Hacker News
- Compromising OpenWrt Supply Chain https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/ 99 comments
- Single-packet race condition breaking the 65535 byte lim https://flatt.tech/research/posts/beyond-the-limit-expanding-single-packet-race-condition-with-first-sequence-sync/ 31 comments
- BatBadBut: You can't securely execute commands on Windows https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/ 42 comments
- Detailed Report on Local Privilege Escalation in Ubuntu Desktop (Pwn2Own 2021) https://flatt.tech/reports/210401_pwn2own/ 7 comments
Lobsters
- Clone2Leak: Your Git Credentials Belong To Us https://flatt.tech/research/posts/clone2leak-your-git-credentials-belong-to-us/ 10 comments security
- Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/ 4 comments security
- BatBadBut: You can't securely execute commands on Windows https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/ 6 comments security , windows
- OpenWrt suggests (inplace) upgrading https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/ 5 comments openwrt
- OpenWrt Supply Chain Compromission via Truncated SHA-256 Collision and Command Injection https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/ 33 comments programming
- Beyond the Limit: Expanding single-packet race condition with a first sequence sync for breaking the 65,535 byte limit https://flatt.tech/research/posts/beyond-the-limit-expanding-single-packet-race-condition-with-first-sequence-sync/ 5 comments netsec
- BatBadBut: You can't securely execute commands on Windows https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/ 11 comments netsec
- Detailed Report on Local Privilege Escalation Vulnerability in Ubuntu Desktop (Pwn2Own 2021) https://flatt.tech/reports/210401_pwn2own/ 8 comments netsec