GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Ange (ange@mastodon.social)

  1. Embed this notice
    Ange (ange@mastodon.social)'s status on Saturday, 25-Jan-2025 19:20:28 JST Ange Ange
    in reply to

    Data chunked that way doesn’t have a pre-declared length.
    The total length is obtained by adding all the lengths of each block.

    In conversation about 4 months ago from mastodon.social permalink
  2. Embed this notice
    Ange (ange@mastodon.social)'s status on Saturday, 25-Jan-2025 19:20:28 JST Ange Ange

    Do you know any format or protocol that uses chunking besides Gif/Jif?
    ICYDK chunking is slicing data in blocks smaller than 256 bytes, with the length before each block. A null block terminates the sequence.

    In conversation about 4 months ago from mastodon.social permalink
  3. Embed this notice
    Ange (ange@mastodon.social)'s status on Thursday, 16-Jan-2025 06:45:57 JST Ange Ange

    This Friday, we’ll explore the Wad archive format, used in Doom.
    https://www.youtube.com/live/g0VyFDYefqQ?si=4tKlJ0gQ9TVFV_Ir

    In conversation about 4 months ago from mastodon.social permalink

    Attachments

    1. 8 WAD archives (Doom)
      from Ange Albertini
      Let's explore the basics of the Wad files.
  4. Embed this notice
    Ange (ange@mastodon.social)'s status on Wednesday, 08-Jan-2025 16:19:52 JST Ange Ange

    What is your favorite pdf hack (not file-format based):
    Change text?
    Remove watermark?
    Remove ads pictures on documents to print?

    In conversation about 4 months ago from mastodon.social permalink
  5. Embed this notice
    Ange (ange@mastodon.social)'s status on Sunday, 05-Jan-2025 20:03:43 JST Ange Ange

    What's your favorite file format challenge / trick / bug / surprise / work / art ?
    Bonus point if it's underrated or obscure!

    In conversation about 4 months ago from mastodon.social permalink
  6. Embed this notice
    Ange (ange@mastodon.social)'s status on Sunday, 05-Jan-2025 10:03:05 JST Ange Ange

    My stream about crafting a PDF file from scratch is over.
    https://www.youtube.com/live/q6KgFezu8tw?si=Ep9Gm-scYSr1FFcg
    It was nice and chill to take the time to answer questions, thanks again for joining!

    In conversation about 4 months ago from mastodon.social permalink

    Attachments

    1. Let's craft a 'hello world' PDF file from scratch!
      from Ange Albertini
  7. Embed this notice
    Ange (ange@mastodon.social)'s status on Saturday, 04-Jan-2025 23:02:29 JST Ange Ange

    I will stream in 8h about the basics of the PDF format, teaching how to make a basic PDF from scratch.

    This is an easy-level introduction to the PDF [portable document format], aimed at all audiences: infosec, but also digipres, DFIR, and others.

    This will not cover complex cases, polyglots, abuses or exploit.
    That will come next but this stream is the start on the topic.
    The stream will be recorded and available publicly.

    In conversation about 4 months ago from mastodon.social permalink
  8. Embed this notice
    Ange (ange@mastodon.social)'s status on Wednesday, 18-Sep-2024 17:55:20 JST Ange Ange

    Some tools detect the EICAR file in Zip files by size and CRC so that it even detects it in password-protected zips without having the password.
    This can of course lead to accidental or intentional FPs.

    In conversation about 8 months ago from mastodon.social permalink
  9. Embed this notice
    Ange (ange@mastodon.social)'s status on Wednesday, 18-Sep-2024 17:55:19 JST Ange Ange
    in reply to

    CRC-forging is also useful to collide arbitrary contents inside a ZIP archive. It makes possible re-usable and instant MD5 collisions for ZIP-based documents such as DOCX, XLSX, EPUB, XPS, 3MF.
    https://speakerdeck.com/ange/inside-out-abusing-archive-file-formats

    In conversation about 8 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: files.speakerdeck.com
      Inside out - abusing archive file formats
      from Ange Albertini
      If a format structure isn't vulnerable, can that change once wrapped in an archive? File formats abuses depend on specific structure characteristics,…
  10. Embed this notice
    Ange (ange@mastodon.social)'s status on Wednesday, 18-Sep-2024 17:55:19 JST Ange Ange
    in reply to

    Some even detect a CRC-colliding file if there's no password.

    In conversation about 8 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/157/571/019/168/588/original/824bea2d4d4e9fa5.png

    2. https://files.mastodon.social/media_attachments/files/113/157/576/859/868/109/original/5d1ad0266a70abf9.png
  11. Embed this notice
    Ange (ange@mastodon.social)'s status on Wednesday, 10-Jan-2024 05:41:53 JST Ange Ange

    An extreme example of a weird file construct, applicable to most formats:
    a polymock, with fake file formats signatures at their correct offset.

    In conversation Wednesday, 10-Jan-2024 05:41:53 JST from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/111/727/540/523/200/860/original/3d7a1255a2ab029d.png
  12. Embed this notice
    Ange (ange@mastodon.social)'s status on Friday, 30-Dec-2022 14:33:27 JST Ange Ange

    My file formats dissection repo should be now up-to-date.
    https://github.com/corkami/pics/blob/master/binary/README.md#images

    In conversation Friday, 30-Dec-2022 14:33:27 JST from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/109/581/230/460/188/646/original/901a25f844982380.png

    2. https://files.mastodon.social/media_attachments/files/109/581/231/503/635/250/original/3acf381bb1eb1175.png

    3. https://files.mastodon.social/media_attachments/files/109/581/232/117/545/114/original/14ea8e0ec51f992f.png

    4. https://files.mastodon.social/media_attachments/files/109/581/232/511/805/107/original/2f047c448f9beaab.png
    5. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      pics/README.md at master · corkami/pics
      Posters, drawings... Contribute to corkami/pics development by creating an account on GitHub.

User actions

    Ange

    Ange

    Corkami, CPS2Shock, PoC||GTFO, Sha1tered. Security engineer @ Google. He/him.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          82636
          Member since
          30 Dec 2022
          Notices
          12
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.