jduck
@jduck.me
📤 677
📥 246
📝 49
Continuously learning about computer security through research and development.
It's official. No hacker summer for me due to family health complications. I will miss everyone but hope you have a great (and safe) time!! ❤️
4 months ago
0
3
0
reposted by
jduck
Zion Leonahenahe Basque
7 months ago
I'm proud to announce that myself and @AtipriyaBajaj have created the Workshop on Software Understanding and Reverse Engineering (SURE), which will be co-located at CCS 2025.
sure-workshop.org/
Please follow our workshop account
@sureworkshop
and RT it for visibility :).
loading . . .
SURE 2025 | The Workshop on Software Understanding and Reverse Engineering
The Workshop on Software Understanding and Reverse Engineering
https://sure-workshop.org/
1
7
6
reposted by
jduck
Binary Ninja
7 months ago
We're proud to announce the release of Binary Ninja 5.0. Here's some highlights: Union Support, Dyld Share Cache & Kernel Cache, Firmware Ninja, Auto Stack Arrays, Stack Structure Type Propagation, and so much more. Check out the blog post for more information:
binary.ninja/2025/04/23/5...
0
25
16
reposted by
jduck
Steve Klabnik
7 months ago
Does using
#rustlang
really make your software safer?
tweedegolf.nl/en/blog/152/...
loading . . .
Does using Rust really make your software safer? - Blog - Tweede golf
We keep saying that Rust is how we make software safer. In this blog, we'll tackle a real-world vulnerability, 'rewrite it in Rust', and show you the results of our empirical research, both as a h ...
https://tweedegolf.nl/en/blog/152/does-using-rust-really-make-your-software-safer
1
54
20
I'm proud to announce that I, through my company
@magnetitesec.bsky.social
, donated to the Redox OS project! If you're not familiar, Redox OS is a pure Rust Micro kernel based operating system. This donation allows them to sponsor one additional student for their Summer of Code!
7 months ago
0
9
2
I played
@defcon.bsky.social
CTF quals with
@shellphish.bsky.social
this year! I'm really impressed with the difficulty levels Nautilus Institute put forth. Making CTF challenges in the AI era has... special considerations... but they nailed it :-) Thanks to everyone involved for a great weekend!
7 months ago
0
5
0
reposted by
jduck
Quarkslab
8 months ago
There is a small bug in the signature verification of OTA packages in the Android Open Source Framework. Official builds doing normal double verification of packages are not vulnerable but OEMs and third party apps may be. Jérémy Jourdois explains it here:
blog.quarkslab.com/aosp_ota_sig...
loading . . .
A small bug in the signature verification of AOSP OTA packages
A signature verification bypass in a function that verifies the integrity of ZIP archives in the AOSP framework
https://blog.quarkslab.com/aosp_ota_signature_bug.html
0
5
5
reposted by
jduck
Elias 🦀🇵🇸
8 months ago
"Building a Linux Kernel Driver using Rust":
rust-exercises.ferrous-systems.com/latest/book/...
loading . . .
Building a Linux Kernel Driver using Rust - Rust Exercises
https://rust-exercises.ferrous-systems.com/latest/book/building-linux-kernel-driver
0
43
10
reposted by
jduck
BSides Canberra
8 months ago
Our Call for Presentations & Events is now open! Got cool research, a fresh exploit, or a unique cybersec insight? Submit your talk & be part of Australia’s biggest hacker con!
cfp.bsidescbr.com.au/bsides-canbe...
loading . . .
BSides Canberra 2025
Schedule, talks and talk submissions for BSides Canberra 2025
https://cfp.bsidescbr.com.au/bsides-canberra-2025/cfp
0
2
3
reposted by
jduck
Steve Klabnik
8 months ago
github.com/ariel-os/ari...
/via
@mattkeeter.com
#rustlang
loading . . .
GitHub - ariel-os/ariel-os: Ariel OS is a library operating system for secure, memory-safe, low-power Internet of Things, written in Rust
Ariel OS is a library operating system for secure, memory-safe, low-power Internet of Things, written in Rust - ariel-os/ariel-os
https://github.com/ariel-os/ariel-os
1
45
4
reposted by
jduck
Phrack Zine
8 months ago
Don't forget, the CFP for the 40th anniversary issue of Phrack is open until June 15th 2025. You can be someone's favorite article in the future!!
bsky.app/profile/phra...
add a skeleton here at some point
0
7
10
reposted by
jduck
stacksmashing
8 months ago
Having some fun with EM measurements today - side-channels are awesome!
loading . . .
1
41
6
reposted by
jduck
Paged Out!
8 months ago
Paged Out! #6 has arrived! And it's jam-packed with content! You can download it here:
pagedout.institute?page=issues....
0
23
30
reposted by
jduck
AHA!
8 months ago
Tonight. AHA 0xDE. If it is your first time attending, you will give an “intro talk”. This is an opportunity to share about yourself and allow us to get to know you. This is an important part of the new attendee process. Please take it seriously. If you’ve given an intro talk before, but have […]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@AustinHackers/114236374771898206
0
2
2
Happy to share my slides from BOOTSTRAP25. Unfortunately the bug discussed is still not patched in Linux 6.14.0 despite it being reported explicitly. Slides are in markdown but there's a PDF in "releases" too
github.com/jduck/bs25-s...
loading . . .
GitHub - jduck/bs25-slides: Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25
Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25 - jduck/bs25-slides
https://github.com/jduck/bs25-slides
8 months ago
1
14
7
reposted by
jduck
Andrew Case
8 months ago
The sedexp Linux malware was disclosed in late 2024. In my talk at
@kernelcon.bsky.social
, I will present my own deep dive of the malware, including many parts that have not been made public, such as loading of a memory-only rootkit. Be sure to attend for a teardown with
@volatilityfoundation.org
3!
0
12
7
Has anyone else seen
m.imdb.com/title/tt0218...
? Eerie
loading . . .
Antitrust (2001) ⭐ 6.1 | Action, Crime, Drama
1h 48m | PG-13
https://m.imdb.com/title/tt0218817/
9 months ago
1
2
0
Last week I attended Vector35
@re-verse.io
RE//verse conference and it was great! Excellent food, high signal to noise (RE/VR), and great people. I scored some amazing schwag including a SIM transposer and a
@binaryninja.bsky.social
hacky sack! w00t!
9 months ago
0
11
0
reposted by
jduck
Andrew Case
9 months ago
On March 29th, I will be speaking at
@bsidessd.bsky.social
on Volatility 3, including all its new features and plugins. Be sure to attend to catch a sneak peak at the new framework before the major release later this Spring!
www.bsidessd.org
#DFIR
#infosec
0
8
8
reposted by
jduck
Aleks
9 months ago
Digital vs film X-ray . Film offers higher resolution and better dynamic range with the same settings, but slightly longer exposure time (and more tedious image acquisition). Comes in handy when it comes to tiny electronics. Images of an Abbott Lingo continuous glucose monitor.
0
2
1
reposted by
jduck
9 months ago
BlackHoodie will be back at
@ringzer0.bsky.social
Bootstrap conference in Austin, TX 🤠 On Friday March 21st I'll be teaching Compiler Internals for Security Engineers, a class for women by women, and it's free. Register here
blackhoodie.re/Ringzer0_Boo...
loading . . .
Blackhoodie at Ringzer0 Bootstrap 2025
Compiler Internals for Security Engineers
https://blackhoodie.re/Ringzer0_Bootstrap_2025/
0
7
12
reposted by
jduck
Tweede golf
9 months ago
Tamme is giving a talk at Embedded World 2025! He shows how Rust’s type system and package manager can help to improve development speed and code quality. Also visit us at our booth, or book a time slot for a private chat:
https://buff.ly/4308AWE
@diondokter.nl
#ew25
#embeddedworld
#rustlang
0
8
3
reposted by
jduck
Gábor Nyéki
9 months ago
Greg KH is a voice of reason downthread:
lore.kernel.org/rust-for-lin...
loading . . .
Re: Rust kernel policy - Greg KH
https://lore.kernel.org/rust-for-linux/2025021954-flaccid-pucker-f7d9@gregkh/
3
92
14
I'm giving a talk at BOOTSTRAP25 in Austin! Hope to see y'all there!
ringzer0.training/bootstrap25-...
loading . . .
TALK: Musing from Decades of Linux Kernel Security Research // Joshua J. Drake
The Linux Kernel powers billions of devices across industries, making it critical infrastructure. But is it secure? Josh explores this by comparing its security investments to a typical SDLC, sharing ...
https://ringzer0.training/bootstrap25-talk-decades-of-linux-kernel-security/
9 months ago
0
11
4
reposted by
jduck
James Munns
9 months ago
It is EXTREMELY cool to me that: * Use of Rust on Embedded platforms is such a high percentage of the ecosystem (16.8% bare metal, 12.9% with an OS) * The usage is increasing year over year Check out the survey results!
blog.rust-lang.org/2025/02/13/2...
2
53
7
NanoKVM is sketchy.
youtu.be/plJGZQ35Q6I
loading . . .
NanoKVM: The S stands for Security
YouTube video by apalrd's adventures
https://youtu.be/plJGZQ35Q6I?si=vo45G140C4yMarOA
10 months ago
0
3
0
First episode is up!
youtu.be/7IHKRzGQeog
via
@rkl.bsky.social
loading . . .
Episode 1: Digital Jesus aka Matt Harrigan
YouTube video by Where Warlocks Stay Up Late
https://youtu.be/7IHKRzGQeog
10 months ago
0
2
1
reposted by
jduck
James Munns
10 months ago
I'm trying to think of a good way to flex Poststation as a demo for the embedded world booth. Does anyone have ideas of fun, interactive, and maybe mind bending things to have 8-16 independent MCUs do? I plan to fit it all into a eurorack case, as individual cards/modules.
2
3
1
reposted by
jduck
Julius Gustavsson
10 months ago
I did the podcast thing! It was great fun chatting with Matthias Endler on his “Rust in Production” podcast. We talked about our little Rust based ECU at Volvo Cars and how it came about. Check it out:
corrode.dev/podcast/s03e...
loading . . .
Volvo with Julius Gustavsson - Rust in Production Podcast | corrode Rust Consulting
The car industry is not known for its rapid adoption of new technologies. Therefore, it’s even more exciting to see a company like Volvo Cars embracing Rust for core components of their software stack...
https://corrode.dev/podcast/s03e08-volvo/
2
44
11
reposted by
jduck
Xeno Kovah
10 months ago
I’ve published CLUES (Custom Lightweight UUID Exchange Schema) and my current data about Bluetooth custom UUIDs to its own repository so that it can easily be incorporated as a git submodule in other research projects.
https://github.com/darkmentorllc/CLUES_Schema
loading . . .
GitHub - darkmentorllc/CLUES_Schema: Custom Lightweight UUID Exchange Schema (CLUES!)
Custom Lightweight UUID Exchange Schema (CLUES!). Contribute to darkmentorllc/CLUES_Schema development by creating an account on GitHub.
https://github.com/darkmentorllc/CLUES_Schema
0
1
1
reposted by
jduck
Xeno Kovah
10 months ago
I’ve published BTIDES (BlueTooth Information Data Exchange Schema) to its own repository so that it can easily be incorporated as a git submodule in other research projects. I have started using this for crowdsourced BT info sharing.
https://github.com/darkmentorllc/BTIDES_Schema
loading . . .
GitHub - darkmentorllc/BTIDES_Schema: BlueTooth Information Data Exchange Schema (BTIDES!)
BlueTooth Information Data Exchange Schema (BTIDES!) - darkmentorllc/BTIDES_Schema
https://github.com/darkmentorllc/BTIDES_Schema
0
0
1
Worst Fit by
@orange.tw
. Nasty stuff.
blog.orange.tw/posts/2025-0...
loading . . .
WorstFit: Unveiling Hidden Transformers in Windows ANSI!
📌 This is a cross-post from DEVCORE. The research was first published at Black Hat Europe 2024. Personally, I would like to thank splitline, the co-author of this research & article, whose help
https://blog.orange.tw/posts/2025-01-worstfit-unveiling-hidden-transformers-in-windows-ansi/
10 months ago
0
3
2
reposted by
jduck
The Rusty Bits
11 months ago
In this one we learn about using embassy to do embedded development with async Rust:
youtu.be/pDd5mXBF4tY
loading . . .
Intro to Embassy : embedded development with async Rust
YouTube video by The Rusty Bits
https://youtu.be/pDd5mXBF4tY
1
42
18
@thejpster.org.uk
You don't follow so I can't message but I hear the PR is coming next week
11 months ago
0
0
0
reposted by
jduck
Łukasz
11 months ago
If you haven't seen the Honey tech drama you absolutely have to, it's awesome!
youtu.be/vc4yL3YTwWk
loading . . .
Exposing the Honey Influencer Scam
YouTube video by MegaLag
https://youtu.be/vc4yL3YTwWk?si=OJct2r2Q3hs820Eo
2
20
4
Why do vendors claim reliable and secure and then have vulns like this?? Let me guess, ping again??
www.moxa.com/en/support/p...
loading . . .
Privilege Escalation and OS Command Injection Vulnerabilities
https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo
11 months ago
3
2
1
reposted by
jduck
Jonathan Pallant
11 months ago
Why is there no tech/hacker news coverage on Aedan Cullen‘s amazing RP2350 OTP glitch work? It’s weird. Here’s the GitHub:
github.com/aedancullen/...
loading . . .
GitHub - aedancullen/hacking-the-rp2350: Resources from my talk "Hacking the RP2350" at 38C3
Resources from my talk "Hacking the RP2350" at 38C3 - aedancullen/hacking-the-rp2350
https://github.com/aedancullen/hacking-the-rp2350
4
25
7
Oh!
@raspberrypi.com
RP2350 gotcha detailed at CCC. Does he win the prize??
events.ccc.de/congress/202...
loading . . .
38c3: Hacking the RP2350
The RP2350 security architecture involves several interconnected mechanisms which together provide authentication of code running on the chip, protected one-time-programmable storage, fine-grained con...
https://events.ccc.de/congress/2024/hub/en/event/hacking-the-rp2350/
11 months ago
0
4
1
Today I used a vinyl sticker from a conference in the place of heatshrink or electrical tape. Gotta do what you gotta do. Can't have this stuff shorting out!
11 months ago
0
3
0
I just disabled Android "Quick phrases" for my alarm clock app after realizing it's causing alarms to be ineffective. Who came up with this feature??? Why is it on by default?? Ensh**tification much?? Is there a class action suit I can join??
11 months ago
0
1
0
reposted by
jduck
Björkus "No time_t to Die" Dorkus
about 1 year ago
📢 It's time for you to MAKE YOUR VOICE HEARD 🗣️ ... ... In the C Survey for the Name of a new Operator!! This one, being something a LOT of you are familiar with! Read up, let us know, and SPREAD THE WORD:
thephd.dev/the-big-arra...
loading . . .
The Big Array Size Survey for C
New in C2y is an operator that does something people have been asking us for, for decades:
https://thephd.dev/the-big-array-size-survey-for-c
7
63
28
reposted by
jduck
Andy Greenberg
11 months ago
Digital license plates, legal to buy in some states and drive with nationwide, can be jailbroken. Hackers can install new firmware in minutes, then change plate numbers via a Bluetooth app to evade surveillance, tolls and tickets—or make someone else pay.
www.wired.com/story/digita...
loading . . .
Hackers Can Jailbreak Digital License Plates to Make Others Pay Their Tolls and Tickets
Digital license plates sold by Reviver, already legal to buy in some states and drive with nationwide, can be hacked by their owners to evade traffic regulations or even law enforcement surveillance.
https://www.wired.com/story/digital-license-plate-jailbreak-hack/
3
87
56
I'm looking forward to that conference badge with CHERI architecture... When is it coming? Hehe
11 months ago
0
2
0
reposted by
jduck
Mike Bell
12 months ago
Picking up from last week's thread on overclocking the
#RP2350
, I'm going to be pushing this Pico 2 further tonight. To start with, I'm doing a run of tests at 576MHz and 1.7V, to see how much difference the cooling has made.
add a skeleton here at some point
3
54
9
If you're looking for a good time programming, I recommend
#adventofcode
Day 6. Part 2 took me 4 tries to get a correct and performant solution.
12 months ago
0
11
0
reposted by
jduck
BSides Canberra
12 months ago
Boot security in the MCU, Daniel & Zoltan Madarassy - BSides Canberra 2024
youtu.be/LXdSVcvhJuI?...
#BSidesCbr2024
loading . . .
Boot security in the MCU, Daniel & Zoltan Madarassy - BSides Canberra 2024
YouTube video by BSides Canberra
https://youtu.be/LXdSVcvhJuI?si=hk2ddjUXHjQWujm3
0
6
7
Is this expected behavior in Go?? I'm seeing the original array get modified by just creating slices from it.
pastecry.pt/MMo4dp#Uk_Ha...
Output:
pastecry.pt/Y1eZuS#Uf7Ge...
#AdventOfCode
loading . . .
PasteCry.pt: A secure pasting solution offering client-side encryption.
Pastecry.pt provides a pasting solution to allow users to paste content securely. We provide a client-side encryption and never handle the un-encrypted data or keys outside of your machine assuring th...
https://pastecry.pt/MMo4dp#Uk_Han4Dua4At1Us8At7En6Eh
12 months ago
1
1
0
reposted by
jduck
Seth Abramson
12 months ago
1377
38793
15163
reposted by
jduck
Catalin Cimpanu
12 months ago
Positive Technologies has developed a new attack that exploits the SD Express standard to gain access to a device's memory through its SD card reader The DaMAgeCard attack exploits the fact that the new SD Express standard can operate in both SDIO and NVMe
swarm.ptsecurity.com/new-dog-old-...
4
59
28
reposted by
jduck
Caitlin Condon
12 months ago
Pretty dope whitepaper from Rapid7's
@stephenfewer.bsky.social
on 5 new vulnerabilities he chained to achieve unauthenticated RCE on Lorex 2K Indoor Wi-Fi security cameras. Whitepaper:
www.rapid7.com/globalassets...
Exploit:
github.com/sfewer-r7/Lo...
loading . . .
https://www.rapid7.com/globalassets/_pdfs/research/pwn2own-iot-2024-lorex-2k-indoor-wi-fi-security-camera-research.pdf
0
5
2
Load more
feeds!
log in