Enderman – Telegram
Enderman
5.78K subscribers
373 photos
23 videos
7 files
133 links
A software engineer, a malware enthusiast and most importantly, a weird tall creature.

https://enderman.ch
https://youtube.com/endermanch
Download Telegram
🪟 Dark mode for the Windows 11 OOBE

This looks so... unbelievably... amazing. Now compare this to what we have now... the stale boring light theme.

Thanks, Wuigi!Source code
Please open Telegram to view this post
VIEW IN TELEGRAM
149👍28🎉11🤔3👎2😱2🤬2
🗂 Speeding up Windows Explorer

If the folder hasn't been explicitly determined in the registry before, the auto discovery feature makes Windows Explorer parse every single file in that folder, causing folders with thousands of files to load outrageously slowly. It also makes your HDD spin up whenever you enter such a folder.

To fix that atrocity, create a registry file with the following contents and execute it:
Windows Registry Editor Version 5.00

[Computer\HKEY_CURRENT_USER\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell]
"FolderType"="NotSpecified"


This registry «hack» works both on Windows 10 and Windows 11.
This is a crazy discovery that has already changed my life.
96👍21😱16🤔4👎2🎉2🤬1😢1
Please open Telegram to view this post
VIEW IN TELEGRAM
88🤔10👍6🤬3👎1🎉1
216😱72👍28🤔15🤬11😢6👎4
🪟 The Windows Paradox

The further I'm into Windows research, the more I respect Windows. People calling it «slow bloatware», following up with the all-time classic — comparing it to Linux really are clueless.

For example, the deployment system is ridiculously solid, though the features are hidden to an ordinary user. From what I can tell, the focal point Microsoft has been improving on for the last 10 years is the enterprise management system.

Windows in general could be better. It's a shame it isn't. So much wasted potential.

It makes sense — enterprises make them money 💰💸
Please open Telegram to view this post
VIEW IN TELEGRAM
97👍43🤔22🤬8👎4😱1
👍171😱3829🤔8🎉4👎3🤬2😢1
Enderman
This media is not supported in the widget
VIEW IN TELEGRAM
🎉159🤬36👎24😢126👍5🤔5
Enderman
⛔️ The Giveaway

I'll make sure to never ever host a giveaway again... Telegram is really stupid. 8K botted subscribers that I can't even ban from the channel...
😢261🤬3420👍18😱9👎6🎉2
🪟 Windows 10 security updates will become paid

Microsoft will offer Extended Security Updates for Windows 10 starting at $61 for the first year.

That's nothing new from Microsoft, but it symbolizes the end of support inevitably looming over...
Please open Telegram to view this post
VIEW IN TELEGRAM
🤬167😢19👎12👍9🤔9🎉73😱2
🪟 The «User Choice Protection» driver

Microsoft blocks third-party tools from setting the default browser again, now using the «User Choice Protection» driver.

That's a really aggressive measure not seen before.
Please open Telegram to view this post
VIEW IN TELEGRAM
🤬171😱21👎8😢6👍4🤔31
😱160😢2516🤬4👍1🤔1
Enderman
Photo
🤬96😢49😱21🤔8👍7🎉2👎1
Enderman
Photo
🐧 LeBron can't stop fumbling everything

Someone on Twitter asked me to make the Linux version, so they shall receive 😄
👍115😱3820😢7🤔6🤬6
This media is not supported in your browser
VIEW IN TELEGRAM
sandwich pisi
236😱16🎉5👍2
144😱24🤔16👍10
👀 .com executables in Windows 11

There is still a handful of seemingly MS-DOS .com executables in Windows 11.

However, if you run them, they execute and operate normally. So, what's the deal?

Well, what's left of them is just an extension. I analyzed the executables, and they all have a PE+ 64 header (PE + 0x6486 little-endian at offset 0xE8 and 0x0B02 little-endian at offset 0x100), meaning they're all modern 64-bit applications.

By all definitions, these applications should have an .exe extension, but they still have .com at the end. That doesn't stop them from executing or break anything, but it's a wrong extension to use.
👍72😱1711🤔9
📩 why are .com extensions applications supporting 64 bit tho???

The biggest misconception about files in Windows is that extensions are important, and somehow define whether the file runs or not. In reality, extensions are purely cosmetic. You can register parsers for your very own extensions within the registry (HKLM\Software\ClassesHKCR) and set verbs and rules for Windows Explorer to follow when it stumbles upon your file association. That's the whole idea of extensions in Windows — to let Windows Shell automate passing the file over to the executable for you. There are protocols too, which Microsoft seem to be more fond of lately... (hello, Android content providers?)

No matter the extension, the contents of the file remain the same, and if the file has executable contents within it, you can run it. In fact, I suggest you try changing the extension of any executable you wish to .jpg and then run that JPEG-file from a command line.

The only difference for «executable files» in Windows is that they are the command that runs upon execution. NoEscape (does anyone even remember that?) leverages the registry nature of the executable file association. It sets up a pass-through executable that runs malicious code, but then follows up with running the original executable. Sneaky. It's called a companion virus. Neshta.A is a great example too.

Shell extensions are sort of similar in fashion. You can check my blog post out if you want to know the basics.
👍57🤔106🤬1🎉1
💻 Customer-friendly design

Meet Fujitsu Lifebook U904 (2013). This bad boy completely defies the corporate rule of «if it doesn't fit, it isn't included». They managed to achieve this by making the Ethernet port... foldable.

While the construction is certainly not network admin friendly, and isn't going to last an exceedingly long time, it's far better than no port at all!

Remember this post when a corporation like Apple uses thinness as an excuse to strip your product of features or make you buy overpriced dongles! 😉
148👍22😱8🎉6