Forwarded from Hacker News
Alexander Popov
Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel
Some memory corruption bugs are much harder to exploit than others. They can involve race conditions, crash the system, and impose limitations that make a researcher's life difficult. Working with such fragile vulnerabilities demands significant time and…
Forwarded from Hacker News
Forwarded from Hacker News
GitHub
GitHub - Tencent-Hunyuan/HunyuanWorld-Voyager: Voyager is an interactive RGBD video generation model conditioned on camera input…
Voyager is an interactive RGBD video generation model conditioned on camera input, and supports real-time 3D reconstruction. - Tencent-Hunyuan/HunyuanWorld-Voyager
Forwarded from Hacker News
actu.epfl.ch
Apertus: a fully open, transparent, multilingual language model
EPFL, ETH Zurich and the Swiss National Supercomputing Centre (CSCS) released Apertus today, Switzerland’s first large-scale, open, multilingual language model — a milestone in generative AI for transparency and diversity.
Forwarded from cKure
■■□□□ News circulating online.
Cloudflare just blocked the largest DDOS attack of all time at 11.5 Tbps. The attack was a UDP flood that came from Google Cloud.
Cloudflare just blocked the largest DDOS attack of all time at 11.5 Tbps. The attack was a UDP flood that came from Google Cloud.
Russia To Mandate Preinstallation Of State Messaging App Max And Rustore On All Smartphones And Tablets
https://github.com/KARENKING112/max-deep-analysis-of-the-messenger
Here's a deep analysis of it.
https://github.com/KARENKING112/max-deep-analysis-of-the-messenger
Here's a deep analysis of it.
General report on the analysis of the application "Max"
General information about the "Max" app: The Max application is positioned as a fast and easy messenger for communication. High-quality calls, animated stickers, sending files up to 4 GB, as well as the presence of chatbots and mini-applications are declared. It is distributed on various platforms: Android (via Google Play, RuStore, AppGallery, iOS (via the App Store) and desktop versions. The application package - ru.oneme.app(According to Android Manifest.xml).
Code obfuscation: A significant part of the application code, especially in the module com.my.tracker.obfuscated, subjected to obfuscation. Names of classes (e0, c1, y2, b3, f1etc.), methods (a(), b(), c()) and variables in these osted files are meaningless and short, which makes the analysis of the logic of the application extremely difficult without debfusion. Oceanscape is often used to difficulty in reverse designing and hiding the true functions of code.
Data collected (MyTracker module): Module com.my.tracker(Judges by MyTracker.java, MyTrackerConfig.java, MyTrackerParams.java) is responsible for the extensive collection of user data and events.
The main categories of data collected:
User events :
Promotional events (trackAdEvent): Information about interaction with advertising.
Events of purchases (trackAppGalleryPurchaseEvent, trackPurchaseEvent): Details of purchases, including product ID, prices, currency, and additional parameters.
General user events (trackEvent): Universal collection of arbitrary events with customizable parameters (e.g. event name, category, value).
Events of invitations (trackInviteEvent): Tracking User invitations.
Start of applications (trackLaunchManually): Fixing each manual application start.
Level Events (trackLevelEvent): User progress by level.
Entrance Events (trackLoginEvent): User input information, including ID and login method.
Events of mini-applications (trackMiniAppEvent): User activity in mini-applications.
Events of registration (trackRegistrationEvent): Details about the user registration process.
Time spent in the annex/event (incrementEventTimeSpent, startAnytimeTimeSpent, stopAnytimeTimeSpent, startForegroundTimeSpent, stopForegroundTimeSpent): Detailed statistics of application use.
Personal data of the user :
Age (getAge, setAge)
Paul (getGender, setGender)
User ID (getCustomUserId/getCustomUserIds, setCustomUserId/setCustomUserIds)
Email Addresses (getEmail/getEmails, setEmail/setEmails)
ID from messengers and social networks: ICQ ID (getIcqIdOK.ru ID (getOkId), VK Connect ID (getVkConnectId), VK ID (getVkId)
Phone numbers (getPhone/getPhones, setPhone/setPhones)
Interface language (getLang, setLang)
Special IDs associated with MRGS (getMrgsAppId, getMrgsId, getMrgsUserId)
Arbitrary custom parameters (getCustomParam, setCustomParam): Allow developers to collect any additional information.
Attribution data :
Diplinki ( getDeeplinkFrom MyTrackerAttribution: Sources of user transfer to the application (e.g., from advertising campaigns or external links).
Data and system with it (Android Manifest.xml): File AndroidManifest.xmldescribes the requested permissions and components that allow the application to interact with the operating system and collect system data.
The main requested permissions:
Access to the network and location:
android.permission.INTERNET: Full access to the network.
android.permission.ACCESS_WIFI_STATE, android.permission.ACCESS_NETWORK_STATE, android.permission.CHANGE_NETWORK_STATE, android.permission.CHANGE_WIFI_STATE: Access to the state of Wi-Fi and cellular network, the ability to change their condition.
GitHub
GitHub - KARENKING112/max-deep-analysis-of-the-messenger
Contribute to KARENKING112/max-deep-analysis-of-the-messenger development by creating an account on GitHub.
Forwarded from cKure Red
https://hackers-arise.com/the-one-man-apt-part-i-a-picture-that-can-execute-code-on-the-target/
Please open Telegram to view this post
VIEW IN TELEGRAM
https://github.com/Mobile-Artificial-Intelligence/maid
No AI is foss, just the container
No AI is foss, just the container
GitHub
GitHub - Mobile-Artificial-Intelligence/maid: Maid is a cross-platform Flutter app for interfacing with GGUF / llama.cpp models…
Maid is a cross-platform Flutter app for interfacing with GGUF / llama.cpp models locally, and with Ollama and OpenAI models remotely. - GitHub - Mobile-Artificial-Intelligence/maid: Maid is a cro...
Forwarded from #TBOT: Take Back Our Tech
Media is too big
VIEW IN TELEGRAM
⚡️FCC to Shut Down 1,000+ VoIP Companies
Do you use a VoIP service? On August 28, over 1,000 U.S. VoIP providers were forced to stop service under a new FCC order.
The reason: companies didn’t meet the latest Robocall Mitigation Database requirements under the TRACED Act. That means within 2 business days, all other carriers must block traffic from these providers.
This isn’t just about robocalls. It’s also about surveillance — with call lookups, timestamps, calling parties, and more stored for months at a time.
Check if your provider is on the list here:
📄 https://web.archive.org/web/20250826200157/https://docs.fcc.gov/public/attachments/DA-25-737A1.pdf
📖Read the full article on Substack
—
🫶 @takebackourtech
📩 WEBSITE & NEWSLETTER | 🎥 VIDEOS| XMPP | SUBSTACK
Do you use a VoIP service? On August 28, over 1,000 U.S. VoIP providers were forced to stop service under a new FCC order.
The reason: companies didn’t meet the latest Robocall Mitigation Database requirements under the TRACED Act. That means within 2 business days, all other carriers must block traffic from these providers.
This isn’t just about robocalls. It’s also about surveillance — with call lookups, timestamps, calling parties, and more stored for months at a time.
Check if your provider is on the list here:
📄 https://web.archive.org/web/20250826200157/https://docs.fcc.gov/public/attachments/DA-25-737A1.pdf
📖Read the full article on Substack
—
🫶 @takebackourtech
📩 WEBSITE & NEWSLETTER | 🎥 VIDEOS| XMPP | SUBSTACK
#Microsoft swats down reports of #SSD failures in #Windows
Company says recent update didn't cause storage failures
https://xcancel.com/pirat_nation/status/1962668041830912305
Company says recent update didn't cause storage failures
https://xcancel.com/pirat_nation/status/1962668041830912305
i changed my kernel to zen, you can use pf too.
GitHub
Detailed Feature List
Zen Patched Kernel Sources. Contribute to zen-kernel/zen-kernel development by creating an account on GitHub.