Openwall
@Openwall
Followers
7K
Following
3
Media
2
Statuses
383
Infosec focused free software, research, publications, community activities @oss_security. Tweets are announcements. Please direct questions to @solardiz.
Joined June 2010
At #NullconBerlin2025, @solardiz unpacked how Linux Kernel Runtime Guard (LKRG) 1.0 brings real-time integrity checking & exploit detection to the Linux kernel, even across different versions & edge-case environments. Watch Now: https://t.co/VPX5t7FbcF
#LKRG #LinuxSecurity
1
6
14
What should @Openwall's simpler vulnerability scoring system (CVSS alternative) be called? Note that we already have OVE https://t.co/ZcLav61N41 as a CVE alternative, but unfortunately the OVSS acronym already has a bit of use in CS/AI for "open-vocabulary semantic segmentation".
2
1
1
Hash Suite 4.0 (Windows) adds support for custom Python scripts as key-provider, updated wordlists to download, better high-resolution support, and should have fewer antivirus false positives.
0
2
4
We've just published the slides of @solardiz's @Nullcon Berlin 2025 talk "Linux Kernel Runtime Guard (LKRG) 1.0" https://t.co/gIj8vDjs1A
#LKRG #nullconBerlin2025 #nullcon
0
17
38
The latest Microsoft Research Forum episode is now available on-demand. Explore purposeful research and its real-world impact.
9
14
146
Linux Kernel Runtime Guard @lkrg_org 1.0.0 by @Adam_pi3 @solardiz @kerneltoast et al. is out, adds support for Linux 6.13+ (tested to 6.17-rc4), forward-edge CFI (Intel CET IBT, KCFI), ..., reduces performance overhead, shrinks the codebase by ~2500 lines.
Heading to Nullcon Berlin 2025? @solardiz will share his LKRG expertise by taking an in-depth look at kernel hardening challenges and what it takes to protect systems in the real world. https://t.co/QSiQzQyrK6
#NullconBerlin2025 #LinuxSecurity #RLC_H
0
8
19
At #NullconBerlin2025, @solardiz will walk us through the journey from LKRG’s edgy debut to its 1.0 release – complete with real-world attacks, trade-offs, nasty bugs, & some honest truths about kernel hardening. Know More: https://t.co/zApTl1QVhx
#LKRG #LinuxSecurity
1
6
14
End of an era: our CVSweb service turned 21 today, and was promptly retired. Our anoncvs was similarly shut down at the age of 21 two years ago, quietly.
All of our projects previously maintained in CVS are now in Git (yes, older ones with commit histories for ~20 years) and under the Openwall organization on GitHub. There are a total of 22 Git repositories now. https://t.co/wlAWzBrE2G
0
3
12
🔒 Enhancing LKRG: A Step Toward Stronger Security. CIQ's own Sultan Alsawaf recently contributed impactful updates to the LKRG project, fixing longstanding bugs & making it stronger & more stable than ever. Learn more here 🔗 https://t.co/M7XYMUqLEh
#HPC #IT #LKRG #OpenSource
0
6
8
I'm happy to build upon and extend the ideas and approaches we had tested and proven, and expertise gained building @Openwall's security enhanced Linux distribution, now for @CtrlIQ's wider audience and in a modern context.
📣 Exciting news from CIQ! 📣 Announcing Rocky Linux from CIQ - Hardened! Read the press release: https://t.co/7c0UicklQz
#RLCHardened #RLC #RockyLinux #CIQ #SysAdmin #ProductLaunch
1
7
18
Linux Kernel Runtime Guard @lkrg_org 0.9.9 by @Adam_pi3 et al. is out, adds support for Linux 6.11+, 6.10.10+, 5.10.220+, CentOS Stream 9 (upcoming RHEL 9.5). https://t.co/EoLLUSgHYO Updated packages for Rocky Linux 9.4 and 8.10 being released https://t.co/65yCiBdt1S
@rocky_linux
1
5
22
We sponsored the porting of the yescrypt Linux password hash algorithm to Go as an open source project. Read more below. This is now part of our agentless password auditor feature on Linux as well.
Announcing yescrypt-go, our pure Go reimplementation of yescrypt key derivation function (KDF) and password hashing scheme. Builds upon @dchest's Go scrypt, with yescrypt support added by @solardiz. Sponsored by @SandflySecurity. https://t.co/ATOv8KMSKl
https://t.co/glYvhP3se6
1
3
11
Announcing yescrypt-go, our pure Go reimplementation of yescrypt key derivation function (KDF) and password hashing scheme. Builds upon @dchest's Go scrypt, with yescrypt support added by @solardiz. Sponsored by @SandflySecurity. https://t.co/ATOv8KMSKl
https://t.co/glYvhP3se6
Sandfly 5.1.1 features yescrypt support for our agentless Linux password auditor, new detection modules for debugger activity, and an important performance fix for the database. Read more about these new features below: https://t.co/BDfPmydrgN
0
6
12
Updated my @offensive_con keynote talk slides page to include links to our other related presentations https://t.co/PPRzSPS0YT
Just published slides of @solardiz's @offensive_con keynote talk "Password cracking: past, present, future"
1
23
60
Just published slides of @solardiz's @offensive_con keynote talk "Password cracking: past, present, future"
0
14
39
Just Announced! Gundam Premiere Night featuring both Iron-Blooded Orphans Urdr-Hunt + Wedge of Interposition, followed by the 4K remaster of Gundam Wing Endless Waltz Special Edition! Each film will feature brand-new intro create just for this release. Coming January 2026!
1
39
227
Is Open Source focused threat intelligence - Tactics, Techniques, and Procedures (TTPs), Indicators of Compromise (IOCs), exploits/rootkits/backdoors in the wild - a desirable topic for oss-security or for a separate mailing list? If separate, where to draw the line (reply)?
1
3
5
CVE-2024-31497: PuTTY: Secret Key Recovery of NIST P-521 Private Keys Through Biased ECDSA Nonces https://t.co/uVOkwMX3Aw Affected Products - PuTTY 0.68 - 0.80 - FileZilla 3.24.1 - 3.66.5 - WinSCP 5.9.5 - 6.3.2 - TortoiseGit 2.4.0.2 - 2.15.0 - TortoiseSVN 1.10.0 - 1.14.6
1
49
118
@solardiz @Adam_pi3 @lkrg_org
https://t.co/uQpq1nmB8q (with the kernel_path fixed) gives me a root shell on a fully patched Debian 12. But with LKRG loaded I see
1
6
9