/explore

Click through on any links that interest you or select the planets on the right to continue exploring the Outer Web.
You are here

nullprogram.com
| | coredumped.dev
5.5 parsecs away

Travel
| | In this post, we are going to take a deep dive into pointer tagging, where metadata is encoded into a word-sized pointer. Doing so allows us to keep a compact representation that can be passed around in machine registers. This is very common in implementing dynamic programming languages, but can really be used anywhere that additional runtime information is needed about a pointer. We will look at a handful of different ways these pointers can be encoded and see how the compiler can optimize them for diff...
| | cardaci.xyz
5.3 parsecs away

Travel
| | A subtlety of the ptrace system call can be used to prevent a program from being debugged on macOS.
| | eyakubovich.github.io
5.7 parsecs away

Travel
| | I recently put a kprobe using eBPF for a function that accepts 8 parameters. The trouble is that BPF_KPROBE macro can only handle functions with up to 5 parameters but I was interested in most of them. It took a bit of fiddling to get to all of them and...
| | mandiant.github.io
19.5 parsecs away

Travel
| [AI summary] capa is an open-source tool developed by the FLARE team to identify capabilities in executable files through static and dynamic analysis, supporting various reverse engineering platforms.