Advertisement · 728 × 90

Posts by ActiveTK․

I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.

The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().

It's RCE, not auth bypass, and gated/unreplayable.

2 years ago 685 275 7 14

既定で20人を自動フォローするのか....いろいろと事故る人いそう

2 years ago 4 0 0 0

activetkの方でアカウントを再作成しました。
MisskeyにせよBlueskyにせよ、やはりtwttrに近いUIですね。

2 years ago 3 0 0 1

Hello, world!

2 years ago 5 0 0 0