Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

131–140 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#131
I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police.

The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue.

Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful day.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#132

Earlier quoted context omitted.

But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.

I'm not sure if this is an unintentional mistake. Gitlab did not perform a ban. Github performed the ban. Github is fully-owned by Microsoft.

Yes they did: https://gitlab.com/nightmare-eclipse

That git account was posted on their blogspot...

Re: GitHub bans security researcher who posted zero-day Windows exploits

#133

Earlier quoted context omitted.

But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.

I'm not sure if this is an unintentional mistake. Gitlab did not perform a ban. Github performed the ban. Github is fully-owned by Microsoft.

Not one or the other but both. He's banned on GitLab as well.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#135
post #105

Earlier quoted context omitted.

ooc, would you claim its the responsibility of the security researcher to remove the webshell, or the company's as soon as they were notified? was it publically discoverable and exploitable or was there some form of protection?

I would agree it's the researcher's responsibility. It's not that the company put up a webshell for kicks. The researcher found an exploit (good), and used it to install a webshell, demonstrating the highest possible risk (fine). Once the shell is up, anyone who finds the URL has code execution on the server, because that's what a webshell is. Using it is a different skill than installing it. Imagine I figure out how…

I.. just can't wrap my head around that.

Once the notification is in and the shell demostrating it is up it should be immediate redeploy to a clean state, fix the hole, redeploy to a patched state.

The shell disappears on step one.

Instead some moron has the audacity to get all hurt because the broken system he is responsible for has not been patched back by the attackers?

What is this lunacy?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#136
post #117

Earlier quoted context omitted.

Yep, and its a really small world out there. If researchers stop believing MS will treat them fairly it's bad news for the entire security industry.

Well. Its a bad news for society as whole. Security industry going to be okay - someone will always pay for 0-days. If vendors wont pay its just gonna be US agencies, Israel resellers, China or Russia. If you don't feed your army, you will soon feed someone's else's.

It's had bad news only for Windows buerocrats. Good orgs don't use Windows.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#137

Researcher seems a bit unhinged.

This often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.

palantir embraces the neurodivergent.

https://x.com/PalantirTech/status/2057157517969445252

Re: GitHub bans security researcher who posted zero-day Windows exploits

#138

I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.

> Guy sells zero days elsewhere.

No problem. The CIA will give it's high level officers millions of dollars in gold bars simply for the asking. I'm sure purchasing exploits doesn't even require a purchase order.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#139
The combination of an overly unstable dramatic researcher, a tech news community which will undermine truth in a desperate plead for some clicks and people that are readily willing to believe everyone is constantly just casually in contact with the NSA, gives us these third rate stories

Re: GitHub bans security researcher who posted zero-day Windows exploits

#140
post #131

I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…

That's really sad to hear, you must have felt really bad. Just because they do not know about the vulnerability, it won't disappear. And they won't fix it too. Ignorance is a bliss, but not in this case...
Post reply on HN