The most successful malware of 2024, even though it only does denial of service.
Seems DoS "just works".
Ask HN: What is in C-00000291*.sys?
71–80 of 104 posts
Re: Ask HN: What is in C-00000291*.sys?
#72Re: Ask HN: What is in C-00000291*.sys?
#73Re: Ask HN: What is in C-00000291*.sys?
#74Re: Ask HN: What is in C-00000291*.sys?
#75On another note, I know nothing about cybersec, is there a reason for which antivirus on windows run at ring 0 while I read that on Linux and Mac they don't have kernel level access?
It's not an anti-virus, it's intended to monitor all and everything on the machine. You^WAn attacker might want to hide what you're doing and thus it runs at that level.
[CrowdStrike Falcon® Pro: Antivirus with Threat Intelligence](https://www.crowdstrike.com/products/bundles/falcon-pro/)
Re: Ask HN: What is in C-00000291*.sys?
#76Re: Ask HN: What is in C-00000291*.sys?
#77Re: Ask HN: What is in C-00000291*.sys?
#78Re: Ask HN: What is in C-00000291*.sys?
#79Hm, is there any website that explains why C-00000291*.sys caused the widespread BSODs? For example, was it some kind of definition file that was accessing invalid memory locations?
Re: Ask HN: What is in C-00000291*.sys?
#80Earlier quoted context omitted.
It’s both. If you’re an engineer and you push out shitty code that takes down 911 systems and ambulances, you f’ed up. Push back against processes that cause harm, or have the potential to cause harm. You are ultimately responsible for your actions. No one else. The excuse of “I was just following orders” has been dead and buried since WW2. Yeah, ideally management should know better. But management aren’t usually en…
> It’s both. If you’re an engineer and you push out shitty code that takes down 911 systems and ambulances, you f’ed up. This is wrong. If a company is developing that kind of software is the responsibility of the company to provide a certain level of QA before they release software. And no, it's not that "engineers are pushing out shitty code", but that the shitty company allows shitty code to be deployed in custome…
What matters is how this was deployed without any testing.