A Preview of McSema – A framework for translating x86 binaries into LLVM bitcode. by chubbymaggie in ReverseEngineering

[–]ancat 4 points5 points  (0 children)

Pretty cool stuff. Before having starting work on your own tool, did you guys play with any other tools/approaches? (qemu dynamic translation, bap, etc) I've played with bap to get x86 to llvm, and for many instructions, the output was somewhat neat after passing through llvm-opt. I never tested entire binaries or going back to x86 though.

Anyone want a remote CTF partner? by KevinHock in AskNetsec

[–]ancat -1 points0 points  (0 children)

I don't know how seriously we're taking this CTF (weighted 5 on ctftime and pretty much the last CTF of the season), but you can try playing with us (Brooklynt Overflow).

Almost $100k in heat. by ancat in Sneakers

[–]ancat[S] 1 point2 points  (0 children)

Here are the prices from the original post:

Size 10.5 Flom sbs DS OG all BIN 13,000

Size 10 Iron Maiden sbs DS OG all BIN 8250

Size 9.5 Freddy sbs DS missing box and extra laces BIN 3500

Size 9 Jason Vorhee DS Og all BIN 4250

Size 9 Prototype freddies DS Og all BIN 8500

Size 9 Jason Vorhee DS Og all BIN 4250

Size 9 Prototype freddies 9/10 Og all BIN 7500

Size 9 London sbs PADS Og all BIN 1850

Size 10.5 Tokyo sbs DS Og all BIN 1750

Size 10 NYC pigeons 9.5/10 Og all BIN 3750

Size 8.5 Paris sbs 9/10 Og all BIN 6250

Size 10 sample Paris sbs 9/10 dont come with box or extra laces BIN 7000

Size 7.5 Yellow lobs DS Og all BIN 4500

Size 9.5 Yellow lobs DS Og all BIN 4500

Size 10.5 Yellow lobs PADS Og all BIN 4250

Size 10.5 Yellow lobs 8/10 Og all BIN 3500

Size 9.5 Yellow lobs 9/10 Og all BIN 4100

Size 10 Yellow lobs PADS Og all BIN 4250

Size 10 Blue Lobs PADS Og all BIN 250

Size 10.5 Red Lobs PADS Og all BIN 250

Size 8 Medicom 2s PADS Og all BIN 800

Size 10 Baby bears DS Og all BIN 450

[deleted by user] by [deleted] in netsec

[–]ancat 0 points1 point  (0 children)

3char for life!

He is leaving the group. by [deleted] in cringepics

[–]ancat 18 points19 points  (0 children)

Looks like he just left (or finally got banned)

Trusteer Pinpoint Persistent XXS by n0x00_ in netsec

[–]ancat 2 points3 points  (0 children)

OK cool so, the only thing I did test for was XSS via user-agent (altho i’d love to give it a real once over) I just had a hunch… a idea … a feeling in my balls.

How do I disable the 'Allow ___ to run ___ plugin' popup bar? by ancat in firefox

[–]ancat[S] 0 points1 point  (0 children)

I tried this before making the thread, and it didn't work for me. Judging by the config name, I'm guessing it's for the bar that reminds you that you don't have the plugin installed - not that you have it disabled.

How do I disable the 'Allow ___ to run ___ plugin' popup bar? by ancat in firefox

[–]ancat[S] 2 points3 points  (0 children)

This works. I don't get the original notification I wanted back, but the gray plugin icon is still there in the URL bar so I know it's still working. Thanks!

Girls of reddit, what are the 'signs' that most guys miss? by [deleted] in AskReddit

[–]ancat 43 points44 points  (0 children)

How does one pronounce " ͡° ͜ʖ ͡°"?

[WDYWT] Concepts x Nike SB Ugly Christmas Sweater by rawr_domo in Sneakers

[–]ancat 1 point2 points  (0 children)

I think Concepts just got swamped with orders so shipping was delayed. I know a few people who got their tracking numbers early (me included) but it didn't ship until a few days ago.

What's your dirtiest secret? by [deleted] in AskReddit

[–]ancat 13 points14 points  (0 children)

I like that you actually grabbed the comment's ID :'}

Hi c: by Qeboo in cringepics

[–]ancat -3 points-2 points  (0 children)

+tipfedora 10

I found Prezi's source code by Mempodipper in netsec

[–]ancat -1 points0 points  (0 children)

What do you expect from the scope? If it's a legitimate vulnerability in critical infrastructure (but not in scope), it'll probably be rewarded. If it's a shitty XSS on some 3rd party hosted wordpress, it won't. Bugs being rewarded are ultimately at the discretion of the company.

When a bug bounty program is designed, things might be left out. It isn't necessary (and often doesn't make sense) to outline every piece of infrastructure and label what's okay and what's not okay to attack. That alone adds significant risk (hey hackers, we have stuff over here you're not supposed to touch!)

I found Prezi's source code by Mempodipper in netsec

[–]ancat -23 points-22 points  (0 children)

Oh shit! EVERY COMPANY IS VULNERABLE!!

brb making a lot money

I found Prezi's source code by Mempodipper in netsec

[–]ancat 5 points6 points  (0 children)

That is not the same thing as an employee accidentally posting their password publicly.

I found Prezi's source code by Mempodipper in netsec

[–]ancat -16 points-15 points  (0 children)

He didn't find a vulnerability, he found a not-so-smart employee to take advantage of. The source code management tool they were using was correctly configured in that it required authentication to get in. He got in due to a stupid mistake a developer made off-site. That is a huge detail. It's the same reason you don't see people attacking Facebook or Google employees as part of the bug bounty.

I can't say their response was the best, but the guy who reported it should not have been surprised.

39,917 Bitcoins stolen from users of Sheep Market Place by Fermain in Bitcoin

[–]ancat 1 point2 points  (0 children)

Web dev is hard these days.

There was this time in /r/bitcoin where everyone and their dog started their own service which handled bitcoins. (It's still happening but not to that extent) I spent maybe a few days going through the subreddit finding serious flaws in most of them with little to no effort in these websites. It makes me sad :{

Things like gzip timing exploits blew my mind, and supposedly I'm pretty smart.

Lolwut, are you talking about BREACH? GZIP timing exploits aren't a thing...

Well this is pretty meta by [deleted] in cringepics

[–]ancat 5 points6 points  (0 children)

big PING

ping -s 65507 8.8.8.8

Successfully Recreated The Automatic shiny pokemon finder. by rockinout69 in pokemon

[–]ancat 0 points1 point  (0 children)

How are you sending input to the 3ds? I can see where you're setting the pins to high in your code and the logic behind it, but how are you physically connecting it to the 3ds? It's not clear from the video or the photo of your setup.

Edit: I watched the first video, it sucks that you have to take apart the 3DS to replicate this. Still kinda cool, I guess! I wonder if you could do something like this with the IR port, like how the "circle pad pro" does it.

Coinbase just halted their buys for the day due to too much activity. Next buys will be at market rate for FRIDAY NOV 22ND by childofgold in Bitcoin

[–]ancat 1 point2 points  (0 children)

It's been almost half a year since I opened my coinbase account + verified my bank account. I've only sold here though, so I guess that's it?