Make a deal with Maxim Suhanov
🔒 Paid proposals held safely in escrow — released only when the work's approved.
Known for
2 views
Unfortunately, this paper from 2017 is still relevant.
https://github.com/MotherOfAllVoids/bachelor_thesis/blob/master/text/flaw.pdf
1. BestCrypt Volume Encryption (BCVE) allows watermarking attacks.
2. BCVE allows plaintext injection attacks.
3. BCVE allows forced decryption of some sectors.
It doesn't matter that AES-XTS is used, the vulnerability is in the function wrapping encryption/decryptio
2 views
According to Microsoft (MSRC), attacks involving symlinks stored on removable drives or in file system images (like VHDX) are not vulnerabilities.
If an unprivileged user manages to quickly replace a regular file in such a location with a symlink to another file (can point anywhere, even into the C:\Windows directory), this is okay.
This means that attackers can defeat existing symlink mitigations
📊 Post engagement
🔥 Top post: CrashXTS (CVE-2025-21210): a practical randomization attack agai · 13 likes + reposts
📊 Activity & format
Recent posts
View on Mastodon ↗
Most FDE vendors/projects don't consider vectors requiring repeated physical access as a vulnerability.
But there is another side to this: an HDD/SSD firmware backdoor (or a network attacker injecting arbitrary data into a disk image boote…
CVE-2024-13745 in EDK II (likely, "WONTFIX"): "what you measure is not what you use".
The story about firmware measuring bytes different from ones being used. It affects PCR[5], so the severity is low (nobody cares about PCR[5] by default)…
NotCVE-2026-0002: if you run two NetScalers in the high availability (HA/HA-INC) deployment, no SSH host key checks are performed between them, even when you followed every advice listed here: https://docs.netscaler.com/en-us/netscaler-adc…
My story of recovering cleared RDP logs from a completely unrelated EVTX file: https://dfir.ru/2026/01/26/windows-event-logs-were-cleared-but-resurrected-in-another-file/ #DFIR
My long post about wide-block & AEAD modes in full-disk encryption: it cover threat models, vulnerabilities, and edge cases.
Key points:
- It's common for FDE implementations to fail outside of the encryption layer.
- Wide-block modes don'…
Unfortunately, this paper from 2017 is still relevant.
https://github.com/MotherOfAllVoids/bachelor_thesis/blob/master/text/flaw.pdf
1. BestCrypt Volume Encryption (BCVE) allows watermarking attacks.
2. BCVE allows plaintext injection atta…
My blog post and a PoC disk image are here: https://dfir.ru/2025/02/23/symlink-attacks-without-code-execution/
According to Microsoft (MSRC), attacks involving symlinks stored on removable drives or in file system images (like VHDX) are not vulnerabilities.
If an unprivileged user manages to quickly replace a regular file in such a location with a …
It seems that GRUB developers decided to disable many file system drivers (JFS, NTFS, UDF, etc.) when the Secure Boot lockdown is on.
https://git.savannah.gnu.org/cgit/grub.git/commit/grub-core/fs?id=c4bc55da28543d2522a939ba4ee0acde45f2fa74
Five vulnerabilities in AMI file system drivers (NTFS, exFAT): https://dfir.ru/2024/12/09/multiple-vulnerabilities-in-ami-file-system-drivers/
The vendor was fixing one of them for more than two years!
🐘 Community & instance
💡 Facts
🕵️ Fake follower check
Estimated- Est. 97% real, active audience · Low fake-follower risk.
- Strong engagement (~4.4% of followers engage each post) — an active, real audience.
- Established account (3+ years old).
Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.
About
📸 Gallery
🔀 Audience overlap
EstimatedEstimated shared audience with similar creators — useful for avoiding overlap (or doubling down) when planning a campaign.
More like this
Find more →✉ Message Maxim Suhanov
Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.
- ✓ Message any influencer from their listing
- ✓ The influencer gets notified by email
- ✓ Manage every conversation in one inbox
Already Pro? Log in.
🎤 Event / appearance with Maxim Suhanov
Booking an event / appearance is a Pro feature. Upgrade to book Maxim Suhanov for an in-person or virtual appearance — payment held safely in escrow until the event is done.
- ✓ Book them for events, livestreams, panels & more
- ✓ Maxim Suhanov gets notified by email
- ✓ Fee held in escrow, released after the appearance
Already Pro? Log in.
You're out of free requests this month
Free accounts get 5 per month. Go Pro for unlimited sponsor pitches, collab requests & sponsorship deals — plus featured placement, the Verified badge, free withdrawals and more.
Upgrade to Pro — $9.95/mo →Your free limit resets on the 1st of next month.
Auto-generated from Mastodon's public data — no affiliation with or endorsement by SocialDB. Is this you? Claim it · Remove