Weekly Shaarli

All links of one week in a single page.

Week 52 (December 23, 2024)

Ultrawide archaeology on Android native libraries - Luca Di Bartolomeo & Rokhaya Fall - 38th Chaos Communication Congress (38C3)

A bug in a scraper script led to us downloading every single native library in every single Android app ever published in any market (~8 million apps).
Instead of deleting this massive dataset and starting again, we foolishly decided to run some binary similarity algos to check if libraries and outdated and still vulnerable to old CVEs. No one told us we were opening Pandora's box.
A tragic story of scraping, IP-banning circumvention, love/hate relationships with machine learning, binary similarity party tricks, and an infinite sea of vulnerabilities.

Running a Domain Registrar for Fun and (some) Profit - Q Misell - May Contain Hackers 2022
thumbnail

Ever wondered what happens behind the scenes when you click buy on that domain for a new side project that'll definitely happen (you will get to it eventually, right)? Well this is the talk for you! We'll cover all the extremely cursed details of how exactly one sells and manages a domain, the standards for this (or lack thereof), and some pointers for how you could get started managing your own domains directly, if you're not completely put off by this talk's contents.

Dialing into the Past: RCE via the Fax Machine – Because Why Not? - Rick de Jager & Carlo Meijer - 38th Chaos Communication Congress (38C3)

Remember the days when faxes were the pinnacle of office tech, and the sound of a paper getting pulled in was as satisfying as a fresh cup of coffee? Well, it's time to dust off those memories and reintroduce ourselves to the quirky world of printers and their forgotten fax interfaces – yes, those relics that make us all feel like we're in an '80ies sci-fi movie – and specifically, how they can unlock a new frontier in printer security exploits!

10 years of emulating the Nintendo 3DS: A tale of ninjas, lemons, and pandas - neobrain - 38th Chaos Communication Congress (38C3)

How is 3DS preservation faring 10 years after the release of the first emulator? What technical obstacles have we overcome, which ones remain? What hidden gems have we discovered beyond games? Join us on a journey through the struggles, the successes, and the future of 3DS emulation!

We've not been trained for this: life after the Newag DRM disclosure - Redford, q3k and MrTick - 38th Chaos Communication Congress (38C3)
thumbnail

You've probably already heard the story: we got contracted to analyze a bunch of trains breaking down after being serviced by independent workshops. We reverse engineered them and found code which simulated failures when they detected servicing attempts. We presented our findings at 37C3… and then shit hit the fan.

How Network Address Translator (NAT) works - David Anderson - Tailscale
thumbnail

We covered a lot of ground in our post about How Tailscale Works. However, we glossed over how we can get through NATs (Network Address Translators) and connect your devices directly to each other, no matter what’s standing between them. Let’s talk about that now!