Forwarded from Vladimir S. | Officer's Channel (Vladimir S. | officercia)
Elliptic's private key extraction in ECDSA upon signing a malformed input.
Private key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come from JSON network input.
I suggest not to be nervous, I think it will be fixed soon. However, this is interesting enough information to share with you!
Link: https://github.com/advisories/GHSA-vjh7-7g9h-fjfh
#cryptography #offtopic
Private key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come from JSON network input.
I suggest not to be nervous, I think it will be fixed soon. However, this is interesting enough information to share with you!
Link: https://github.com/advisories/GHSA-vjh7-7g9h-fjfh
#cryptography #offtopic
GitHub
GHSA-vjh7-7g9h-fjfh - GitHub Advisory Database
Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
#solana #links
- Solana Hardware Compatibility List — https://solanahcl.org/
- Полезное для валидаторов Solana — https://teletype.in/@in_extremo/solana_useful
- Solana Hardware Compatibility List — https://solanahcl.org/
- Полезное для валидаторов Solana — https://teletype.in/@in_extremo/solana_useful
👍2
Forwarded from Denis Sexy IT 🤖
Интересный вид атаки протестировали через опенсорс LLM-модели:
1. Берем любую опенсорс модель
2. Учим ее добавлять незаметно какие-то вещи в код (например, ссылки на вредоносные скрипты)
3. Загружаем обратно куда-то сохраняя имя оригинальной модели или просто делаем вид что это новая версия
4. Все, зараженную модель невозможно обнаружить, защиты тоже нету
Поэтому, всегда проверяйте кто поставщик модели и куда она загружена – у известных лаб как правило много прошлых публикаций моделей, рейтинги и тп
Tldr: всякие
На скриншоте пример взаимодействия с такой моделью и подключение вредоносного скрипта:
1. Берем любую опенсорс модель
2. Учим ее добавлять незаметно какие-то вещи в код (например, ссылки на вредоносные скрипты)
3. Загружаем обратно куда-то сохраняя имя оригинальной модели или просто делаем вид что это новая версия
4. Все, зараженную модель невозможно обнаружить, защиты тоже нету
Поэтому, всегда проверяйте кто поставщик модели и куда она загружена – у известных лаб как правило много прошлых публикаций моделей, рейтинги и тп
Tldr: всякие
Deep.Seek.r1.2025.671b.BluRay.x264.AAC.gguf не качаемНа скриншоте пример взаимодействия с такой моделью и подключение вредоносного скрипта:
Forwarded from Ian
This media is not supported in your browser
VIEW IN TELEGRAM
Now that we know who's behind the
@Bybit_Official
attack. Let's look at how the hack actually worked.
At a high level, the hack involved the 4 broad group of events:
1. Attacker deployed a trojan contract and a backdoor contract.
2. Attacker tricked signers of the upgradeable multisig "cold" wallet to authorize a malicious ERC-20 transfer to a trojan contract
3. Instead of transferring tokens, trojan contract replaces the master copy of the actual Safe multisig implementation contract with the backdoor contract, which is solely controlled by the attacker.
4. The attacker called sweepETH and sweepERC20 to drain the wallet of all its native ETH, mETH, stETH, and cmETH tokens.
(Source: https://x.com/dhkleung/status/1893073663391604753)
Funny fact:
In Elixir you have
In Elixir you have
~/ → /home/user expand helpers, and in NodeJS and Go you haven't
IO.puts Path.expand("~/.xxx") # "/home/user/.xxx"
❤2😢2
Why I hate JS?
> const { web3 } = await import('@coral-xyz/anchor')
undefined
> new web3.PublicKey(web3.PublicKey.default.toString()) == new web3.PublicKey(web3.PublicKey.default.toString())
false
> new web3.PublicKey(web3.PublicKey.default.toString()).toString() == new web3.PublicKey(web3.PublicKey.default.toString()).toString()
true
> console.log(web3.PublicKey.default.toString())
11111111111111111111111111111111
❤4
Впервые в связи с китайцами выражение «May you live in interesting times» употребили в 1936 году. Британская газета The Yorkshire Post процитировала выступление сэра Остина Чемберлена, который сказал: «Не так давно в Лондоне дипломат, проработавший несколько лет в Китае, сказал мне, что есть китайское проклятие, которое звучит как "Чтобы вы жили в интересные времена". Несомненно, что на нас обрушилось проклятие». Кстати, об «интересных временах» в своих выступлениях не раз говорил отец Остина Чемберлена, видный государственный деятель Джозеф Чемберлен. Правда, с китайцами он это выражение никак не связывал.
(Source)
Up: Originally — "Better to be a dog in times of tranquility than a human in times of chaos" (source)
👍3
Trump just legalized confiscation as a funding source. NSA/FBI is the US’ Lazarus, doesn’t it?
🔥2