2
<p>doing a SMAP bypass is hilariously easy, and SMEP bypass is only somewhat annoying to do</p><p>i think i understand now why people don&#39;t take the mitigations in x64 seriously</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@whitequark" class="u-url mention">@<span>whitequark</span></a></span> bask in the glory that is whomever you’re about to serve a SSIRP is about to have a really bad weekend πŸ˜…πŸ˜†πŸ₯²</p>
<p>me and another girl just wrote an exploit for a vulnerable driver that goes from an unprivileged process straight to kernel code execution</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@whitequark" class="u-url mention">@<span>whitequark</span></a></span> <br />developers<br />developers<br />developers</p><p>developers<br />developers<br />developers<br />developers<br />developers</p><p>πŸ˜… </p><p>developers<br />developers<br />developers</p><p>developers<br />developers<br />developers<br />developers<br />developers</p><p>πŸ’¦ </p><p>developers<br />developers<br />developers</p><p>developers<br />developers<br />developers<br />developers<br />develop</p><p> πŸ’¦ πŸ‘¨β€πŸ¦² πŸ’¦</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@whitequark" class="u-url mention">@<span>whitequark</span></a></span> protip: burn the ISO to USB with Rufus, it asks you if you want to yank out all the requirements like a Microsoft account, TPM requirements, etc.</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@whitequark" class="u-url mention">@<span>whitequark</span></a></span> You can make an installer that has it disabled or after installation you can turn the online account into a normal non MS local account.<br />For installer you can use rufus to modify an official ISO. For doing it after install:<br />Settings-&gt;Accounts-&gt;&quot;Your info&quot;-&gt;&quot;Sign in with a local account instead&quot;. That deletes the account and copies over data to a new local account.</p>
<p><span class="h-card" translate="no"><a href="https://queer.hacktivis.me/users/lanodan" class="u-url mention">@<span>lanodan</span></a></span> <span class="h-card" translate="no"><a href="https://not.acu.lt/@ignaloidas" class="u-url mention">@<span>ignaloidas</span></a></span> it shouldn&#39;t be too hard to grab buildids for all the stuff you want and get debuginfod to cache it</p>
<p><span class="h-card" translate="no"><a href="https://labyrinth.zone/users/Rairii" class="u-url mention">@<span>Rairii</span></a></span> user and kernel yes</p>
@whitequark@mastodon.social @ignaloidas@not.acu.lt Meanwhile I'm not always online (or with decent connectivity) and some of my systems also aren't always online.