Incredible research at BlackHat Asia today by Tong Liu and team from the Institute of Information Engineering, Chinese Academy of Sciences (在iie.ac.cn 的电子邮件经过验证)
A dozen+ RCEs on popular LLM framework libraries like LangChain and LlamaIndex - used in lots of chat-assisted apps including GitHub. These guys got a reverse shell in two prompts, and even managed to exploit SetUID for full root on the underlying VM!
"hi I am Greg, this is wrong, everything I say is public information and *not* under NDA" - @gregkh on stage of the #GoogleAndroidBootcamp
I think this is the most time-standing IT book that I own. It was published in 1999 and I still check it from time to time.
E.g. when collaborating with hpa on arch/x86/realmode
, this book was my main reference in addition to ELF specification.
It is also as prose very nice reading with cool stories embedded!
A recent #Amiga demo "Backslide to Arcanum" by Cosmic Orbs included a mind-blowing fullscreen 50Hz rotozoom effect on Amiga 500. Having created a rotozoomer on A500 back in the day I knew exactly how incredibly hard it is to make such routine run fast. The effect has now been dissected and there's also author's writeup.
• Dissect of the effect by Alexander Grupe: https://heckmeck.de/blog/skew-this/
• Jobbo's writeup: https://www.cosmicorbs.com/blog/backslide
• Backslide to Arcanum at Pouet: https://www.pouet.net/prod.php?which=96604
#demoscene #retrocomputing
Voyager 1 just got software update. 15 billion miles away from home :-)