In zooms all day? Try spicing it up by mangling your cliche phrases!
"I don't have a horse in that fight"
"Half of one, 6 dozen of another"
"Too many chefs in the fire"
"Let's not put the hearse before the car"
Brandon Edwards
4,782 posts
CTO @crashappsec. Past: Cofounder and Chief Scientist @capsule8, Hacker-in-Residence @NYUTandon, and other research, reverse-engineering, and exploit dev roles.
NYC
Joined June 2009
- Step 1: start zoom (don't) Step 2: cat /proc/`pidof zoom | awk {'print $1'}`/maps | grep rwx Step 3: laugh (cry)
- A friend texted and said "your twitter is brutal this morning" Here's the thing. Between 2018 and 2021 CRWD would blatantly lie to their existing customers (of win agent) to not pursue Capsule8 for Linux. They would say they have a Linux agent that does what we do, except..
- it's a tired topic, I'm sick of it, but the "it's not a backdoor" crowd compelled me to help people understand:
- Rewatching Sneakers and I’m certain it’s the best hacking movie of all time
- This is spot on. The preference to allow nothing more than the “strictly necessary” cookies never changes, so it shouldn’t require telling every site. It’s not like suddenly on some site I’m like “actually here specifically I want surveillance spam cookies, collect all my shit”Replying to @invisig0thClicking all those "accept cookies" buttons is expending energy to support security theatre. Tech exists to *enforce* these preferences. Saying "please don't" does not. </rant>
- Why is ARM so hideous? x86 instructions look like what they do, "add", "push", etc. ARM out here with "ldar x29, [x0], #-7" Cue the ARM fans to come in talking about how obviously ldar means "load double aquarius rising"
- I'm excited to announce that @0x7674 and I will be presenting our Compendium of Container Escapes at @BlackHatEvents USA 2019
- Happy 25th anniversary to Hackers, here's a throwback from the 15th anniversary:
- Is there a nerdcore rapper named Lil Endian? There should be
- That systemd local privilege escalation? Here's how to write an initial PoC for it (via @kallsyms) @capsule8: capsule8.com/blog/exploitin…
- Replying to @drraidSo yeah, I'm taking the moment to get a bit of a laugh. This is why IPS vendors stopped doing kernel modules ~2010. Or at least the smart ones did?





