Dominic White's Avatar

Dominic White

@singe.bsky.social

Hacker at Orange Cyberdefense's SensePost Team https://hello.singe.za.net/

1,170 Followers  |  738 Following  |  561 Posts  |  Joined: 24.04.2023  |  2.1335

Latest posts by singe.bsky.social on Bluesky

Post image

Turns out you can communicate across containers via 63-bits of available space in a shared lock you acquire on /proc/self/ns/time that all processes have access to.

No networking required. The post has a demo of a chat app communicating across unprivileged containers.

h4x0r.org/funreliable/

12.11.2025 14:35 β€” πŸ‘ 218    πŸ” 56    πŸ’¬ 3    πŸ“Œ 10
Preview
BlackHoodie Interview: Building Community, Opportunity, & Confidence BlackHoodie founder Marion Marschalek shares her journey from early challenges to creating a global, inclusive reverse-engineering network.

I chatted with @hex-rays.bsky.social about how I found my place in the security industry, how @blackhoodie.bsky.social came to be, what our goals are and why community matters so much. hex-rays.com/blog/blackho...

18.11.2025 18:02 β€” πŸ‘ 7    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0
HOPE CONFERENCE BANNED BY ST. JOHN'S UNIVERSITY | 2600

HOPE has been banned from St. John's University. www.2600.com/content/hope...

18.11.2025 18:21 β€” πŸ‘ 87    πŸ” 64    πŸ’¬ 10    πŸ“Œ 18

The new kids use uv, so:

uv run raw.githubusercontent.com/sensepost/CV... !

18.11.2025 17:11 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
GitHub - sensepost/CVE-2025-64446: A scanner for the FortiNet vulnerability CVE-2025-64446 A scanner for the FortiNet vulnerability CVE-2025-64446 - sensepost/CVE-2025-64446

Here’s a free scanner for that FortiWeb CVE-2025-64446 I made for you.

18.11.2025 17:07 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
Be KVM, Do Fraud Hi Everyone! It’s me, your friendly Wav3.

The clever folks at Grumpy Goose Labs have published even more ways to identify unauthorized IP KVMs across your environment, with some great memes to boot! Be KVM, Do Fraud - blog.grumpygoose.io/be-kvm-do-fr...

15.11.2025 00:00 β€” πŸ‘ 8    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Post image

No Sleep Again

Full version: youtu.be/zK9HSXrvUMg

#γƒ‰γƒƒγƒˆη΅΅ #pixelart

05.08.2025 22:17 β€” πŸ‘ 617    πŸ” 162    πŸ’¬ 11    πŸ“Œ 2
Post image

ocean tides 🌊✨

#pixelart

10.11.2025 21:08 β€” πŸ‘ 1780    πŸ” 548    πŸ’¬ 15    πŸ“Œ 2
slide with a burning flag, the text "join a union", and a picture of parliament burning on guy fawkes day with the text "i got Radicalised at kawaiicon 2025"

slide with a burning flag, the text "join a union", and a picture of parliament burning on guy fawkes day with the text "i got Radicalised at kawaiicon 2025"

10.11.2025 11:08 β€” πŸ‘ 26    πŸ” 7    πŸ’¬ 1    πŸ“Œ 4
You can change the world

Plant trees so others can enjoy their shade for generations to come

So what you're able to make things easier for those around you so they can do the same for you.

The only real power is the friends we made along the way.

You can change the world Plant trees so others can enjoy their shade for generations to come So what you're able to make things easier for those around you so they can do the same for you. The only real power is the friends we made along the way.

@ellearmageddon.bsky.social wirh some words of inspiration at #kawaiicon

We can change the world, we do it in small steps, making each thing just a little better

06.11.2025 21:35 β€” πŸ‘ 15    πŸ” 6    πŸ’¬ 2    πŸ“Œ 0

NEW: Paragon spyware hit a key Italian campaign manager / political strategist.

Super concerning case & a reminder that Italy has a growing pile of unexplained infections with Paragon's Graphite spyware.

06.11.2025 21:03 β€” πŸ‘ 30    πŸ” 23    πŸ’¬ 1    πŸ“Œ 0
Post image

D3 viz of Symbiote malware call graph created with @binaryninja.bsky.social. Interactive, and makes pewpew sounds. The pewpew sounds are naturally the most important analysis feature, duh. Code going public soon.

07.11.2025 01:52 β€” πŸ‘ 13    πŸ” 3    πŸ’¬ 3    πŸ“Œ 0
Post image

Heeey, ncurses/terminfo has a small virtual machine! And if there's a VM, there are CTF challenges :)
hackarcana.com/public-exerc...
hackarcana.com/public-exerc...
(third one coming next week, will be a bit harder)

01.11.2025 16:15 β€” πŸ‘ 17    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0
shifttymike’s weaponised infrared remote no touch sensor trigger turned into a key fob. These were the speaker gifts.

shifttymike’s weaponised infrared remote no touch sensor trigger turned into a key fob. These were the speaker gifts.

T’was 0xC0N Jozi today. That makes number 9, finally beating ZaC0N’s run of 8 years. It’s such a special con because it’s small and full of passionate attendees - no corporate wage slaves there for a day off work, just a bunch of hackers new and old.

01.11.2025 15:59 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Three terminals stack on top of eachother. The top is running hub.pl on the host. The middle is running pool.pl on the β€œhacker” server. And the bottom shows a connection from the host through the hacked server to a target server over SOCKS.

Three terminals stack on top of eachother. The top is running hub.pl on the host. The middle is running pool.pl on the β€œhacker” server. And the bottom shows a connection from the host through the hacked server to a target server over SOCKS.

Just added SOCKS support to this reverse tunnelling tool github.com/singe/contun...

28.10.2025 14:58 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - singe/contun.pl: A concurrent listen:listen connect:connect tunnelling solution written in Perl A concurrent listen:listen connect:connect tunnelling solution written in Perl - singe/contun.pl

github.com/singe/contun.p… this was a fun nerd snipe - how do you build a listed:listen connect:connect reverse tunnel that can handle concurrent connections when you only have Perl.

27.10.2025 19:00 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
phone next to a speaker

phone next to a speaker

I just can't get over how this track is literally about when your phone's 2G GSM signals would interfere with speakers, and they even sample the interference sound repeatedly: www.youtube.com/watch?v=gpQS... (1/2)

25.10.2025 01:58 β€” πŸ‘ 9    πŸ” 2    πŸ’¬ 4    πŸ“Œ 0

codex is much better in my exp. Found the chat super frustrating in the past.

23.10.2025 05:24 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@vhata.net I didn’t tag you properly in the original.

19.10.2025 11:47 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Rediscovering some of those factoids has been amusing.

19.10.2025 11:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
A screenshot of the mobile view of GitHub looking at a private repo for the cabbage bot with 10 plugins in the plugins folder.

A screenshot of the mobile view of GitHub looking at a private repo for the cabbage bot with 10 plugins in the plugins folder.

I missed Spinach & was tired of writing hard code that LLMs struggled to help with. So I decided to recreate the functionality of Spinach in a discord world. And so Cabbage was born. Cabbage is private for now, but it’s been so cathartic writing something easy and fun. And vhata saved Spinach’s DB!

19.10.2025 11:29 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
GitHub - ibid/ibid: Ibid is a multi-protocol general purpose chat bot written in Python. Bugs tracked on launchpad. Ibid is a multi-protocol general purpose chat bot written in Python. Bugs tracked on launchpad. - ibid/ibid

Back in days of IRC my friend vhata maintained an ibid* bot called Spinach. Spinach had a ton of lore saved in its factoid database and was an essential part of our daily lives. From helping us with cricket scores to making major life choices with the choose plugin.

*

19.10.2025 11:26 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Root for Your Friends Discover the power of rooting for your friends and how it can amplify success for everyone involved.

Seriously, I love this post so much - Good weekend timeline cleanser: "Root for Your Friends Β· Joseph Thacker"

m.cje.io/3KYvnLt

18.10.2025 22:39 β€” πŸ‘ 6    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
Post-ex Weaponization: An Oral History This is "Post-ex Weaponization: An Oral History" by AFF-WG on Vimeo, the home for high quality videos and the people who love them.

Why plant a Tradecraft Garden?

April 2025, I talked to my camera about how tradecraft may go the route we saw vuln research go years ago, red teaming's retreat to self-protective secrecy, and the opportunity I see for a public tradecraft ecosystem. This starts @ 1:16:00

vimeo.com/1074106659#t...

14.10.2025 16:57 β€” πŸ‘ 10    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Preview
Considering the Bathroom Scale (Which Might be Fucked) by Genna Gardini | Amsterdam Review Read "Considering the Bathroom Scale (Which Might be Fucked)" by Genna Gardini

www.amsterdamreview.org/considering-... via @tashjoeza.bsky.social

11.10.2025 17:40 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Turgid with blood even.

11.10.2025 16:57 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Unsolicited tick pic

11.10.2025 11:49 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 2    πŸ“Œ 1

Rewatching this banger of a talk, that we’re now spoiled with two versions of; the original DEFCON 33 main stage talk, and the follow up RomHack 2025 talk with the PipeTap additions.

DEFCON https://youtube.com/watch?v=zSBf2CMKlBk
RomHack https://youtube.com/watch?v=_39UbCePFfw

11.10.2025 10:57 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Please support my ride I’m taking on the Brisbane to Gold Coast Cycle for Cancer to raise money for cancer research at Mater. Please support my ride by making a donation today. Thank you.

Tomorrow morning I am cycling 100km from Brisbane to the Gold Coast for cancer research πŸš΄β€β™€οΈβ€οΈ

If you’d like to sponsor me (even small donations are super appreciated): fundraise.mater.org.au/s/120023/179...

11.10.2025 10:29 β€” πŸ‘ 50    πŸ” 13    πŸ’¬ 7    πŸ“Œ 1

I think about this often.
What is a real world bad guy's level of effort for cracking?
How long do they spend?
How big is their cracker?
Do they have multiple crackers?
How do they distribute the load?

30.09.2025 14:18 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

@singe is following 20 prominent accounts