home > posts
  • July 16, 2023
    HD Moore
    @hdm

    This walkthrough of reverse engineering and then exploiting a RIGOL scope by @krive@fosstodon.org is beautiful, thanks for sharing! https://tortel.li/post/insecure-scope/

    ↪ reply
  • July 14, 2023
    HD Moore
    @hdm

    Introducing jswzl: In-depth JavaScript analysis for web security testers https://www.jswzl.io/post/introducing-jswzl-in-depth-js-analysis-for-web-security-testers

    Congratulations on the launch Charlie Eriksen!

    ↪ reply
  • July 14, 2023
    HD Moore
    @hdm

    >We used a Google Ads pre-registration campaign to get installs for our app. We paid for 16,171 conversions. We only received 1,371 installs.

    Not a great outcome:
    https://andreaskambanis.com/google-play-store-pre-registration-campaigns/

    ↪ reply
  • July 13, 2023
    HD Moore
    @hdm

    A neat information leak in browsers that support mDNS-based hostname resolution. The demo brute forces common names + device prefixes/suffixes, but this can be abused for a dozen other things (do you have a specific IoT device on your network? do you use Meraki? etc):
    https://fingerprint.com/blog/apple-macos-mdns-brute-force/

    ↪ reply
  • July 13, 2023
    HD Moore
    @hdm

    A great analysis of resident key challenges with UAF: https://fy.blackhats.net.au/blog/2023-02-02-how-hype-will-turn-your-security-key-into-junk/

    ↪ reply
  • June 16, 2023
    HD Moore
    @hdm

    PSA: If you are using AWS Aurora PostgreSQL 15.2 on aarch64 (r6g, etc) your servers may randomly abort with `PANIC: queueing for lock while waiting on another one`: https://github.com/postgres/postgres/blob/f4c00d138f6dea4c9d8af8ec280b7edc9b0a29e1/src/backend/storage/lmgr/lwlock.c#L1074

    ↪ reply
  • June 16, 2023
    HD Moore
    @hdm

    Google Domains is shutting down after selling the business to Squarespace... any great registrar recommendations? https://9to5google.com/2023/06/15/google-domains-squarespace/

    ↪ reply
  • June 14, 2023
    HD Moore
    @hdm

    Congrats to the Gandi investors on their sale. Thanks for posting such a comprehensive list of price increases too! https://www.gandi.net/static/documents/2023-july-usd-renew-price-increase.pdf

    ↪ reply
  • June 13, 2023
    HD Moore
    @hdm

    Hackers can steal cryptographic keys by video-recording power LEDs 60 feet away:
    https://arstechnica.com/information-technology/2023/06/hackers-can-steal-cryptographic-keys-by-video-recording-connected-power-leds-60-feet-away/

    I love these kinds of attacks. Via @dangoodin at @arstechnica

    ↪ reply
  • June 11, 2023
    HD Moore
    @hdm

    #reconmtl 

    This #reconmtl talk by Ang Cui looks epic: Ice Ice Baby: Coppin' RAM With DIY Cryo-Mechanical Robot https://cfp.recon.cx/2023/talk/HCJHBW/

    (coverage at https://www.theregister.com/2023/06/09/cold_boot_ram_theft/ by @thomasclaburn)

    ↪ reply
  • << View newer posts View older posts >>

Copyright 1998-2026 HD Moore