Log inSign up
blasty
4,469 posts
Image
user avatar
blasty
@bl4sty
irresponsible disclosure aficionado
The Netherlands
haxx.in
Joined April 2009
1,147
Following
17.3K
Followers
  • user avatar
    blasty
    @bl4sty
    Jul 11, 2023
    wholesome yet dystopian
    Image
    5.5M
  • user avatar
    blasty
    @bl4sty
    Apr 6, 2024
    the xz sshd backdoor rabbithole goes quite a bit deeper. I was just able to trigger some harder to reach functionality of the backdoor. there's still more to explore.. 1/n
    Image
    872K
  • user avatar
    blasty
    @bl4sty
    Apr 6, 2024
    Replying to @bl4sty
    auth bypass confirmed! > INFO:paramiko.transport:Authentication (password) successful! mm_keyallowed_backdoor cmd 1 allows to override the response for mm_answer_authpassword with a custom one. if you set it to { u32(9), u8(13), u32(1), u32(0) } you can login with any pass 🤓
    110K
  • user avatar
    blasty
    @bl4sty
    Apr 2, 2024
    xz bd engineer 1: bro, we need a way to probe the address space to make sure we never SEGV sshd xz bd engineer 2: we'll just do a pselect syscall with empty fd sets, a timeout of 1 nanosecond and the addr we want to probe is passed as the sigmask pointer, EFAULT means unmapped
    Image
    164K
  • user avatar
    blasty
    @bl4sty
    Jan 10, 2023
    Decided to publish the Lexmark printer exploit + writeup + tools instead of sell it for peanuts. 0day at the time of writing: github.com/blasty/lexmark -- enjoy!
    Image
    GitHub - blasty/lexmark
    From github.com
    147K
  • user avatar
    blasty
    @bl4sty
    Mar 29, 2024
    nothing to see here, just properly documenting the fixed defects in the backdoor code 😂
    Image
    89K
  • user avatar
    blasty
    @bl4sty
    Mar 7, 2022
    Hacked up a quick Dirty Pipe PoC that spawns a shell by hijacking (and restoring) the contents of a setuid binary. haxx.in/files/dirtypip…
    Image
  • user avatar
    blasty
    @bl4sty
    Jul 11, 2023
    Replying to @bl4sty
    .. since this tweet is ballin' slightly outta control: 1) image was stolen from @[email protected] on the fediverse, not my neighbourhood (SF) 2) all the printers I currently own will only display this quirky animation: x.com/thezdi/status/… -- who do I contact??
    user avatar
    TrendAI Zero Day Initiative
    @thezdi
    Dec 8, 2022
    While @bl4sty only scored a COLLISION (non-unique bug) - Peter definitely gets a boatload of STYLE POINTS for this hack on a Canon printer @ #P2OToronto #Pwn2Own
    Image
    00:00
    445K
  • user avatar
    blasty
    @bl4sty
    Mar 29, 2024
    Replying to @bl4sty
    you gotta appreciate the way they shipped the backdoored object file. added some "test" data to the source tree that gets unxz'd and (dd) carved in a specific way, that is fed into a deobfuscator written in.. awk script and the result gets unxz'd again
    Image
    108K
  • user avatar
    blasty
    @bl4sty
    Apr 6, 2024
    Replying to @bl4sty
    whoever designed this stuff had to take a deep dive into openSSH(d) internals (and so did I for the past couple of days, oof) .. hats off, once again :)
    76K
  • user avatar
    blasty
    @bl4sty
    Mar 25, 2025
    Here we can see @AnthropicAI's claude (Sonnet 3.7 model) talking to IDA pro to reverse engineer a CTF task I made for @PotluckCTF, it does pretty well! It manages to get a grasp of the entire custom VM instruction set, file format, syscall interface etc.🤓 The MCP server is
    Image
    00:00
    61K
  • user avatar
    blasty
    @bl4sty
    Jan 25, 2022
    haxx.in/files/blasty-v… enjoy, my fellow scriptkiddies
  • user avatar
    blasty
    @bl4sty
    Feb 6, 2018
    *facepalm*
    Image
    Image
  • user avatar
    blasty
    @bl4sty
    Mar 7, 2022
    Dirty Pipe PoC (dirtypipe.cm4all.com) works beautifully. 🤑
    Image

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement