Live data from Hacker News

Anonymous GitHub account mass-dropping undisclosed 0-days

github.com

71–80 of 407 posts

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#72
post #26

Earlier quoted context omitted.

Cash doesn't require a bank.

Banks are kinda useful to avoid getting robbed all your money, on a regular basis. Many French people with crypto money experienced that the hard way recently.

do you have links about the french people?

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#73
post #52

Earlier quoted context omitted.

Repo claims > A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way. Which is roughly the definition of zero day. Whether the contents of…

> Please do not abuse these. Reminds me of Jamie Wolf's joke about bestiality laws. Who are those for? What stops most people from bestiality is… not wanting to have sex with animals! For people who do want to, what, they won't because of… the law?? Who will this comment stop??

Well, it's a joke because the problem becomes apparent after you think a bit about it. The exact same reasonig can be applied to anything illegal, criminals are criminals because they don't respect the law, so you could try to say that laws are useless. Reality is, if something is illegal not only someone can be punished after the fact, but in some cases also preventive measures can be taken.

Regarding the comment, it isn't going to stop anyone. Most people will not do cybercrime because they're honest. Of the remaining, the risk of being sentenced to jail time will instead stop some people, even if not all of them.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#74
post #17

I took a look at the Ghidra ones (because I use Ghidra), and I'm unimpressed: https://github.com/bikini/exploitarium/blob/main/ghidra-12.1... The first requires being able to overwrite binaries in the Swift tool directory. Yes, if you overwrite binaries executed by ghidra, you can trigger code execution. This is not a surprise. The second, idk, I'm not familiar with TraceRMI (but it's probably worth noting that "RMI"…

I'm no expert on any of these programs, but that's kinda the problem, isn't it? No single person is an expert on every codebase supposedly exploited in this repo.

After a bit of research, the Firefox one seems plausible to me. But, I haven't actually tried the POC. The explanation about the private-data and untrusted-input flags is plausible but I'm not an expert on Firefox's internals, maybe that's not actually how it works.

This just sucks, all around. Are we going to need every open source project gawking at the same repo full of stuff that has nothing to do with them, on the off chance that someone discloses a vuln that does have to do with them? Is this some kind of performative complaint about high friction in responsible disclosure? Well great job dickhead, you've just made a system that's even worse. Nobody benefits from this. Yuck yuck yuck.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#75
post #58
post #30

There is going to be a flurry of this sort of stuff as the AIs get smart enough to find them. It will naturally die down as the legitimate ones are fixed. Yes, there will always be some level of this, but I’d expect it to be low and the exploits found to be increasingly complex. This is a time of transition.

> a flurry of this sort of stuff as the AIs get smart enough to find them. I really think this characterization is misleading. It's not "getting smart", only more tailored toward a specific usage, better curated dataset, better harness, better prompts, better labeling of results, documentation of failures and success, etc. The outcome is (hopefully) overall better but this anthropomorphized wording makes it sound lik…

Do you have a definition of "smart" such that there is something an AI could do to prove itself intelligent?

Or are you just defining "fast" as something only horses can do, and considering that a useful insight about cars?

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#76
post #52

Earlier quoted context omitted.

Repo claims > A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way. Which is roughly the definition of zero day. Whether the contents of…

> Please do not abuse these. Reminds me of Jamie Wolf's joke about bestiality laws. Who are those for? What stops most people from bestiality is… not wanting to have sex with animals! For people who do want to, what, they won't because of… the law?? Who will this comment stop??

The jury, maybe.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#77

Pretty unimpressive as security vulnerabilities. It would be better to just say these are simple bugs for the most part.

all vulnerabilities are just bugs.

But not the other way around, which makes them different.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#78
post #33

A friendly reminder that a 0-day is a vulnerability that wasn't known until after a malicious actor exploited it. If someone publishes a PoC, it is not a 0-day, just a vulnerability.

No, the days start counting from the availability of a patch.

I was thinking that the other definition was right and this correction was wrong.

Then I did some searching and found multiple examples of both definitions in use, making things murky.

So I turned to Merriam-Webster’s dictionary: “ of, relating to, or being a vulnerability (as in a computer or computer system) that is discovered and exploited (as by cybercriminals) before it is known to or addressed by the maker or vendor”

And of course they use an “or” to make it ambiguous as to whether the days start counting when the vulnerability becomes known, or when the vendor has addressed it.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#79

Pretty unimpressive as security vulnerabilities. It would be better to just say these are simple bugs for the most part.

all vulnerabilities are just bugs.

Vulns are a subset of bugs. What the above commenter is saying, is that some bugs don't belong to this category.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#80
post #52

Earlier quoted context omitted.

Repo claims > A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way. Which is roughly the definition of zero day. Whether the contents of…

> Please do not abuse these. Reminds me of Jamie Wolf's joke about bestiality laws. Who are those for? What stops most people from bestiality is… not wanting to have sex with animals! For people who do want to, what, they won't because of… the law?? Who will this comment stop??

> Who are those for?

The people who want to see the people doing bestiality punished

Post reply on HN