good evening,
you're listening to the ADHD Internal Monologue F.M. with me, DJ subconscious,
speaking all your thoughts,
non-stop,
uninterrupted,
24 hours a day,
from classics like "why did i say that?",
and goldest oldies like "am i a horrible person?"
to today's hottest hits,
"what the hell am i doing with my life?"
and "am i hungry or am i bored?"
stay tuned,
24/7,
ADHD radio.
long, research, raid shadow legends (pc) privesc 0day (lol)
going to reverse plarium play (basically a required client for raid shadow legends)
...and their service running as SYSTEM appears to just give privesc by design, kinda?
it does IPC via localhost TCP socket with lots of memecrypto involved (salted SHA512 hash, where the salt is stored in the registry crypted by AES-CBC with hardcoded key and IV, and protocol messages are also AES-CBC crypted with a different hardcoded key + IV too)
when running a file, files are allowlisted by server-side check of sha512 hash, but there's a race condition and a path traversal, so you can place an allowed file there, tell the service to run it with whatever args, wait for it to read the file and then replace it...
alternatively you can make a download and install request, using the path traversal to replace a service binary or whatever, it'll write the file out as SYSTEM after all
and yes i just dropped a 0day but on the bright side i just gave everyone a reason to uninstall raid shadow legends on pc so...
Things are pretty bleak these days. I have curated my TL pretty tightly but the bad news is still unrelenting.
This is maybe a good time to remind folks YOU are the algorithm.
Instead of amplifying outrage (and there is plenty to be mad about, I get it. Holy fuck I get it) consider prioritizing the boosting of: resources, solutions, hope, even humour, and definitely anything that celebrates folks stepping up to make things better.
Huh. So apparently those battery-powered trains that Stadler were testing in Germany last year, are destined for Merseyrail. Which is interesting, I didn't realize it'd gotten beyond the proof-of-concept stage already!
Cannabis should be legal, all convictions for possession expunged, and all opportunities for legal licensure offered to the most harmed and marginalized, first.
But until then, here's a portal to get your fed-level simple possession convictions pardoned:
https://www.justice.gov/iqextranet/EForm.aspx?__cid=Pardon_prod&__fid=5&link_id=3&can_id=9353bf9204555509ae8c9aed63a01b16
I kinda have an itch to resurrect my old community platform thing project, that lets people create their own 'community' with a forum and photo gallery and articles and stuff, but that lets you use HTML and design customizations etc.
This is something I built back in 2009 or thereabouts, but unfortunately it went under due to personal issues :(
And I've kinda felt like it wouldn't be worth resurrecting because social media have moved on (though admittedly even back then it was an outlier), but lately I've been reconsidering that... maybe there *is* a place for that sort of thing?
So yeah, all those people calling for "reform" and "change from the inside" and "work within the system to improve it"? *This* is what that leads to, and why we do not care for reforms - all it ended up doing was laundering Facebook's reputation
abortion, facebook
Actually, as a bit of backstory for those who weren't there for this: Stamos, as the newly hired CSO, was the Weirdly Defensive Nerd jumping in front of Facebook to defend it from public criticism about how Facebook was a danger to privacy and safety.
He was insistent that there was nothing fundamentally wrong with Facebook, it just needed the right person to safeguard that safety, and the people criticizing Facebook were just alarmists/extremists (paraphrased, it's been a few years).
And well, here we are, this is what you get, an unavoidable megacorp snitching on people who are trying to get an abortion
uspol, growing us fascism
PSA: when you are committing crimes against any government at any level, please don’t use commercial internet services to talk about doing so or planning to do so.
Don’t post about specific actions you’re taking, because those services WILL turn you in.
This message brought to you by https://www.reddit.com/r/technology/comments/11indx4/facebook_and_google_are_handing_over_user_data_to/?utm_source=share&utm_medium=ios_app&utm_name=iossmf
In the process of moving to @joepie91. This account will stay active for the foreseeable future! But please also follow the other one.
Technical debt collector and general hype-hater. Early 30s, non-binary, ND, poly, relationship anarchist, generally queer.
- No alt text (request) = no boost.
- Boosts OK for all boostable posts.
- DMs are open.
- Flirting welcome, but be explicit if you want something out of it!
- The devil doesn't need an advocate; no combative arguing in my mentions.
Sometimes horny on main (behind CW), very much into kink (bondage, freeuse, CNC, and other stuff), and believe it or not, very much a submissive bottom :p
My spoons are limited, so I may not always have the energy to respond to messages.
Strong views about abolishing oppression, hierarchy, agency, and self-governance - but I also trust people by default and give them room to grow, unless they give me reason not to. That all also applies to technology and how it's built.