Email or username:

Password:

Forgot your password?
5 posts total
Catalin Cimpanu

Minecraft RANDAR exploit lets you find the in-game location of any player by looking at how pieces of a broken block fall

Write-up: github.com/spawnmason/randar-e

Video: youtube.com/watch?v=maMpMOnIJD

Show previous comments
Armando

@campuscodi this reminds me of tea leaves reading or chicken bones tossing. Really scary actually.

🌱 Ligniform :donor:​

@campuscodi 2B2T back at it again for helping people find exploits I see

Catalin Cimpanu

Just a reminder to everyone to never use Chrome for anything than downloading another browser.

Show previous comments
Shannon Skinner (she/her)

@campuscodi
I have switched to Firefox/Duck Duck Go combo for search and browsing, but I get overwhelmed when attempting to find replacements for Gmail/Calendar/Cloud storage combo.

I want to start transitioning away from the Google ecosystem, but it's honestly a huge hurdle.

Recommendations accepted.

Eric Lynema

@campuscodi
What is the general browser landscape look like... Firefox works so far so good. Is there another good option?

Catalin Cimpanu

A team of security researchers has discovered a vulnerability in Echo, an anti-cheat and cheater detection software advertised to gaming companies.

The vulnerability (named EchOh-No) resides in the tool's kernel driver and can be exploited by attackers to gain SYSTEM privileges.

The research team says they tried to disclose the vulnerability to the Echo team, but they were mocked and banned from their Discord channel.

Write-up: ioctl.fail/echo-ac-writeup/

PoC: github.com/kite03/echoac-poc

A team of security researchers has discovered a vulnerability in Echo, an anti-cheat and cheater detection software advertised to gaming companies.

The vulnerability (named EchOh-No) resides in the tool's kernel driver and can be exploited by attackers to gain SYSTEM privileges.

The research team says they tried to disclose the vulnerability to the Echo team, but they were mocked and banned from their Discord channel.

Show previous comments
DELETED

@campuscodi I think the response to the bs from the devs and the company was appropriate. πŸ˜‚πŸ˜‚πŸ˜‚

Tim Panton

@campuscodi @mcfly

β€˜One thing to note is that the driver does not have a "write" function, but you can simply flip the to and from address parameters to "read" your data buffer into another program just fine.’ Oh good grief.

Chris

@campuscodi I loved passing the blame to Microsoft 🀣

Catalin Cimpanu

Twitter is shadow-blocking tweets with Substack links.

You can tweet links but nobody can interact with them, most likely to prevent amplifying content.

Translation: Some reporter is probably publishing something bad about Twitter or Musk in the next few hours or days.

Catalin Cimpanu

I also see Twitter removed the option to self-revoke my "Verified" badge.

This means all those bot networks, right-wingers nutjobs, and Russian propaganda accounts that buy Twitter Blue are basically abusing the reputation that legitimate accounts built for the Verified badge to spew their non-sensical garbage.

Go Up