Enderman
βœ”
5.8K subscribers
388 photos
25 videos
7 files
140 links
A software engineer, a malware enthusiast and most importantly, a weird tall creature.

https://enderman.ch
https://youtube.com/endermanch
Download Telegram
πŸͺŸ The Windows Paradox

The further I'm into Windows research, the more I respect Windows. People calling it Β«slow bloatwareΒ», following up with the all-time classic β€” comparing it to Linux really are clueless.

For example, the deployment system is ridiculously solid, though the features are hidden to an ordinary user. From what I can tell, the focal point Microsoft has been improving on for the last 10 years is the enterprise management system.

Windows in general could be better. It's a shame it isn't. So much wasted potential.

It makes sense β€” enterprises make them money πŸ’°πŸ’Έ
Please open Telegram to view this post
VIEW IN TELEGRAM
❀97πŸ‘43πŸ€”22🀬8πŸ‘Ž4😱1
πŸ‘171😱38❀29πŸ€”8πŸŽ‰4πŸ‘Ž3🀬2😒1
Enderman
This media is not supported in the widget
VIEW IN TELEGRAM
πŸŽ‰159🀬36πŸ‘Ž24😒12❀6πŸ‘5πŸ€”5
Enderman
⛔️ The Giveaway

I'll make sure to never ever host a giveaway again... Telegram is really stupid. 8K botted subscribers that I can't even ban from the channel...
😒262🀬34❀20πŸ‘18😱9πŸ‘Ž6πŸŽ‰2
πŸͺŸ Windows 10 security updates will become paid

Microsoft will offer Extended Security Updates for Windows 10 starting at $61 for the first year.

That's nothing new from Microsoft, but it symbolizes the end of support inevitably looming over...
Please open Telegram to view this post
VIEW IN TELEGRAM
🀬167😒19πŸ‘Ž12πŸ‘9πŸ€”9πŸŽ‰7❀3😱2
πŸͺŸ The Β«User Choice ProtectionΒ» driver

Microsoft blocks third-party tools from setting the default browser again, now using the Β«User Choice ProtectionΒ» driver.

That's a really aggressive measure not seen before.
Please open Telegram to view this post
VIEW IN TELEGRAM
🀬171😱21πŸ‘Ž8😒6πŸ‘4πŸ€”3❀1
😱160😒25❀16🀬4πŸ‘1πŸ€”1
Enderman
Photo
🀬96😒49😱21πŸ€”8πŸ‘7πŸŽ‰2πŸ‘Ž1
Enderman
Photo
🐧 LeBron can't stop fumbling everything

Someone on Twitter asked me to make the Linux version, so they shall receive πŸ˜„
πŸ‘115😱38❀20😒7πŸ€”6🀬6
This media is not supported in your browser
VIEW IN TELEGRAM
sandwich pisi
❀236😱16πŸŽ‰5πŸ‘2
❀144😱24πŸ€”16πŸ‘10
πŸ‘€ .com executables in Windows 11

There is still a handful of seemingly MS-DOS .com executables in Windows 11.

However, if you run them, they execute and operate normally. So, what's the deal?

Well, what's left of them is just an extension. I analyzed the executables, and they all have a PE+ 64 header (PE + 0x6486 little-endian at offset 0xE8 and 0x0B02 little-endian at offset 0x100), meaning they're all modern 64-bit applications.

By all definitions, these applications should have an .exe extension, but they still have .com at the end. That doesn't stop them from executing or break anything, but it's a wrong extension to use.
πŸ‘72😱17❀11πŸ€”9
πŸ“© why are .com extensions applications supporting 64 bit tho???

The biggest misconception about files in Windows is that extensions are important, and somehow define whether the file runs or not. In reality, extensions are purely cosmetic. You can register parsers for your very own extensions within the registry (HKLM\Software\Classes ← HKCR) and set verbs and rules for Windows Explorer to follow when it stumbles upon your file association. That's the whole idea of extensions in Windows β€” to let Windows Shell automate passing the file over to the executable for you. There are protocols too, which Microsoft seem to be more fond of lately... (hello, Android content providers?)

No matter the extension, the contents of the file remain the same, and if the file has executable contents within it, you can run it. In fact, I suggest you try changing the extension of any executable you wish to .jpg and then run that JPEG-file from a command line.

The only difference for Β«executable filesΒ» in Windows is that they are the command that runs upon execution. NoEscape (does anyone even remember that?) leverages the registry nature of the executable file association. It sets up a pass-through executable that runs malicious code, but then follows up with running the original executable. Sneaky. It's called a companion virus. Neshta.A is a great example too.

Shell extensions are sort of similar in fashion. You can check my blog post out if you want to know the basics.
πŸ‘57πŸ€”10❀6🀬1πŸŽ‰1
πŸ’» Customer-friendly design

Meet Fujitsu Lifebook U904 (2013). This bad boy completely defies the corporate rule of Β«if it doesn't fit, it isn't includedΒ». They managed to achieve this by making the Ethernet port... foldable.

While the construction is certainly not network admin friendly, and isn't going to last an exceedingly long time, it's far better than no port at all!

Remember this post when a corporation like Apple uses thinness as an excuse to strip your product of features or make you buy overpriced dongles! πŸ˜‰
❀148πŸ‘22😱8πŸŽ‰6
Enderman
Photo
This media is not supported in your browser
VIEW IN TELEGRAM
Here is how the foldable port works!
😱138❀41πŸ‘13πŸŽ‰5πŸ‘Ž3πŸ€”1
😒130❀63🀬17πŸ‘11πŸ€”11😱10πŸŽ‰7πŸ‘Ž3
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸ‘65❀14😱7πŸ€”4πŸ‘Ž3
This media is not supported in the widget
VIEW IN TELEGRAM
🀬112❀11😱11πŸ€”4πŸ‘2