just hijack the parent process of sudo with reptyr instead of sudo directly. Also seems a bit absurd to try and pr…
-
comment
Comment #34784705
From their FAQ and blog posts, I don't believe they apply much FHE. Seems what they do is use work from a different subfield [1], which seems to be able to achieve the required spe…
-
comment
Comment #31042842
It actually does run on KVM! I spent yesterday trying to get it to work and found the trick was setting the chipset to i440FX, and putting every drive on the IDE bus. Probably not …
-
comment
Comment #29590015
Far from the most qualified to answer this but it's probably a mixture of market demand, the targets, mindshare and QA. Higher value targets tend to use iOS more often so their adv…
-
comment
Comment #28995662
I stumbled upon a talk from GRCon18 a few weeks ago where they did this [1], though on a much more restricted testcase. Find the idea interesting, but I'm curious how resistant it …
-
comment
Comment #27831923
I've ran some student hackathons in the UK (worth noting we have a very different culture than the US scene) and we actually tried to discourage the whole working 24 hours straight…
-
comment
Comment #27300337
Worth noting that it's quite common for people to not be publicly listed as part of Github organizations. The archive.org snapshot of the organization page from February [1] shows …
-
comment
Comment #26033989
While the authors of this definitely didn't handle this well, I'd argue it's a pretty severe weakness and the tool shouldn't have been released in this state. Active probing has be…
-
comment
Comment #25761723
The google form lists the prices in an image: * $119 for 4GB of RAM * $149 for 8GB of RAM But the early version apparently is only the 8GB variant.
-
comment
Comment #25638677
Been using the project for a year now and submitted a few patches. It's a fun project to hack on, so would recommend getting involved if this sort of thing interests you. Regarding…
-
comment
Comment #18821957
I arranged everything on day I needed to move on (except in Dushanbe where I arranged the transport to Khrough via the hostel, who I just told the night before). Worked even on the…
-
comment
Comment #18819474
I did the journey in early September, starting in Dushanbe, as part of my backpacking trip throughout Central Asia. Highlight of my trip. Surprisingly easy to travel as a lone back…