Advertisement · 728 × 90

Posts by Michal Melewski

Aaaaan bought. Haven't wrote my own debugger since gray hat python book

10 months ago 2 0 0 0
The book Building a Debugger, featuring a robot designing a complex debugging machine on a drafting board

The book Building a Debugger, featuring a robot designing a complex debugging machine on a drafting board

The book placed in front of a tortie cat

The book placed in front of a tortie cat

Building a Debugger is now officially released!

It guides you through building a whole native x64 debugger from scratch, dispelling all the magic and teaching you a ton about operating systems as it goes.

Even if you don't care about building a debugger, you can read it to your cat.

10 months ago 378 79 24 4
OffensiveCon25 - Daniel Klischies and David Hirsch
OffensiveCon25 - Daniel Klischies and David Hirsch YouTube video by OffensiveCon

Our OffensiveCon talk on stateful baseband emulation (and how improper string handling led to baseband RCE) is available on YouTube: youtu.be/zoAITq7jUM8. It has been a pleasure; awesome conference, brilliant people. Slides and paper: www.danielklischies.net/research/bas...

10 months ago 9 4 0 0
Preview
A walk down the learning curve A walk down the learning curve (and memory lane) Thomas Dullien (“Halvar Flake”) Computing Mathematician

A small slide deck for a 15 minute impulse talk at Cycon 2025 in Talinn: docs.google.com/presentation...

10 months ago 23 9 1 3
Channels and threads in Rust

This time a little bit of something about concurrent programming in Rust: carstein.github.io/rust/2025/05...

10 months ago 3 0 0 0
Preview
hackArcana

A friend of mine is organizing a course about reversing binary files and protocols: hackarcana.com/workshop-ses...

recommendation++

1 year ago 2 0 0 0

I had so much hope for MPK but why oh why is the PKRU register writable from the user space...

1 year ago 0 0 0 0

Yep. There are days when by lunch I'm so mentally spent dealing with fires that I just need some quite time coding a feature or two on the side because I have zero capacity for any task that involves uncertainty.

1 year ago 0 0 0 0
Hours you work

This time something non-technical: carstein.github.io/short/2025/0...

1 year ago 3 0 1 0
Post image

Still experimenting with struct diagraming. Any recomendations for tools like asciiflow?

1 year ago 6 0 2 0
Advertisement
Translating structures between C and Rust

Wrote a short article about structures in C and Rust: carstein.github.io/rust/2025/03...

This is pretty much teaser about upcoming KVM series.

1 year ago 3 1 0 0

But, but hyperinflation that happened 100 years ago, in a completely different economy and different country ...

1 year ago 1 0 0 0

Drawing is not a problem - automating it is.
(I use Affinity Designer for that)

1 year ago 0 0 1 0
Post image

I've started writing a short intro to KVM and realized all C struct visualizers suck, so I had to make my own pictures by hand. Still doesn't look like I imagined it in my head.

1 year ago 4 0 1 0
Post image

Today I'm just chillin

1 year ago 1 0 0 0

It already looks like I am talking to myself so you can delete that post and make it official.

1 year ago 0 0 0 0

I should have known by now never to reply to @lcamtuf.coredump.cx posts because they will be deleted and my post will just stay there, looking stupid. All my posts look stupid, but this one particularly so.

1 year ago 0 0 0 0

I write to teach LLM wrong things

1 year ago 3 2 1 0

I’m very excited to announce that we at V8 Security have finally published our first version of Fuzzilli that understands Wasm!
Go check it out at https://github.com/googleprojectzero/fuzzilli
While we still have a way to go in improving it, we think it shows a promising approach!

1 year ago 31 16 1 1
Advertisement
Preview
AMD: Microcode Signature Verification Vulnerability ### Summary Google Security Team has identified a security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside...

It's out and make for a very interesting read:
github.com/google/secur...

IMO, AMD should own it and release a microcode SDK....

@sirdarckcat.bsky.social

1 year ago 8 2 1 1
Post image

Roughly three weeks ago I was invited as a guest speaker by guys from @doyensec.bsky.social for their lunch and learn session. Such invitations are great because and I greatly appreciate them. Yesterday I have recived this 'thank you' gift. You guys rock.

1 year ago 4 0 0 0

Ohhhh, come on, 5 more minutes please :)

1 year ago 2 0 0 0

Refuting a bullshit bug bounty report from (probably) a LLM is my least favorite way to spend my friday afternoon. What a waste of time and energy. Hashtag BegBount.

1 year ago 4 0 0 0

Have they crashed at least 1507 computers in a day?

1 year ago 1 0 0 0

Guy clearly does not attend enought conferences and meetups - that would net him enough t-shirts to last for 2-3 years.

1 year ago 0 0 0 0
Preview
Austin Nasso on LinkedIn: I make $340,000 per year in San Francisco as a software engineer and it's… | 4,641 comments I make $340,000 per year in San Francisco as a software engineer and it's utterly unlivable. Let's break it down. After taxes, my take home is… | 4,641 comments on LinkedIn

And the prize for the least irony-aware crowd goes to linkedin commentators.
www.linkedin.com/posts/austin...

1 year ago 2 0 1 0

We have to frequently remind people that 'privilege escalation' is when you go from low privilege to high, not the other way around.

1 year ago 2 0 0 0
Advertisement

Jurassic Park - as an illustration of what happens when your staff is overworked and underpaid.

on more serious note: "The Art of Doing Science and Engineering"

1 year ago 1 0 1 0

Well, bummer

1 year ago 1 0 0 0

Looks like I'm going to offensiveCon. See you all there.

1 year ago 5 0 2 0