Earlier quoted context omitted.
I used to be an em-dash user, but now my opinion is that I’d rather be perceived as someone who does not want to be confused with an LLM. So I’ve changed my writing style.
I don’t give a flying fuck what people think. Most colleges copied or adopted my (for a few semesters) school’s style guide, so LLMs are essentially copying me , and I won’t change my punctuation usage because they suck.
Anonymous GitHub account mass-dropping undisclosed 0-days
221–230 of 407 posts
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#222> At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. I do this so to allure people into the field, and I've always found this is the most efficient way. I've been a skiddy, he would have believed this. Thankfully, I've grown a bit, and can see this for the transparent, "I'm angry and want to hurt others so I will feel a little less alon…
Please name the "victims" here.
I'm genuinely curious, have you ever had actual, direct threats to your safety before, as a person? As in, murder, torture, false imprisonment, or other __likely and credible__ threats of grave bodily harm?
> but as someone who's joined the blue side
Are you somebody who separates "cybersecurity" from say: military intelligence poisoning one of your employees, sending them to a hospital which is already compromised, before sending back their new asset into your very "secure" company?
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#223Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#224Pretty unimpressive as security vulnerabilities. It would be better to just say these are simple bugs for the most part.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#225Looks like a bunch of re worded copies of existing CVE and a few new lower severity things. I only call them low sev because they seem to require the user to do things that are already inherently dangerous. Just my 2 cents from a quick scan. Edit: To be clear still interesting finds. I think with some chaining some of them might be more severe. Like the ovpn one and windows potentially registering vpn app as default…
Floci, libssh2, c-ares, FFmpeg, and the PHP one are all LEGIT./
The Ghidra one for example, not so much. I cant help but wonder if this was halfway completed research folder and they just published it as is
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#226Earlier quoted context omitted.
I don’t give a flying fuck what people think. Most colleges copied or adopted my (for a few semesters) school’s style guide, so LLMs are essentially copying me , and I won’t change my punctuation usage because they suck.
The purpose of good writing style has always been to signal education and class. Well, your style no longer does. The future is now.
Sure, that’s why there have never been any authors that became famous despite being poor and deliberately writing with that affect.
Good writing style does connote good education, and in environments where being upper-class bolsters social standing, some people flaunt it to signify class, as they would with any other wealth signifier, like expansive shoes.
I am a union tradesman— the third generation to work in manufacturing in this area. Affecting an upper-class identity diminishes social standing in my environment. Having a lot of money, definitely doesn’t. My dirty work boots probably cost as much as many of the trendiest shoes on the market, and the guys at work know that and admire them… but my wearing them doesn’t signify class. Similarly, you can use good writing style in a way that shows you went to a good school and paid attention without wearing it like a Harvard Business School fleece.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#227I took a look at the Ghidra ones (because I use Ghidra), and I'm unimpressed: https://github.com/bikini/exploitarium/blob/main/ghidra-12.1... The first requires being able to overwrite binaries in the Swift tool directory. Yes, if you overwrite binaries executed by ghidra, you can trigger code execution. This is not a surprise. The second, idk, I'm not familiar with TraceRMI (but it's probably worth noting that "RMI"…
A glance at the nmap one seems potentially high severity. It might be a nothing in practice, but it being around parser code means the chances of preparing something to jump around are pretty high. There'd be a certain irony being able to reverse shell anyone doing an nmap scan. If i had infinite tokens i'd throw claude on writing an exploit and dig through the history who made it possible because - if we take a mome…
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#228Earlier quoted context omitted.
I said "doesn't matter" to someone once... the resulting lesson came in the form of a reply from the whitehat researcher ( waves , hi brian!) a 16step exploit chain resulting in a one click full account takeover. I'm equally annoyed and over the alarmist takes. But I don't think it's fair to group mine into it. I'm annoyed at seeing discard respect for others into the same void everyone is happy to toss quality. Do t…
No one is doing 16 step exploits unless you're a huge target in some way. 0.0000001% of companies fit that bill. And even then, ok, what did they get? An account login? What are they doing to do? Read email? Then what? "Use it for social engineering"? Who cares, you have MFA right? You have a firewall? You don't allow people to randomly jump from box to box via RDP? You have basic security and auditing on your filesh…
Account take over of a user account. I'm pretty sure I could sell access to the DMs of a few popular people for 100x what we paid out for that report.
But also, I'm pretty confident that this researcher delivered this exploit because I'd said that there was no way he could use it maliciously, not because he wanted to be paid. Then, once I made that critical error in judgement by questioning (rejecting) his assertion in his report. He, like most hackers, being insulted by the idea, was then required to restore his name and reputation. There are the people who only go after targets that they can confidently make money off targeting... some of us care more about reputation than money, and will die on any hill when our reputation/work is questioned/doubted.
> Security "teams" are a bunch of fucking busybodies with nothing to do. Pay for a competent admin team and the security dept is completely redundant and useless.
Lmao, tell me you don't really understand what goes into getting functional systems/corp security without telling me. I don't even disagree with the point you were trying to make. You're absolutely correct! If you have a competent admin team, you don't need a dedicated security team. Unfortunately, as I live in the real world, where most people are incompetent, it does help to have a dedicated security team. Especially considering if you were an admin who is competent, you could make 2x as a security engineer, which normally keeps all the competent people out of admin, and thus requiring a dedicated security team.
I don't know why you're mad, or why you're arguing it at me. I'm pretty sure I already agree with most of your points... the only one I might disagree with, and only then because you're arguing at me for some reason, and that makes me think you probably disagree, with the important point which is, we're all on the planet together, you're not required to help me do my day job, but as an industry, both security engineers and security researchers, we need to remember that we're actually on the same side, and we need to aggressively resist returning to the us vs them mentality that we're just barely starting to escape from. Case in point, it appears to me that you think complaining about how security people are useless and CVEs don't matter, as a much more important point, than complaining about obviously irresponsible disclosure.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#229Earlier quoted context omitted.
> Please do not abuse these. Reminds me of Jamie Wolf's joke about bestiality laws. Who are those for? What stops most people from bestiality is… not wanting to have sex with animals! For people who do want to, what, they won't because of… the law?? Who will this comment stop??
Those seem like two different scenarios though, right? The point of beastiality laws are to give society some recourse to punish people who abuse animals. There was a very famous case back in Washington state back in the early 2000s where a group of men were sexually abusing horses. It was uncovered because one of them died, and the other could only be charged with trespassing because it wasn't illegal at the time to…
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#230Earlier quoted context omitted.
Actually, Mudge of the l0pht (and later DARPA) once famously made the claim that all bugs are security issues waiting to be exploited in some way (I’m probably paraphrasing). I kind of agree. Although, the bugs on this dump are indeed mostly pretty lame, which is exactly what I’ve seen you get a lot of when you let an llm go bug hunting with no human vetting and confirmation in the loop. It’s possible/likely that who…
Such claims can both be true and pointless. For those of us who have to decide what actions to take, there is a point in differentiating between bugs and vulnerabilities, and breathlessly proclaiming "we found a vulnerability but we don't have an exploitation vector or proof that there's a meaningful security consequence" is annoying and likely to get the proclaimer ignored in the future.