<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-04-20T18:20:43Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by James Forshaw :donor:</title>
  <author>
    <name>James Forshaw :donor:</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1wp4gyc9xmkjxl0vpxpmv0hmsw25uyhvwnynewn5mrj8s66v8ku6sesejcr.rss" />
  <link href="https://yabu.me/npub1wp4gyc9xmkjxl0vpxpmv0hmsw25uyhvwnynewn5mrj8s66v8ku6sesejcr" />
  <id>https://yabu.me/npub1wp4gyc9xmkjxl0vpxpmv0hmsw25uyhvwnynewn5mrj8s66v8ku6sesejcr</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/286/075/107/959/801/original/e338c8bf2f90599b.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/286/075/107/959/801/original/e338c8bf2f90599b.jpg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsfcrc86whkdler2ssaaygk344h9f0v0zwuqy6lljf6nws5gu6pk9qzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn26zjh7x</id>
    
      <title type="html">I&amp;#39;ve put up the slides from my Zer0Con 2026 presentation on ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfcrc86whkdler2ssaaygk344h9f0v0zwuqy6lljf6nws5gu6pk9qzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn26zjh7x" />
    <content type="html">
      I&amp;#39;ve put up the slides from my Zer0Con 2026 presentation on Administrator Protection. &lt;a href=&#34;https://github.com/tyranid/infosec-presentations/blob/master/Zer0Con/2026/Protecting%20your%20Administrator.pdf&#34;&gt;https://github.com/tyranid/infosec-presentations/blob/master/Zer0Con/2026/Protecting%20your%20Administrator.pdf&lt;/a&gt;
    </content>
    <updated>2026-04-07T08:32:00Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv6sdgku6wlpaq8uw752ramsec90r94vgn459nnu83dtxd8gv6qugzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2jhvzj2</id>
    
      <title type="html">the real question, is &amp;#34;gib&amp;#34; pronounced with a hard g like ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv6sdgku6wlpaq8uw752ramsec90r94vgn459nnu83dtxd8gv6qugzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2jhvzj2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstwjrtu5dty3dkpzs02pumtsm94wvdvqdq36k9ly9aapg5hq98u9gr4t78l&#39;&gt;nevent1q…t78l&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;the real question, is &amp;#34;gib&amp;#34; pronounced with a hard g like gif, or a soft g like gif?
    </content>
    <updated>2026-04-06T19:11:33Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyejk8gklka35lydj7cnhd5f4wu83kvrgjzzfg8340qx4mgm9at8qzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2jtkyj5</id>
    
      <title type="html">My final blog related to admin protection is up. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyejk8gklka35lydj7cnhd5f4wu83kvrgjzzfg8340qx4mgm9at8qzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2jtkyj5" />
    <content type="html">
      My final blog related to admin protection is up. &lt;a href=&#34;https://projectzero.google/2026/02/gphfh-deep-dive.html&#34;&gt;https://projectzero.google/2026/02/gphfh-deep-dive.html&lt;/a&gt; I go into a bit of history of the interesting GetProcessHandleFromHwnd API, how it ended up allow you to bypass protected process restrictions and how it&amp;#39;s now &amp;#34;fixed&amp;#34;.
    </content>
    <updated>2026-02-26T19:51:32Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs03tkhuntkzcvstkn9sekr22zx8hn4wtr82ds8lc3jt4taartpwpgzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2r3ktgf</id>
    
      <title type="html">My first blog post on Windows Administrator Protection is out. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs03tkhuntkzcvstkn9sekr22zx8hn4wtr82ds8lc3jt4taartpwpgzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2r3ktgf" />
    <content type="html">
      My first blog post on Windows Administrator Protection is out. &lt;a href=&#34;https://projectzero.google/2026/26/windows-administrator-protection.html&#34;&gt;https://projectzero.google/2026/26/windows-administrator-protection.html&lt;/a&gt; probably the most interesting and complex bug out of the 9 I found, but that doesn&amp;#39;t mean the rest weren&amp;#39;t interesting as well, stay tuned :D
    </content>
    <updated>2026-01-26T18:37:06Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdc4jh9rj423xuug7jk02c82xc0qjarl33aw68380hwjm56ey4spgzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2zqchlk</id>
    
      <title type="html">Project Zero have finally got around to updating the blog to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdc4jh9rj423xuug7jk02c82xc0qjarl33aw68380hwjm56ey4spgzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2zqchlk" />
    <content type="html">
      Project Zero have finally got around to updating the blog to something less blogger-esc, check it out at &lt;a href=&#34;https://projectzero.google&#34;&gt;https://projectzero.google&lt;/a&gt;. To coincide with this momentous occasion I dug out the draft of my blog post about Windows Object Manager performance which became the basis of my article in PoC||GTFO #13 and updated it to see if it still worked in Windows 11. You can read it at &lt;a href=&#34;https://projectzero.google/2025/12/windows-exploitation-techniques.html&#34;&gt;https://projectzero.google/2025/12/windows-exploitation-techniques.html&lt;/a&gt;
    </content>
    <updated>2025-12-16T23:17:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgxa32tyjq8percexf3jmfkp28xd6j4q4kemv8whuq75ccdl2ezgszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2fmaemu</id>
    
      <title type="html">the most concerning part of admin protection&amp;#39;s design was ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgxa32tyjq8percexf3jmfkp28xd6j4q4kemv8whuq75ccdl2ezgszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2fmaemu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrdy2vrl3vw5y0vesc3muvty2dkejk2h8c9qhtmha0jw6zpc2vtwqtcgufe&#39;&gt;nevent1q…gufe&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;the most concerning part of admin protection&amp;#39;s design was just that UI Access seemed to not considered part of the boundary. Of the 9 bugs I reported, 5 were basically ways of getting control over a UI Access process and from there full admin. I think if you&amp;#39;re going to break app compat anyway you might as well have done something more than UAC with bells on it.
    </content>
    <updated>2025-11-23T17:35:50Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswauqyaz56tw0g2yc6psw9cnu8e38cdta77ccvlgydla96895h4yszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2vzlykm</id>
    
      <title type="html">I wasn&amp;#39;t imagining things, Administrator Protection has ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswauqyaz56tw0g2yc6psw9cnu8e38cdta77ccvlgydla96895h4yszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2vzlykm" />
    <content type="html">
      I wasn&amp;#39;t imagining things, Administrator Protection has indeed been pulled for now. &lt;a href=&#34;https://learn.microsoft.com/en-us/windows/security/application-security/application-control/administrator-protection/?tabs=intune#system-requirements&#34;&gt;https://learn.microsoft.com/en-us/windows/security/application-security/application-control/administrator-protection/?tabs=intune#system-requirements&lt;/a&gt;
    </content>
    <updated>2025-11-21T20:10:32Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsve7503c2rllm9rxxeahgkuejn6we8jqzvva2khz8zdvkw077xxaczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2x5nayk</id>
    
      <title>Nostr event nevent1qqsve7503c2rllm9rxxeahgkuejn6we8jqzvva2khz8zdvkw077xxaczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2x5nayk</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsve7503c2rllm9rxxeahgkuejn6we8jqzvva2khz8zdvkw077xxaczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2x5nayk" />
    <content type="html">
      Neat!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/539/153/487/976/845/original/2a90f7a4e81197fa.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-11-12T22:47:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsywd9rwf45d74dlrhrz5u0xnv0dtwtpn7sn4cjrfj39z2245y9gvczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2j62p7t</id>
    
      <title type="html">Administrator Protection has finally been released in KB5067036. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsywd9rwf45d74dlrhrz5u0xnv0dtwtpn7sn4cjrfj39z2245y9gvczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2j62p7t" />
    <content type="html">
      Administrator Protection has finally been released in KB5067036. This is an optional update, but it does fix 7 of the 9 issues that I reported to MSRC (hopefully the other 2 get fixed next month as security bulletins). I honestly don&amp;#39;t know if they&amp;#39;ve actually fixed the SSPI issues like my Kerberos bypass or not, I&amp;#39;m not inclined to check. People should kick the tyres on it, maybe there&amp;#39;s still some bounties to be had :D
    </content>
    <updated>2025-10-29T10:17:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszadhpuxen5evttxf5fm5cvek78ge4fd52e798rwfa76f62q60cdgzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2m83md7</id>
    
      <title type="html">unsafe BinaryFormatter usage has been on the shit list for at ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszadhpuxen5evttxf5fm5cvek78ge4fd52e798rwfa76f62q60cdgzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2m83md7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp4f9zwd67vwxyrcw36qak6aaa5y02e3pulddgc45jj3f7g6es2xgzyrcun&#39;&gt;nevent1q…rcun&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;unsafe BinaryFormatter usage has been on the shit list for at least a decade, this should have been found in less than a hour with grep. This should never have been in the code so long, it should have been audited out.
    </content>
    <updated>2025-10-24T18:48:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxqnhzhkwtp6cprrej3mdvufesf9ycwzw3fz4a2g6xqvvmmtu6chqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2e9zhac</id>
    
      <title type="html">honestly, just calling the bug RCE almost undersells the damage ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxqnhzhkwtp6cprrej3mdvufesf9ycwzw3fz4a2g6xqvvmmtu6chqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2e9zhac" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgesz23vpa6dpqug3cehul6p6plf74qhq7uhgtnx2a9ljnj0dx2yg3y69pl&#39;&gt;nevent1q…69pl&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;honestly, just calling the bug RCE almost undersells the damage this bug can do. Such as stupid bug as well.
    </content>
    <updated>2025-10-24T18:32:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsx9chw3uk6edg8xdgm4fxtahtrmmkvmudggfe5ndf93c7wcscjvnszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2mc3ull</id>
    
      <title type="html">Honestly, WTF Microsoft. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsx9chw3uk6edg8xdgm4fxtahtrmmkvmudggfe5ndf93c7wcscjvnszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2mc3ull" />
    <content type="html">
      Honestly, WTF Microsoft. &lt;a href=&#34;https://hawktrace.com/blog/CVE-2025-59287&#34;&gt;https://hawktrace.com/blog/CVE-2025-59287&lt;/a&gt;
    </content>
    <updated>2025-10-20T15:10:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstvwkwnkp73nmvhn4r3e6znlc5dql95ay97cpq8w3cgz64wfzw4wgzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2axwfk2</id>
    
      <title type="html">RE: https://infosec.exchange/@tiraniddo/115295709143228986 Well, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstvwkwnkp73nmvhn4r3e6znlc5dql95ay97cpq8w3cgz64wfzw4wgzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2axwfk2" />
    <content type="html">
      RE: &lt;a href=&#34;https://infosec.exchange/@tiraniddo/115295709143228986&#34;&gt;https://infosec.exchange/@tiraniddo/115295709143228986&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Well, Windows Administration Protection still hasn&amp;#39;t been released even though technically 25H2 has. So none of those 6 bypasses have been fixed, but then again there&amp;#39;s no code to bypass, so.... At least some of them are fun UAC bypasses :)&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1cqj47lfg4wm6ltvmef7grez484xg758lyatar8nykxsw9c4f9kfs8n0fdz&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1cqj…0fdz&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; Seems Windows 11 25H2 is finally rolling out, and they&#39;re shipping the new Administrator Protection feature. Hopefully MS should have fixed 6 bypasses I found in it during insider preview :D &lt;/blockquote&gt;
    </content>
    <updated>2025-10-15T15:20:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvqf2l0552hda04kdu5lypu32n6ny02rljw473nejtrg8zu25jmyczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2xjn2g6</id>
    
      <title type="html">Seems Windows 11 25H2 is finally rolling out, and they&amp;#39;re ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvqf2l0552hda04kdu5lypu32n6ny02rljw473nejtrg8zu25jmyczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2xjn2g6" />
    <content type="html">
      Seems Windows 11 25H2 is finally rolling out, and they&amp;#39;re shipping the new Administrator Protection feature. Hopefully MS should have fixed 6 bypasses I found in it during insider preview :D
    </content>
    <updated>2025-09-30T22:55:05Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqdset0jsyyhkvpwrfs6krtpjf96p9etxua3hjc5ry9nxl3y8mrzczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn26832jc</id>
    
      <title type="html">creative for sure, but I wonder if there&amp;#39;s not other places ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqdset0jsyyhkvpwrfs6krtpjf96p9etxua3hjc5ry9nxl3y8mrzczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn26832jc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd8zs4a0h5z4yqrsrs0f34tga0jqgm94xa3q4hhz4gddghxmml4egm9u2cx&#39;&gt;nevent1q…u2cx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;creative for sure, but I wonder if there&amp;#39;s not other places that could force a process to suspend at least if you already have admin access. Ultimately EDR lives and dies by it&amp;#39;s ability to catch the malware before it disables the EDR. Not sure how MS would fix this in the OS.
    </content>
    <updated>2025-09-24T06:22:59Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrzxv738dfxs82czq8rgahn8gghwa4e5ywc7w8dumzu9hfatnfmtczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2gmsdqm</id>
    
      <title type="html">Errata ID [sic] is just too complex for it&amp;#39;s own good. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrzxv738dfxs82czq8rgahn8gghwa4e5ywc7w8dumzu9hfatnfmtczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2gmsdqm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszcu0gzg8yz7z7dqyqwgkmpxq3tqsdyagds25cuthxqgaeupm6tdcpjhmrz&#39;&gt;nevent1q…hmrz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Errata ID [sic] is just too complex for it&amp;#39;s own good. It&amp;#39;s like they looked at AD, and went &amp;#34;What if more, and harder to reason about&amp;#34;, then bolted on on-prem AD connection for good measure.
    </content>
    <updated>2025-09-17T18:05:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr8rsaqas8fe5mncr7ty24z8qv8v6fun2e72yu2yusu2uzpyzzmagzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn28xvdde</id>
    
      <title type="html">such a valuable feature then, but I shouldn&amp;#39;t need to do ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr8rsaqas8fe5mncr7ty24z8qv8v6fun2e72yu2yusu2uzpyzzmagzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn28xvdde" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyttp90ydnsdptpn7ju0p2xfauve6ln6cvqxwf06y2cwumpy8c37qs5flv8&#39;&gt;nevent1q…flv8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;such a valuable feature then, but I shouldn&amp;#39;t need to do stupid approaches to bypass it. Honestly I wouldn&amp;#39;t really care if it blocked &amp;#34;adult content&amp;#34; in the feed, as that could always be disabled. But I have no idea what they were thinking when they decided that DMs were needing of age verification.
    </content>
    <updated>2025-08-13T11:57:32Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2f5w7t8cqsefgld32nrt23wtgnqp04vj6sc9cez2shzl9j2wgvqqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2n4lle9</id>
    
      <title type="html">While I&amp;#39;ve always focussed on using Mastodon I did try and ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2f5w7t8cqsefgld32nrt23wtgnqp04vj6sc9cez2shzl9j2wgvqqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2n4lle9" />
    <content type="html">
      While I&amp;#39;ve always focussed on using Mastodon I did try and give Bluesky a go, but the community doesn&amp;#39;t seem there and I never got much engagement on security topics. Bluesky&amp;#39;s decisions regarding the stupid UK&amp;#39;s Online Safety Act to make DMs locked behind age verification is the final straw, so I&amp;#39;ve deactivated the account and maybe it&amp;#39;ll get deleted eventually. I&amp;#39;ll go back to not posting anything exclusively on here :D
    </content>
    <updated>2025-08-13T11:37:06Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqnulvn5j84xfxzw8nmpxxh3t7e4pszje37dx2qh074mr2lszjz9qzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2d8ejhx</id>
    
      <title type="html">&amp;#34;Gone are the days of trying to memorize and remember file ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqnulvn5j84xfxzw8nmpxxh3t7e4pszje37dx2qh074mr2lszjz9qzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2d8ejhx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrhxwzgmjuzvadvt34kqaf57v3wqpeps8qfcx9ts03x2lgr6fy0ngdcm6hs&#39;&gt;nevent1q…m6hs&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&amp;#34;Gone are the days of trying to memorize and remember file names or exact words. With improved Windows search...&amp;#34; we can shove AI generated garbage straight from Bing to your eyeballs with no way of disabling any of it if all you wanted was finding your own files.
    </content>
    <updated>2025-04-25T19:39:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfm946lvtxzy8978xxve2v6c3x2mh3u65ly7n0pdyqhftz9wyqtgczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn26u3nq2</id>
    
      <title type="html">I still can&amp;#39;t quite believe _this_ was their fix.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfm946lvtxzy8978xxve2v6c3x2mh3u65ly7n0pdyqhftz9wyqtgczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn26u3nq2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsryre6dw2ne4jdv7xf9epykznsc96k96p9h9c39xu0xepdwdgu3rqd7lyy2&#39;&gt;nevent1q…lyy2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I still can&amp;#39;t quite believe _this_ was their fix.
    </content>
    <updated>2025-04-22T19:24:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstn26a9lfh2fdlnmju3xv0dnz70lvypssq3f2uh8k4r9ksqlf5ckszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2dk0ssw</id>
    
      <title type="html">I never managed to the get the updated version working on the ARM ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstn26a9lfh2fdlnmju3xv0dnz70lvypssq3f2uh8k4r9ksqlf5ckszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2dk0ssw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9jcryyt8jf04hlvc8990fl0sc7s0nekl3g06rdtcygp4r944yv8q46v7dd&#39;&gt;nevent1q…v7dd&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I never managed to the get the updated version working on the ARM CoPilot laptop I bought specifically for that purpose. I don&amp;#39;t know of any current write ups other than the puffery from MS.&lt;br/&gt;&lt;br/&gt;I&amp;#39;d certainly focus on the encryption, how it ties into Windows Hello, whether there&amp;#39;s any obvious bypasses and also whether you can still hoover up the details _if_ the user has unlocked it first (as in how hard is it to access the database once the key is available).
    </content>
    <updated>2025-04-17T15:28:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvxt8lax4aal4x0atnxklfufw5pj7cyt5sl73lcu6rusplnm75zvszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2e5aj64</id>
    
      <title type="html">The second blog is about an interesting bug class in COM servers ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvxt8lax4aal4x0atnxklfufw5pj7cyt5sl73lcu6rusplnm75zvszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2e5aj64" />
    <content type="html">
      The second blog is about an interesting bug class in COM servers that implement IDispatch, which allows you to potentially create other objects in the process. For example every OOP COM server with IDispatch allows you to create a STDFONT object which isn’t really designed to be safely used cross process. To demo its usefulness I then use the trick to get code injection in a Windows-PPL process from where you could open protected LSASS etc. &lt;a href=&#34;https://googleprojectzero.blogspot.com/2025/01/windows-bug-class-accessing-trapped-com.html&#34;&gt;https://googleprojectzero.blogspot.com/2025/01/windows-bug-class-accessing-trapped-com.html&lt;/a&gt;
    </content>
    <updated>2025-01-30T18:35:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsflpj5jzvefqjr9ku3jn3hufsq0j5ry2aahtsh2cv6zgvmuj8vpvszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2623rdu</id>
    
      <title type="html">A companion blog to my Bluehat 2024 presentation on OleView.NET ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsflpj5jzvefqjr9ku3jn3hufsq0j5ry2aahtsh2cv6zgvmuj8vpvszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2623rdu" />
    <content type="html">
      A companion blog to my Bluehat 2024 presentation on OleView.NET is up now. &lt;a href=&#34;https://googleprojectzero.blogspot.com/2024/12/windows-tooling-updates-oleviewnet.html&#34;&gt;https://googleprojectzero.blogspot.com/2024/12/windows-tooling-updates-oleviewnet.html&lt;/a&gt;
    </content>
    <updated>2024-12-12T23:32:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2gk2edfwz0ap28k3pt3t2e42tkljslxwy2zm50kt943ykgtud4nqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2mxp567</id>
    
      <title type="html">I had no idea they released Otomedius outside Japan, tis weird, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2gk2edfwz0ap28k3pt3t2e42tkljslxwy2zm50kt943ykgtud4nqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2mxp567" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9xa6myxsk8pdzx4kmkxphn5xkzc2620t6geezgqap3m2ju5vwpmg4nrhxh&#39;&gt;nevent1q…rhxh&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I had no idea they released Otomedius outside Japan, tis weird, but no less weird and kinky than its Parodius predecessor, especially Sexy Parodius :)
    </content>
    <updated>2024-12-09T14:05:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9g32lhtm8a3lfgasr84q8208ddk5r53lx52zjk5ynn9ccxawtmeqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn20armg4</id>
    
      <title type="html">FFS</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9g32lhtm8a3lfgasr84q8208ddk5r53lx52zjk5ynn9ccxawtmeqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn20armg4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvu6evs70ew8wzd8h0uw5eh9na760q445xdy60h6h6d0y5z43qxssc0e5m4&#39;&gt;nevent1q…e5m4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;FFS
    </content>
    <updated>2024-12-02T23:25:29Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswaw59tane02pa29rx34jc2ekhz50at9kmw0lm0g7aw9c7d2jrccczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2ag3qde</id>
    
      <title type="html">comical :D</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswaw59tane02pa29rx34jc2ekhz50at9kmw0lm0g7aw9c7d2jrccczypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2ag3qde" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst8qeqwmgaf0tm5vf9prtk0appk596qwueewdsxn23z4tl2qxj33g3dqreg&#39;&gt;nevent1q…qreg&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;comical :D
    </content>
    <updated>2024-11-29T16:19:09Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdj2ksjrrj25pyyhyrf37rceu82hc5rqa3hyx2mxl528hvj9vwg4czypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2657tvm</id>
    
      <title type="html">as far as I know mine doesn&amp;#39;t crash but it&amp;#39;s still yet to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdj2ksjrrj25pyyhyrf37rceu82hc5rqa3hyx2mxl528hvj9vwg4czypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2657tvm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswgah4l5c8h5zt59nuue6leaget3la6f94s2hww5z7qjgyjp0pv9g4uah6w&#39;&gt;nevent1q…ah6w&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;as far as I know mine doesn&amp;#39;t crash but it&amp;#39;s still yet to capture a single snapshot. I did take a look an the enclave binaries though, first (and minimal) pass seems it&amp;#39;s &amp;#34;maybe better&amp;#34;, at least no obvious bug assuming they&amp;#39;re using it correctly.
    </content>
    <updated>2024-11-29T03:52:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstfhnmp4vunxqdshy84rxul6lera9j0trg8kajy4f5rvsyeq0935qzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn238lglq</id>
    
      <title type="html">Awesome that MS are supported and documenting VBS enclaves ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstfhnmp4vunxqdshy84rxul6lera9j0trg8kajy4f5rvsyeq0935qzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn238lglq" />
    <content type="html">
      Awesome that MS are supported and documenting VBS enclaves properly now *apropos of nothing in particular*. &lt;a href=&#34;https://learn.microsoft.com/en-us/windows/win32/trusted-execution/vbs-enclaves-dev-guide&#34;&gt;https://learn.microsoft.com/en-us/windows/win32/trusted-execution/vbs-enclaves-dev-guide&lt;/a&gt;. Also awesome that in the example exported entry point they provide they don&amp;#39;t seem to mention how careful you need to be with the input pointer that you don&amp;#39;t just read/write enclave memory :)
    </content>
    <updated>2024-11-25T02:46:54Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstrl7dgc8sl5unpezcsuc95kmae2jupm4ggpc5ecjmc7lgrlkr3kszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2mj90eq</id>
    
      <title type="html">actually scratch that, it seems that this feature was removed ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstrl7dgc8sl5unpezcsuc95kmae2jupm4ggpc5ecjmc7lgrlkr3kszypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2mj90eq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxhswcgewq04wxdea4k5fzpfjwsx8ntxnn07e6e40qepdztv03chqjkz402&#39;&gt;nevent1q…z402&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;actually scratch that, it seems that this feature was removed from Windows 11, boo :|
    </content>
    <updated>2024-11-07T21:46:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxhswcgewq04wxdea4k5fzpfjwsx8ntxnn07e6e40qepdztv03chqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2qxqhd3</id>
    
      <title type="html">what would be fun is to deploy the undocumented ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxhswcgewq04wxdea4k5fzpfjwsx8ntxnn07e6e40qepdztv03chqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2qxqhd3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdhzlrn5s97m3556n9k7a668vv82lzzfl3eak0en52wzk9dz65nwcq3u34p&#39;&gt;nevent1q…u34p&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;what would be fun is to deploy the undocumented &amp;#34;adminless&amp;#34; mode through a code integrity policy. That basically disables the administrator group SID, so it might look like you&amp;#39;re an admin but only SYSTEM is really an admin :D
    </content>
    <updated>2024-11-07T21:39:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsx4g0wrrpqqvap0uv0rayul0u7ft0fq6a67dgkvkf08d9llj3hf8czypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2yef0vf</id>
    
      <title type="html">for now at least you can uninstall notepad (right click the start ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsx4g0wrrpqqvap0uv0rayul0u7ft0fq6a67dgkvkf08d9llj3hf8czypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2yef0vf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspxvqkd65ltlxn36gvl0uvxtamt9uqy3f73y93wpjpdmpl7hm5s6cd0czca&#39;&gt;nevent1q…czca&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;for now at least you can uninstall notepad (right click the start icon and choose uninstall) and it&amp;#39;ll revert to the classic version. How long that lasts I don&amp;#39;t know. Also it breaks it being used as a target for opening .txt files as modern explorer is garbage.
    </content>
    <updated>2024-11-07T15:43:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvznz9rn0cmes5rcszumke5rc5hycg4wsw7p9w2qnxe39wkdw2wmqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2fyqsf2</id>
    
      <title type="html">Put up the slides for my Bluehat 2024 presentation on ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvznz9rn0cmes5rcszumke5rc5hycg4wsw7p9w2qnxe39wkdw2wmqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2fyqsf2" />
    <content type="html">
      Put up the slides for my Bluehat 2024 presentation on improvements to OleView.NET &lt;a href=&#34;https://github.com/tyranid/infosec-presentations/blob/master/Bluehat/2024/DCOM%20Research%20for%20Everyone!.pdf&#34;&gt;https://github.com/tyranid/infosec-presentations/blob/master/Bluehat/2024/DCOM%20Research%20for%20Everyone!.pdf&lt;/a&gt; You can also grab v1.15 of OleView.NET from the PS Gallery which has the new features to generate proxy clients on the fly.
    </content>
    <updated>2024-10-31T01:39:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdlck69a7u4y35axg4ghha54dpeupz4hhk6mx070nvev3qettujjqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2uhcymz</id>
    
      <title type="html">The new Windows 11 Admin approval mode certainly needs some ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdlck69a7u4y35axg4ghha54dpeupz4hhk6mx070nvev3qettujjqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2uhcymz" />
    <content type="html">
      The new Windows 11 Admin approval mode certainly needs some tweaking. Currently you&amp;#39;re required to elevate taskmgr, which only used to be the case if you disabled auto-elevation. Why taskmgr starts elevated is one of Microsoft&amp;#39;s many dumb decisions in Windows 10.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/309/383/889/473/450/original/d025c40fa17de73e.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-10-15T03:47:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9dknaxvuf659mngvvgt3v5knepl8zmff0fw0xmgz8qwl8ja6qmuqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2ewy96t</id>
    
      <title type="html">Now this is interesting, Windows 11 24H2 allows you to connect to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9dknaxvuf659mngvvgt3v5knepl8zmff0fw0xmgz8qwl8ja6qmuqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn2ewy96t" />
    <content type="html">
      Now this is interesting, Windows 11 24H2 allows you to connect to an SMB server with an arbitrary TCP port. Could come in handy ;-)&lt;br/&gt;&lt;a href=&#34;https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-alternative-ports-now-supported-in-windows-insider/ba-p/3974509&#34;&gt;https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-alternative-ports-now-supported-in-windows-insider/ba-p/3974509&lt;/a&gt;
    </content>
    <updated>2024-10-02T09:35:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswu76977q7rhgczzreh2w2s0smdesavdszc9r0z57sta0h482s6kqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn28ahty7</id>
    
      <title type="html">from the article &amp;#34;a sentencing hearing was postponed for a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswu76977q7rhgczzreh2w2s0smdesavdszc9r0z57sta0h482s6kqzypcx4qnq5mw6gmaasyc8d37lwpe2nsja36vj096wnvwg7rtfs7mn28ahty7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdywg5usls5nwhzhcu0uqjrsz2eg6fsf886alf2qel2avkz9wk8zcwztwxy&#39;&gt;nevent1q…twxy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;from the article &amp;#34;a sentencing hearing was postponed for a 12-year-old boy who admitted taking part in two separate incidents of disorder in Manchester because his mother had gone on holiday to Ibiza&amp;#34;. Hmm I wonder what could possibly be the root problem of the boys misdeeds?
    </content>
    <updated>2024-09-02T17:36:33Z</updated>
  </entry>

</feed>