Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. h/t @nyanbinary

h/t @nyanbinary

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
33 Indlæg 18 Posters 133 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.social
    wrote sidst redigeret af
    #1

    h/t @nyanbinary

    so let me get this straight
    microsoft defender, the built-in antivirus tool for windows

    has a heap based buffer overflow that leads to remote code execution

    if you get it to scan a file, and that file is crafted the right way.

    the antivirus tool is the carrier for the execution of malware.

    J mccrankyface@beige.partyM _greywolf@kinkycats.org_ huronbikes@cyberplace.socialH apodoxus@mastodon.onlineA 12 Replies Last reply
    1
    0
    • viss@mastodon.socialV viss@mastodon.social

      h/t @nyanbinary

      so let me get this straight
      microsoft defender, the built-in antivirus tool for windows

      has a heap based buffer overflow that leads to remote code execution

      if you get it to scan a file, and that file is crafted the right way.

      the antivirus tool is the carrier for the execution of malware.

      J This user is from outside of this forum
      J This user is from outside of this forum
      jlin@cosocial.ca
      wrote sidst redigeret af
      #2

      @Viss @nyanbinary antivirus needs an antivirus

      viss@mastodon.socialV 1 Reply Last reply
      0
      • J jlin@cosocial.ca

        @Viss @nyanbinary antivirus needs an antivirus

        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.social
        wrote sidst redigeret af
        #3

        @jlin @nyanbinary i think france, denmark and germany have the right idea - just ditch windows entirely

        crazyeddie@mastodon.socialC 1 Reply Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          h/t @nyanbinary

          so let me get this straight
          microsoft defender, the built-in antivirus tool for windows

          has a heap based buffer overflow that leads to remote code execution

          if you get it to scan a file, and that file is crafted the right way.

          the antivirus tool is the carrier for the execution of malware.

          mccrankyface@beige.partyM This user is from outside of this forum
          mccrankyface@beige.partyM This user is from outside of this forum
          mccrankyface@beige.party
          wrote sidst redigeret af
          #4

          @Viss @nyanbinary

          Microsoft is an APT.
          It is known

          1 Reply Last reply
          0
          • viss@mastodon.socialV viss@mastodon.social

            h/t @nyanbinary

            so let me get this straight
            microsoft defender, the built-in antivirus tool for windows

            has a heap based buffer overflow that leads to remote code execution

            if you get it to scan a file, and that file is crafted the right way.

            the antivirus tool is the carrier for the execution of malware.

            _greywolf@kinkycats.org_ This user is from outside of this forum
            _greywolf@kinkycats.org_ This user is from outside of this forum
            _greywolf@kinkycats.org
            wrote sidst redigeret af
            #5

            @Viss
            Though that kinda is always the risk
            Antivirus just had the biggest attack surface
            @nyanbinary

            nyanbinary@infosec.exchangeN 1 Reply Last reply
            0
            • viss@mastodon.socialV viss@mastodon.social

              h/t @nyanbinary

              so let me get this straight
              microsoft defender, the built-in antivirus tool for windows

              has a heap based buffer overflow that leads to remote code execution

              if you get it to scan a file, and that file is crafted the right way.

              the antivirus tool is the carrier for the execution of malware.

              huronbikes@cyberplace.socialH This user is from outside of this forum
              huronbikes@cyberplace.socialH This user is from outside of this forum
              huronbikes@cyberplace.social
              wrote sidst redigeret af
              #6

              @Viss @nyanbinary

              1 Reply Last reply
              0
              • viss@mastodon.socialV viss@mastodon.social

                h/t @nyanbinary

                so let me get this straight
                microsoft defender, the built-in antivirus tool for windows

                has a heap based buffer overflow that leads to remote code execution

                if you get it to scan a file, and that file is crafted the right way.

                the antivirus tool is the carrier for the execution of malware.

                apodoxus@mastodon.onlineA This user is from outside of this forum
                apodoxus@mastodon.onlineA This user is from outside of this forum
                apodoxus@mastodon.online
                wrote sidst redigeret af
                #7

                @Viss @nyanbinary This is why we always advocated for MAC rather than addling layers of bullshit. Ya'll are just increasing the attack surface area all the time. You need to REDUCE it with a tiny thoroughly audited reference monitor.

                apodoxus@mastodon.onlineA 1 Reply Last reply
                0
                • apodoxus@mastodon.onlineA apodoxus@mastodon.online

                  @Viss @nyanbinary This is why we always advocated for MAC rather than addling layers of bullshit. Ya'll are just increasing the attack surface area all the time. You need to REDUCE it with a tiny thoroughly audited reference monitor.

                  apodoxus@mastodon.onlineA This user is from outside of this forum
                  apodoxus@mastodon.onlineA This user is from outside of this forum
                  apodoxus@mastodon.online
                  wrote sidst redigeret af
                  #8

                  @Viss @nyanbinary Can't make money doing that though... and that's all anyone cares about.

                  1 Reply Last reply
                  0
                  • viss@mastodon.socialV viss@mastodon.social

                    h/t @nyanbinary

                    so let me get this straight
                    microsoft defender, the built-in antivirus tool for windows

                    has a heap based buffer overflow that leads to remote code execution

                    if you get it to scan a file, and that file is crafted the right way.

                    the antivirus tool is the carrier for the execution of malware.

                    jeffers00n@tiny.tilde.websiteJ This user is from outside of this forum
                    jeffers00n@tiny.tilde.websiteJ This user is from outside of this forum
                    jeffers00n@tiny.tilde.website
                    wrote sidst redigeret af
                    #9

                    @Viss @nyanbinary straight out of Jennifer Government. (A good read if you haven't read it)

                    mpc3032at@mastodon.socialM 1 Reply Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      h/t @nyanbinary

                      so let me get this straight
                      microsoft defender, the built-in antivirus tool for windows

                      has a heap based buffer overflow that leads to remote code execution

                      if you get it to scan a file, and that file is crafted the right way.

                      the antivirus tool is the carrier for the execution of malware.

                      slyborg@ohai.socialS This user is from outside of this forum
                      slyborg@ohai.socialS This user is from outside of this forum
                      slyborg@ohai.social
                      wrote sidst redigeret af
                      #10

                      @Viss @nyanbinary this isn’t even the first time this has happened with Defender

                      1 Reply Last reply
                      0
                      • jeffers00n@tiny.tilde.websiteJ jeffers00n@tiny.tilde.website

                        @Viss @nyanbinary straight out of Jennifer Government. (A good read if you haven't read it)

                        mpc3032at@mastodon.socialM This user is from outside of this forum
                        mpc3032at@mastodon.socialM This user is from outside of this forum
                        mpc3032at@mastodon.social
                        wrote sidst redigeret af
                        #11

                        @jeffers00n @Viss @nyanbinary also a subplot in Snow Crash iirc

                        viss@mastodon.socialV 1 Reply Last reply
                        0
                        • mpc3032at@mastodon.socialM mpc3032at@mastodon.social

                          @jeffers00n @Viss @nyanbinary also a subplot in Snow Crash iirc

                          viss@mastodon.socialV This user is from outside of this forum
                          viss@mastodon.socialV This user is from outside of this forum
                          viss@mastodon.social
                          wrote sidst redigeret af
                          #12

                          @mpc3032at @jeffers00n @nyanbinary oh boy its been a while since i listened to snowcrash on audiobook.

                          s'too bad we cant have a "but they're sure to listen to reason" moment

                          mpc3032at@mastodon.socialM 1 Reply Last reply
                          0
                          • viss@mastodon.socialV viss@mastodon.social

                            h/t @nyanbinary

                            so let me get this straight
                            microsoft defender, the built-in antivirus tool for windows

                            has a heap based buffer overflow that leads to remote code execution

                            if you get it to scan a file, and that file is crafted the right way.

                            the antivirus tool is the carrier for the execution of malware.

                            argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
                            argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
                            argv_minus_one@mastodon.sdf.org
                            wrote sidst redigeret af
                            #13

                            @Viss @nyanbinary

                            Ah good. Now I don't have to deal with code signing my app any more. 😂

                            N 1 Reply Last reply
                            0
                            • viss@mastodon.socialV viss@mastodon.social

                              @mpc3032at @jeffers00n @nyanbinary oh boy its been a while since i listened to snowcrash on audiobook.

                              s'too bad we cant have a "but they're sure to listen to reason" moment

                              mpc3032at@mastodon.socialM This user is from outside of this forum
                              mpc3032at@mastodon.socialM This user is from outside of this forum
                              mpc3032at@mastodon.social
                              wrote sidst redigeret af
                              #14

                              @Viss @jeffers00n @nyanbinary aww i remember almost nothing about the book now, but the one lady hacking away feverishly on that was a standout for me at the time, it seemed so cool, in like a 'obvious in retrospect' way... but actually living it derpishly like this is... i dunno 😕

                              (also, hello fediverse! 2nd ~post, woo! and hello fediverse person... you gave me lovely positive feedback in *minutes*... i like this!)

                              more ->

                              mpc3032at@mastodon.socialM 1 Reply Last reply
                              0
                              • mpc3032at@mastodon.socialM mpc3032at@mastodon.social

                                @Viss @jeffers00n @nyanbinary aww i remember almost nothing about the book now, but the one lady hacking away feverishly on that was a standout for me at the time, it seemed so cool, in like a 'obvious in retrospect' way... but actually living it derpishly like this is... i dunno 😕

                                (also, hello fediverse! 2nd ~post, woo! and hello fediverse person... you gave me lovely positive feedback in *minutes*... i like this!)

                                more ->

                                mpc3032at@mastodon.socialM This user is from outside of this forum
                                mpc3032at@mastodon.socialM This user is from outside of this forum
                                mpc3032at@mastodon.social
                                wrote sidst redigeret af
                                #15

                                @Viss @jeffers00n @nyanbinary a couple years back i got depressed about softwaring because of this ~'AI' silliness coming down the pike, but of late it is SO BAD i feel incrementally fired up, renewed

                                riffing wildly, maybe software, because of its peculiar nature (this reified perfection of causality) is a good, stark example of why things should be done by people who love the things...because when not, the error compounds exponentially, and we get *this* (gestures wildly all around)

                                viss@mastodon.socialV 1 Reply Last reply
                                0
                                • mpc3032at@mastodon.socialM mpc3032at@mastodon.social

                                  @Viss @jeffers00n @nyanbinary a couple years back i got depressed about softwaring because of this ~'AI' silliness coming down the pike, but of late it is SO BAD i feel incrementally fired up, renewed

                                  riffing wildly, maybe software, because of its peculiar nature (this reified perfection of causality) is a good, stark example of why things should be done by people who love the things...because when not, the error compounds exponentially, and we get *this* (gestures wildly all around)

                                  viss@mastodon.socialV This user is from outside of this forum
                                  viss@mastodon.socialV This user is from outside of this forum
                                  viss@mastodon.social
                                  wrote sidst redigeret af
                                  #16

                                  @mpc3032at @jeffers00n @nyanbinary yeah i wager youre probably in good company here

                                  mpc3032at@mastodon.socialM 1 Reply Last reply
                                  0
                                  • viss@mastodon.socialV viss@mastodon.social

                                    @mpc3032at @jeffers00n @nyanbinary yeah i wager youre probably in good company here

                                    mpc3032at@mastodon.socialM This user is from outside of this forum
                                    mpc3032at@mastodon.socialM This user is from outside of this forum
                                    mpc3032at@mastodon.social
                                    wrote sidst redigeret af
                                    #17

                                    @Viss @jeffers00n @nyanbinary yay!

                                    Vive la révolution!

                                    (although, evolution preferably... i offer myself to the commons for the cause, lol)

                                    1 Reply Last reply
                                    0
                                    • viss@mastodon.socialV viss@mastodon.social

                                      h/t @nyanbinary

                                      so let me get this straight
                                      microsoft defender, the built-in antivirus tool for windows

                                      has a heap based buffer overflow that leads to remote code execution

                                      if you get it to scan a file, and that file is crafted the right way.

                                      the antivirus tool is the carrier for the execution of malware.

                                      alesandroortiz@infosec.exchangeA This user is from outside of this forum
                                      alesandroortiz@infosec.exchangeA This user is from outside of this forum
                                      alesandroortiz@infosec.exchange
                                      wrote sidst redigeret af
                                      #18

                                      @Viss @nyanbinary Reminds me of Taviso's P0 research from a few years ago targeting AV scanning sandboxes/VMs.

                                      viss@mastodon.socialV 1 Reply Last reply
                                      0
                                      • argv_minus_one@mastodon.sdf.orgA argv_minus_one@mastodon.sdf.org

                                        @Viss @nyanbinary

                                        Ah good. Now I don't have to deal with code signing my app any more. 😂

                                        N This user is from outside of this forum
                                        N This user is from outside of this forum
                                        nowayeast@mastodon.social
                                        wrote sidst redigeret af
                                        #19

                                        @argv_minus_one @Viss @nyanbinary I wonder if I can use this to configure winrm so I can remote in and fix the random shit Microsoft keeps breaking.

                                        1 Reply Last reply
                                        0
                                        • alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

                                          @Viss @nyanbinary Reminds me of Taviso's P0 research from a few years ago targeting AV scanning sandboxes/VMs.

                                          viss@mastodon.socialV This user is from outside of this forum
                                          viss@mastodon.socialV This user is from outside of this forum
                                          viss@mastodon.social
                                          wrote sidst redigeret af
                                          #20

                                          @AlesandroOrtiz @nyanbinary oh yeah, 100%

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper