VessOnSecurity's Avatar

VessOnSecurity

@vessonsecurity

Anti-virus, malware and infosec expert, crypto amateur, privacy advocate and general annoyance. PGP keyID: 0x365697c632dd98d9

315
Followers
27
Following
565
Posts
07.12.2023
Joined
Posts Following

Latest posts by VessOnSecurity @vessonsecurity

Fun fact: I had disassembled the whole of Apple ]['s DOS 3.3 and knew what every single byte of it did. But Windows? Aw, fugeddabaoutit.

08.03.2026 16:35 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Declaring that a C function has no parameters and/or return value.

08.03.2026 08:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

It's mostly macro viruses, because this was my area of responsibility at the time. There is some script stuff, and some "other platforms" - this is where the WANK variants came from. No Morris Worm, though, dunno why. Do you have the DECNet Father Christmas worm? Not CHRISTMA EXEC, the other one.

06.03.2026 16:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

There might have been others - but nothing as widespread in the wild to be the thing that actually hit you; mostly rare stuff found collections.

06.03.2026 07:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Client Challenge

I can't find my Symbian virus collection right now, but take a look at this:

www.scribd.com/doc/81472223...

It's a pretty complete list of Symbian malware with the name of the SIS file after the "!-". (The name of the malware is before it.)

06.03.2026 07:47 πŸ‘ 1 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

I mean, this is what the phone would show you - even before the virus is installed, run, and shown any messages - so it's something you'd see in any case.

03.03.2026 06:30 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Can you remember the name of the SIS file that you received via Buletooth? Cabir was *very* widespread and there were many variants of it but there were others, too; the name of the file might help me figure out which one it was.

02.03.2026 22:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

It underwent rapid unscheduled disassembly?

02.03.2026 12:49 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Mar 01 9:41 AM PST We want to provide some
additional information on the power issue in a
single Availability Zone in the ME-CENTRAL-1
Region. At around 4:30 AM PST, one of our
Availability Zones (mec1-az2) was impacted by
objects that struck the data center, creating
sparks and fire.

Mar 01 9:41 AM PST We want to provide some additional information on the power issue in a single Availability Zone in the ME-CENTRAL-1 Region. At around 4:30 AM PST, one of our Availability Zones (mec1-az2) was impacted by objects that struck the data center, creating sparks and fire.

June 2023: a Google data center in France floods and they call it a β€œwater intrusion event”

February 2026: an Amazon data center in the Middle East is literally struck by a fucking ballistic missile in a hot war and they call it β€œimpacted by objects”

https://health.aws.amazon.com/health/status

02.03.2026 09:51 πŸ‘ 59 πŸ” 30 πŸ’¬ 4 πŸ“Œ 2

Those 100 or so children that were killed in an Israeli airstrike in Iran. They all had names. They had parents, siblings and perhaps pets. They had best friends. They had dreams, frustrations and anxieties. They had moments of utter happiness. And each of them was someone else's everything.

01.03.2026 06:24 πŸ‘ 52 πŸ” 18 πŸ’¬ 1 πŸ“Œ 1

Reminds me of an old joke:

- How are you?
- How should I know; I haven't talked to my doctor yet.

01.03.2026 06:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Why, do you have in mind another country that needs bombing?

28.02.2026 14:18 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

In hindsight, expanding executive powers to normalize presidents unilaterally approving foreign strikes was a bad idea. But in midsight and foresight it was also a bad idea.

28.02.2026 13:27 πŸ‘ 239 πŸ” 39 πŸ’¬ 2 πŸ“Œ 3

Tell me about it... It still thinks that my first name is Vaseline.

27.02.2026 15:53 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Download cloner.asm | LimeWire Download cloner.asm on LimeWire

BTW, I see that you have the disassembly of the Elk Cloner there. I used to know the Apple ][ environment (6505 assembler, DOS, BIOS, etc.) rather well; if you're interested in my commented disassembly of it, here it is:

limewire.com/d/cwGjX#fguw...

25.02.2026 19:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Download WANK.ZIP | LimeWire Download WANK.ZIP on LimeWire

Nope, Google won't let them through. Try this:

limewire.com/d/LcfBK#p1xL...

25.02.2026 19:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Sent. Let's see if Google will let them through. Couldn't password-protect the archive because it rejects such archives no matter what's in them.

25.02.2026 18:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Wait, I found it. "Them", actually - I have 2 different variants of the worm. Found it on a DVD containing my old script and macro collection. How would you like me to send them? They definitely need to be preserved for posteriority. I won't be around much longer... I'll contact VX Underground too.

25.02.2026 18:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0
Post image

No, I've never seen the full thing - only the ASCII art from it that everybody quotes. The Oberman paper contains a few other lines from it too but not the full source. I can send you the paper, if you want. I'll also ask Ken van Wyk, but he's unlikely to have it, either.

25.02.2026 17:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Two stories next to each other: from CNN 'Pentagon threatens to make Anthropic a pariah if it refuses to drop Al guardrails', and from New Scientist: 'Als can't stop recommending nuclear strikes in war game simulations Leading Als from OpenAl, Anthropic and Google opted to use nuclear weapons in simulated war games in 95 per cent of cases'

Two stories next to each other: from CNN 'Pentagon threatens to make Anthropic a pariah if it refuses to drop Al guardrails', and from New Scientist: 'Als can't stop recommending nuclear strikes in war game simulations Leading Als from OpenAl, Anthropic and Google opted to use nuclear weapons in simulated war games in 95 per cent of cases'

Just leaving these two stories next to each other.:
'AIs can’t stop recommending nuclear strikes in war game simulations' & 'Pentagon threatens to make Anthropic a pariah if it refuses to drop AI guardrails'
www.newscientist.com/article/2516... edition.cnn.com/2026/02/24/t...

25.02.2026 12:53 πŸ‘ 41 πŸ” 27 πŸ’¬ 3 πŸ“Œ 2
Preview
Large-scale online deanonymization with LLMs We show that large language models can be used to perform at-scale deanonymization. With full Internet access, our agent can re-identify Hacker News users and Anthropic Interviewer participants at hig...

And right on schedule: there goes pseudonymity on the Internet. arxiv.org/abs/2602.16800

25.02.2026 00:37 πŸ‘ 96 πŸ” 61 πŸ’¬ 4 πŸ“Œ 12
Preview
Our Search Party: Finding a Ring Bounty Winner People who own doorbell cameras bought them, in part, to keep people out of their homes. As long as their video footage is stored on corporate servers, consumers could inadvertently be letting others ...

The Fulu Foundation is offering a $10,000 bug bounty to security researchers to hack Ring cameras and disable their Amazon data sharing feature

fulu-foundation.ghost.io/our-search-p...

22.02.2026 00:53 πŸ‘ 17 πŸ” 11 πŸ’¬ 0 πŸ“Œ 0

It shows. Bad trigger discipline.

22.02.2026 06:15 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Single vaccine could protect against all coughs, colds and flus, researchers say A Stanford University team have tested their nasal spray vaccine in animals but still need to do human clinical trials.

Best case, IF it works, it's a stop-gap solution at the start of an epidemic to reduce spread/mortality/etc. until a proper vaccine is developed and distributed.

BBC article:

www.bbc.com/news/article...

20.02.2026 22:57 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

BBC had an article about this vaccine. It's... problematic. To begin with, it's been tested only on mice - we don't know if it will work the same on humans. Second, it is very short duration - a few months. Third, the heightened state of the immune system it stimulates might be harmful sometimes.

20.02.2026 22:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Too easy to take down. Use a Russian bulletproof hoster instead.

17.02.2026 06:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

That's strange; all Chromium browsers (not just Chrome but also Edge, Brave, etc.) use the Windows system emoji font. (That's why they don't have country flag emojis, unlike Firefox, unless you install an emoji swapping add-on.) I mean, it's not anything new that has happened recently.

16.02.2026 19:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Standards

Obligatory XKCD:

www.xkcd.com/927/

15.02.2026 18:20 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
promethee UEFI Bindings for JavaScript (Proof of Concept)

How about UEFI bindings for JavaScript?

codeberg.org/smnx/promethee

13.02.2026 19:37 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I suggest watching the movie "The Internship". Intelligence agencies can use it as a teaching material - to teach new recruits how covert operations are NOT conducted.

13.02.2026 19:34 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0