Talented programmer

Joined July 2020
1 Photos and videos
Pinned Tweet
If you're interested about anti-cheat reverse engineering then please checkout my very detailed and rich article about EMACLAB Anti-cheat. This anti-cheat software is used in Counter-Strike 2 league called GamersClub, pretty popular in South America. github.com/crvvdev/emaclab-r…
4
18
59
5,578
How did Claude gone from: "Ok I will reverse engineer this 20 year old proprietary encrypted protocol for you" to "Sorry I cannot process your request because it violates the..." We enriched your models capabilities for free and now you gatekeep the most important features...
46
63
1,678
55,672
Agora esta explicado o motivo de eu não estar conseguindo mecher no github direito ontem... que palhaçada
Confirmo que há todos os indícios típicos de bloqueio nacional determinado pela Anatel no dia de hoje para api.github.com. Nas quartas-feiras, geralmente em dias de jogos de futebol, a agência de reúne com as maiores operadoras do país e determina o bloqueio de endereços utilizados pelos TV boxes. A lista de endereços bloqueados é mantido em sigilo pela agência, algo que tenho criticado em artigos, entrevistas e palestras. Os indícios são: 1) O fato de ocorrer numa quarta-feira e pelo relato desse internauta que me acionou, ontem o problema não ocorria. 2) O fato do IP 4.228.31.149 para qual aponta o FQDN api.github.com estar bloqueado somente na Claro, Vivo, Nio, Algar e TIM e *NÃO* em ISPs regionais conforme posso testar com o comando globalping. 3) O fato de outros endereços IP contidos no mesmo bloco /24 serem normalmente alcançáveis, o que exclui problemas de roteamento já que todos os IPs entre 4.228.31.1 e 4.228.31.255 necessariamente pertencem a mesma rota (vide exemplo 4.228.31.3). Recomendo que os afetados entrem em contato com seus provedores mostrando evidências coletadas a partir de sua casa ou empresa e exijam uma resposta do porquê não havia rota para 4.228.31.149 na noite de 10/06/26 enquanto para 4.228.31.3 há. Nesse thread a seguir, colocarei algumas informações úteis sobre o problema.
1
135
Has gotten so crazy that anticheats now needs a motherboard database to force you update to up to date pre-boot DMA firmware versions, lol
The UEFI firmware on motherboards from ASUS, Gigabyte, MSI, and ASRock tells the operating system the IOMMU is ready for DMA protection during early boot. In reality, the IOMMU initialization fails silently on a wide range of these motherboards. A malicious PCIe device with physical access gets unfiltered memory access before the OS loads any defenses. The firmware asserted the lock was engaged.
1
3
67
7,807
I have been telling everyone that the real plan of big hardware companies is forcing users away from open source solutions and real control over YOUR hardware.
Replying to @Sosowski
I can see the seething in the comments. The issue with ARM platforms is they lack an equivalent of BOIS/UEFI. The real magic of the PC is the BIOS. That allows for a far more open platform than ARM or even RISC-V. If you care about open computing, it's x86 all the way
106
mesmo eu sendo da area de tecnologia e desenvolvimento eu não entendi bulhufas do que está sendo discutido aqui
Tô num server de ML no Discord Decidiram usar MÉTODO DE NEWTON numa rede neural, a justificativa dos caras foi: “Vai convergir em menos épocas” kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk demorou 7 minutos para a rede treinar usando o dataset WEB10K
1
108
Did you literally know that Windows has something called Warbird that literally executes encrypted shellcode on your computer? And that all of its functionality is not really known, we just know that exists and is actively running in everyones computers?
32
54
960
88,133
Did you also know that this is done using syscalls? Which means it gets executed at kernel level, in a very very obfuscated/virtualized proprietary driver!?
2
2
110
10,208
Windows cannot be considered safe to begin with, and it surely does not protects your privacy at all.
2
3
115
10,176
About the recent Vanguard drama all I can say is that FACEIT AC did it first for at least 1 year now and they're far ahead of the competition; they also closed a hole for SMM/HV abuse that vgk didn't realize or isn't capable of dealing with right now.
1
4
1,001
Ricardo Carvalho retweeted
Replying to @vxunderground
Kernel Anti-cheat? NO WAY! The tens of other drivers on my system surely would never be vulnerable and I can trust hardware companies to write competent drivers instead of le spooky anticheat
4
8
89
3,035
I forked ReClass .NET and revamped the interface and also refactored the native and managed plugin system to be more flexible. I then created a backend plugin that hooks native core functionality to use leechcore or any r/w primitive really. Any more improvement ideas?
1
1
10
1,058
Added Scylla support, no more broken/partial dumps; My plugin (called Xywd) also provides remote DLL injection and driver manual mapping, everything is self-contained, the only requirement is r/w primitives. This is enough for me to reverse engineer any software with ease.
211
Not true, people didn't really used git or version control properly back then
Imagine if codex existed in 2007 (last one)
1
160
10 years ago games rarely used any kind of protection or virtualization/obfuscation but now almost every AAA comes with obfuscation of some kind, built in anti-tamper that prevents easy memory access, and etc. Yea, it sure is a lot harder now.
Apr 15
Young people just getting into vulnerability research and exploit development today days have it soooo much harder than those who started even as little as 10 years ago. Binary exploitation is at least an order of magnitude more difficult today than in 2015. Especially if you have zero experiencing doing it. For those who are experienced, the difficulty levels have risen *somewhat* gradually. Though many still haven't been able to keep up. And even among those who could keep up, there are many who have just found it to be so hard as to no longer be fun, and have moved on to other things. Some have posited that binary exploitation has become so hard that the future will be logical/functionality abuse. And while this category of bugs certainly shows a quite a bit of promise in second order exploitation components like LPE, TCC bypass, etc—memory corruption still reigns supreme when it comes to initial access. Memory corruption that is actually exploitable in a reliable, near-instant and deterministic manner—versus random non-useful null ptr dereferences in browsers that require spraying whatevers to get 60% reliability—has gotten so incredibly tough (at least in the most contested systems) that there may be as few as 400 or 500 people in the world today that can actually pull it off repeatably. Seriously, it's probably 400 or 500 people (just my best guess) And that's *with* the help of AI, custom/expensive/gov-only tooling, insider insights/experience and any other resources imaginable. So if you don't make it into the elite of binary exploitation, don't beat yourself up. It's a group of people roughly as rare as NBA players. However, unlike the NBA, it's not obvious who is 7 feet tall with a 40 inch vertical, and who isn't. So it doesn't hurt to try—as long as you're having fun.
2
6
583
CSGO players begged for Source 2 since 2015 and when they finally got it they started flaming the game devs saying Source was better lmao
Apr 14
Three years ago, when CS2 was just a dream, this man asked for only three things: - 128-tick Servers - Source 2 Engine - Better matchmaking Do we actually have any of it? 🤔
1
295
Any mastermind can explain to me why KTHREAD->PreviousMode doesn't reset to UserMode on user syscall invoke?
276
I find it very annoying that LLMs other than Claude simply refuse to help when you ask about malware/anti-cheat related stuff because it is "unethical"!? Very sensitive topic I know, but that is my full time job brother...
1
2
348
I still don't understand why devs don't just block admin endpoints with proxy!? Setup a proxy in a random compute engine Protect the endpoints on edge or nginx Profit?? There's probably a way to spoof IP address but the attacker must know first
> be kippu > some startup app or something > idfk > goes live > people sign up > realize it's vibe coded > nerds get silly > nerds do http get on api endpoint > dumps entire database *image censored, although it's all over xitter
1
343
This is full stack programming 101, vibe coding is acceptable only if you know at least the basics
106