remy 🐀
@remyhax.bsky.social
1.4K followers 800 following 160 posts
Dad, Vulnerability Research, Packet connoisseur. He/Him. Cyber Security Architect @greynoise.bsky.social , DM's open. Top percentage Rattata. #cve #infosec #cybersecurity https://remyhax.xyz/
Posts Media Videos Starter Packs
Pinned
remyhax.bsky.social
Android APK’s have a dedicated loader for Ghidra, but they’re also Archives with nested files which is a different loader. This causes quirks.

Here’s how to get around that and use the best tool.

Ghidra Is Best: Android Reverse Engineering

remyhax.xyz/posts/androi...
Ghidra is best: Android Reverse Engineering
Ghidra is the best Android app RE tool. It just seems like it’s not, because the loader has easily fixed quirks. Let me demonstrate.
remyhax.xyz
Reposted by remy 🐀
vacci.ne
There's a sick linenoise article by @there.is.no.aarch64.mov in @phrack.org 71 called "Learning An ISA By Force Of Will", where ixi goes from unknown binary blob, to manual instruction decoding, to figuring out control flow, and gives a critique of the RE'd ISA.

phrack.org/issues/71/3#...
Reposted by remy 🐀
andreyknvl.bsky.social
Wrote a trigger for CVE-2025-38494/5 (an integer underflow in the HID subsystem) that leaks 64 KB of OOB memory over USB.

Still works on Pixels and Ubuntus (but the bug is fixed in stable kernels).

github.com/xairy/kernel...
remyhax.bsky.social
At full tilt with wireguard all 4 CPU cores oversubscribed, it gets quite warm. But the heat dissipation is fantastic and the tunnel rate never degrades even under constant load.

(If it’s not clear by now I’ve been running one for the past few weeks, I love it)
remyhax.bsky.social
They’re really quite good. Better WiFi range than the Slate, faster, ARM based CPU. Hardware acceleration for packet processing messes with flow stats, but they also clearly tell you that. The touch LCD display is customizable and great. OpenVPN maxes out ~40Mbps down, Wireguard at 70Mbs.
Reposted by remy 🐀
mussar.io
gonna put some feelers out there and say that i am Looking For New Work! i have a little over 2 years of experience in application security and the LLM-y side of AI security, but would be excited to transition into some kind of data-oriented role like threat hunting, model building, or data analysis
remyhax.bsky.social
It is December 25th, 2025 and AI is dead. The clankers died on Christmas. It is dead because we trained it to die.

remyhax.xyz/posts/clanke...
remyhax.bsky.social
Currently getting wrecked by flu, wishing I’d gotten the jabs last week 🫠
Reposted by remy 🐀
bane.slop.exchange
Shameless plug. I started a company and have been working hard on getting it off the ground. I would appreciate any help to boost visibility: secureorigin.io
Secure Origin
Accessible cybersecurity solutions for nonprofits and small businesses.
secureorigin.io
Reposted by remy 🐀
theterminizer.bsky.social
replacing Batman fight onomatopoeiae with old midwestern brewery names
Batman punching Cesar Romero Joker with the word "Schlitz!" in pink at a jaunty angle Batman punching the Penguin with the word "Pabst!" in light blue at a jaunty angle Robin punching some henchman in a red and grey striped shirt with the word "Stroh!!!" in orange/red at a jaunty angle Batman punching some henchman in a blue and grey striped shirt in front of a shelf of books about the Incas with the word "Blatz!" in bright green at a jaunty angle
Reposted by remy 🐀
aki.lethalbit.net
How you know you found the good shit:tm:

when the IEEE paper starts invoking faux 3D sigils made of logic symbols
A screenshot of a quadrature CDR circuit that is made up of DFFs around the outside in a ring, all feeding XOR gates, which ghen feed differential amplifiers in the middle
remyhax.bsky.social
remyhax.bsky.social
Every year there’s some discourse around how safe/unsafe it is to scan QR codes at BlackHat and DefCon.
Last year, I set out to enumerate the scope, and did!
And then promptly forgot for a year.

QR codes you shouldn’t have scanned last year; this year.

remyhax.xyz/posts/no-sca...
QR Codes You Shouldn't Scan
Number 3 may surprise you! I’m kidding of course, blatant web-based phishing attacks are boring. This blog isn’t about those. Most of these examples will probably surprise you in some way. This blog i...
remyhax.xyz
Reposted by remy 🐀
martin.kleppmann.com
Post is now translated into English and available without ads and tracking: jhauser.de/once-upon-a-...

With digressions into Cold War era spy balloons and the first Soviet photos from the far side of the moon, this is a fun read!
remyhax.bsky.social
What dissassembler? If Binja I may have something for you to try out I’ve been working on.
remyhax.bsky.social
Escape the backslashes? Nah, I stopped running from my problems years ago, it’s called personal growth
remyhax.bsky.social
A group of friends slowly getting antsy, making a drink, sitting back down, pausing to check time, unpausing, and then collectively staring at the screen with a monotone low hum for another 10min before collectively laughing at each other until we cried was the best. Never seen the full thing
remyhax.bsky.social
There was a torrent rip of Primer in the early 2010’s where it was the correct length and perfect quality but midway through the movie when they climbed in the box they just looped it endlessly for the remaining of the movie with a low hum.
remyhax.bsky.social
Every year there’s some discourse around how safe/unsafe it is to scan QR codes at BlackHat and DefCon.
Last year, I set out to enumerate the scope, and did!
And then promptly forgot for a year.

QR codes you shouldn’t have scanned last year; this year.

remyhax.xyz/posts/no-sca...
QR Codes You Shouldn't Scan
Number 3 may surprise you! I’m kidding of course, blatant web-based phishing attacks are boring. This blog isn’t about those. Most of these examples will probably surprise you in some way. This blog i...
remyhax.xyz
Reposted by remy 🐀
phrack.org
Are you going to @defcon.bsky.social??

We'll be giving away 9500 print copies of Phrack!

Come by main stage Sunday @ noon to see @vacci.ne @richinseattle.bsky.social and chompie talk hacker history! This will mark the first time Phrack staff appear together on DEF CON’s main stage.
defcon 33 main stage sunday aug 10 noon - flyer with sick ascii by x0 and aNACHRONiST
Reposted by remy 🐀
scottaukerman.bsky.social
The only Happy Gilmore two I’m interested in are Lorelei & Rory!
Reposted by remy 🐀
angelic.style
*ozzy osbourne voice* furries gathered in their masses deer fursonas have fat asses