4Dgifts's Avatar

4Dgifts

@4dgifts.bsky.social

culprit %x%x%n%n

324 Followers  |  126 Following  |  201 Posts  |  Joined: 29.06.2023
Posts Following

Posts by 4Dgifts (@4dgifts.bsky.social)

Reflective loading of an unsigned Windows driver.
This may be useful for red teaming and game cheating, but also to reclaim ownership of your computering device.
Yay, you don't need a cloud services account to do it!

09.10.2025 16:30 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
RW physical memory pages with a side of LSTAR MSR overwrite? YOLO!

RW physical memory pages with a side of LSTAR MSR overwrite? YOLO!

BYOVD is a well-known technique commonly used by threat actors to kill EDR ๐Ÿ”ช
However, with the right primitives, you can do much more.
Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver.
๐Ÿ‘‡
blog.quarkslab.com/exploiting-l...

23.09.2025 17:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Microsoft says Azure affected after cables cut in the Red Sea | TechCrunch It's not clear who cut the cables or why.

It's not clear who cut the cables or why.

07.09.2025 15:24 โ€” ๐Ÿ‘ 35    ๐Ÿ” 12    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 5

Reverse engineering of the patch for a (remote?) code execution vuln recently fixed by Apple, allegedly used in attacks ITW.
They "improved bounds checking" at an infinite rate, from 0 to actually checking.
This is the kind of simple bug that a fuzzer would catch so it is puzzling that it wasn't.

05.09.2025 19:14 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

What kind of advise is "We don't know what is going on, disable your VPN server" ?
Also a 0day is not "a security bug that was discovered and exploited before the vendor could patch the issue".
0day is a vuln that is not publicly known.
A known vuln that the vendor did not care to patch isn't 0day.

05.08.2025 14:01 โ€” ๐Ÿ‘ 7    ๐Ÿ” 6    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

30+ years in cybersecurity and I still see these vendor-supported private 0day sharing clubs.
Vendors that tilt the patch and later demand fair play.
We have not learned anything from MAPP have we?

06.06.2025 17:38 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ˜Un equipo de la UBA se ubicรณ entre los 5 mejores (de mรกs de 100) en el mundial de โ€œsatรฉlites enlatadosโ€๐Ÿ‘‡en la final del proyecto CanSat, organizado por la Universidad Nacional de Mรฉxico, con un satรฉlite del tamaรฑo de una lata que ellos mismos diseรฑaron y fabricaron ๐Ÿ‘‡

28.05.2025 18:14 โ€” ๐Ÿ‘ 71    ๐Ÿ” 32    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 1

tambien acรก ๐Ÿ‘‹

28.05.2025 15:58 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

last I checked immigrant expenditures are not tax free either

28.05.2025 11:32 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

"(...) esa lรญnea de crรฉdito es extorsiva, y mientras la mantengan siempre China va a poder extorsionar"

En cambio, el crรฉdito que el FMI por recomendaciรณn de los Estados Unidos le otorga a la Argentina... ยกCaramba! ยกquรฉ coincidencia!

17.05.2025 15:26 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
La recomendaciรณn a Milei de un funcionario de Trump: โ€œMientras tenga el swap con China, Argentina no serรก libreโ€ Mauricio Claver-Carone, enviado especial de Estado Unidos para Amรฉrica Latina, fue entrevistado en exclusiva por Infobae

Estados Unidos en el rol del novio violento y golpeador recomendรกndole a la novia liberarse de las amigas que la bancan cada vez que la faja

www.infobae.com/economia/202...

17.05.2025 15:19 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

This is *significantly* better than Johnny Mnemonic and yet much less known.
Recommended!

10.05.2025 00:01 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
Motosierra sin fin: el Gobierno eliminรณ definitivamente el FISU y el Fondo Fiduciario para la Promociรณn Cientรญfica | Luego de subejecutarlos En una nueva muestra de su desprecio por las polรญticas pรบblicas, el Gobierno de Javier Milei eliminรณ dos fondos fiduciarios clave: uno destinado a la ciencia y tecnologรญa, y otro a la vivienda. Esta d...

OJO con esta nota.
El fondo fiduciario eliminado NO es el FONCYT, que no es un fondo fiduciario.
El eliminado es el FONDOTEC, creado por la Ley Nยฐ 23.877, de 1990.
El FONCYT se creรณ en 1996 con la @agenciaidiar

www.pagina12.com.ar/823318-motos...

06.05.2025 14:29 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Strange times: CISA employees this morning received a "workforce accountability survey" email requiring them to say whether they were on-site, teleworking, on leave, on travel, or no longer employed at CISA.

Then a few hours later, they got another email saying "no response is needed."

30.04.2025 17:52 โ€” ๐Ÿ‘ 38    ๐Ÿ” 13    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 1
A small bug in the signature verification of AOSP OTA packages A signature verification bypass in a function that verifies the integrity of ZIP archives in the AOSP framework

There is a small bug in the signature verification of OTA packages in the Android Open Source Framework.
Official builds doing normal double verification of packages are not vulnerable but OEMs and third party apps may be.
Jรฉrรฉmy Jourdois explains it here:
blog.quarkslab.com/aosp_ota_sig...

08.04.2025 17:51 โ€” ๐Ÿ‘ 5    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

PARA PARA PARA VOS ME ESTAS DICIENDO DE QUE PATRISSIA BULLREICH ES UNA ZURDA?

28.03.2025 16:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

beware of how this plays out..
as in "we cannot do it unless a backdoor is installed..." etc

27.03.2025 22:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Agrego que cerraron estaciones d ela lรญnea D durante 3 meses no de sabe para quรฉ carajos. La frecuencia de trenes sigue siendo una mierda, esta llenos todo el tiempo y cada dos por tres se quedan parados varios minutos en los tรบneles.
Solo hicieron boludeces cosmรฉticas

26.03.2025 12:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Pope Francis made a brief statement from the hospital balcony:

23.03.2025 13:44 โ€” ๐Ÿ‘ 8024    ๐Ÿ” 1128    ๐Ÿ’ฌ 73    ๐Ÿ“Œ 124
Post image

Saw this on the other site but I should comment here:
Can't remember his hacker handle but I think Pad & Gandalf of 8lgm were arrested the same day in 1991.
You may not know it but the entire infosec & software industries owe 8lgm immense gratitude for making vendors accountable for their vulns

17.03.2025 22:59 โ€” ๐Ÿ‘ 9    ๐Ÿ” 6    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

ZOMG

17.03.2025 20:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This is the new diplomacy?

17.03.2025 20:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
FCC Reaffirms Decision to Reject Starlink Application for Nearly $900 Million in Subsidies FCC reaffirmed WCB's prior decision to reject the long-form application of Starlink to receive public support through the RDOF program, based on the applicant's failure to meet the program requirement...

Es una saga que lleva aรฑos. Previamente le cancelaron un subsidio por casi $900M USD por no cumplir con los requerimientos tรฉcnicos prometidos
www.fcc.gov/document/fcc...

17.03.2025 20:26 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Excellent Zoolander reference by @wdormann.bsky.social in his video.

You know where to find us if you need help @msftsecresponse.bsky.social

๐ŸŒบ @lutasecurity.bsky.social ๐ŸŒบ

17.03.2025 20:12 โ€” ๐Ÿ‘ 20    ๐Ÿ” 7    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

le hicieron una bandera a Dani Osvaldo ?
๐Ÿ˜‚

17.03.2025 00:34 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

But not the swastitrunk?

12.03.2025 03:50 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

A deep dive into phishing
I guess there is a pun in there but child[0|1] have banned dad jokes.
sorry

11.03.2025 16:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Y ni hablar si Putin lo invitaba a tomar un tรฉ

09.03.2025 22:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0