Pretty unimpressive as security vulnerabilities. It would be better to just say these are simple bugs for the most part.
Anonymous GitHub account mass-dropping undisclosed 0-days
71–80 of 407 posts
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#72Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#73Earlier quoted context omitted.
Repo claims > A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way. Which is roughly the definition of zero day. Whether the contents of…
> Please do not abuse these. Reminds me of Jamie Wolf's joke about bestiality laws. Who are those for? What stops most people from bestiality is… not wanting to have sex with animals! For people who do want to, what, they won't because of… the law?? Who will this comment stop??
Regarding the comment, it isn't going to stop anyone. Most people will not do cybercrime because they're honest. Of the remaining, the risk of being sentenced to jail time will instead stop some people, even if not all of them.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#74I took a look at the Ghidra ones (because I use Ghidra), and I'm unimpressed: https://github.com/bikini/exploitarium/blob/main/ghidra-12.1... The first requires being able to overwrite binaries in the Swift tool directory. Yes, if you overwrite binaries executed by ghidra, you can trigger code execution. This is not a surprise. The second, idk, I'm not familiar with TraceRMI (but it's probably worth noting that "RMI"…
After a bit of research, the Firefox one seems plausible to me. But, I haven't actually tried the POC. The explanation about the private-data and untrusted-input flags is plausible but I'm not an expert on Firefox's internals, maybe that's not actually how it works.
This just sucks, all around. Are we going to need every open source project gawking at the same repo full of stuff that has nothing to do with them, on the off chance that someone discloses a vuln that does have to do with them? Is this some kind of performative complaint about high friction in responsible disclosure? Well great job dickhead, you've just made a system that's even worse. Nobody benefits from this. Yuck yuck yuck.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#75There is going to be a flurry of this sort of stuff as the AIs get smart enough to find them. It will naturally die down as the legitimate ones are fixed. Yes, there will always be some level of this, but I’d expect it to be low and the exploits found to be increasingly complex. This is a time of transition.
> a flurry of this sort of stuff as the AIs get smart enough to find them. I really think this characterization is misleading. It's not "getting smart", only more tailored toward a specific usage, better curated dataset, better harness, better prompts, better labeling of results, documentation of failures and success, etc. The outcome is (hopefully) overall better but this anthropomorphized wording makes it sound lik…
Or are you just defining "fast" as something only horses can do, and considering that a useful insight about cars?
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#76Earlier quoted context omitted.
Repo claims > A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way. Which is roughly the definition of zero day. Whether the contents of…
> Please do not abuse these. Reminds me of Jamie Wolf's joke about bestiality laws. Who are those for? What stops most people from bestiality is… not wanting to have sex with animals! For people who do want to, what, they won't because of… the law?? Who will this comment stop??
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#77Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#78A friendly reminder that a 0-day is a vulnerability that wasn't known until after a malicious actor exploited it. If someone publishes a PoC, it is not a 0-day, just a vulnerability.
No, the days start counting from the availability of a patch.
Then I did some searching and found multiple examples of both definitions in use, making things murky.
So I turned to Merriam-Webster’s dictionary: “ of, relating to, or being a vulnerability (as in a computer or computer system) that is discovered and exploited (as by cybercriminals) before it is known to or addressed by the maker or vendor”
And of course they use an “or” to make it ambiguous as to whether the days start counting when the vulnerability becomes known, or when the vendor has addressed it.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#79Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#80Earlier quoted context omitted.
Repo claims > A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way. Which is roughly the definition of zero day. Whether the contents of…
> Please do not abuse these. Reminds me of Jamie Wolf's joke about bestiality laws. Who are those for? What stops most people from bestiality is… not wanting to have sex with animals! For people who do want to, what, they won't because of… the law?? Who will this comment stop??
The people who want to see the people doing bestiality punished