Today I got RDOFF (.rdf) files working in nasm 2.15. I wrote my own lib bc nasm didn't generate properly. Also patched the 32-bit loader in `rdx` with mmap tricks (shoutout ixi). An executable RDOFF has likely never run on a 64 bit system before today. Writeup soon! #BGGP6
ALT gdb executing the rdx binary with the global.rdf file as the argument, returning 6 and exiting
ALT screenshot of a terminal with the rdx binary running global.rdf checking the return value, a hex dump of the file, and the output of the generator script that built it
Then for bonus points just delete all the junk after the ? and wow, your link is normal again.
At the very least, all the tracking junk doesnt get auto rendered if you do the space before ? trick.
ALT Sim City 2000 Advisor NPC Dialogue quoting the tweet by @awscloud "More AI-generated code doesn't make your team faster. It might actually slow you down."
Link:
https://iokaravas.github.io/SierraDeathGenerator/#!/sc2k
Arbitrary code execution in objdump -g
We have a thing for finding bugs in bug finding tools. IDA Pro, Ghidra, Binja Sidekick, or radare2. You name it we hacked it. Our friends were saying we should try objdump. So here we go.
Blog post: blog.calif.io/p/oobdump-relo…
AI-generated PoC and writeup: github.com/califio/publicati…
This is how boomers did debugging :D, this shows loading the ring0 softice tool on windows 2000, setting some style options, then setting a system wide API breaking point and following a stack string decryption
yesterday @b1ack0wl nerd sniped me into this, it's been a lot of fun, but my god, it's not so easy to generalize instruction formats, since instructions randomly have little curve balls depending on the context
Twelfth LangSec IEEE Security & Privacy workshop announces its preliminary agenda langsec.org/spw26/abstracts.… . Join us on May 21 for two keynotes on formal methods reaching broad industry practice, a panel on AI & LangSec, and talks. Work-in-progress reports and more TBA soon.
When working with computers we frequently find these cool little tidbits/tricks/tips we could share. They are too small to make a full article, but they are likely the right size for Paged Out! magazine, where each article is just 1 page 😎
CFP deadline for Issue #9: 30th April