Live data from Hacker News

We found a division by zero bug in FFmpeg with a vibecoded fuzzer

code.ffmpeg.org

251–260 of 274 posts

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#251

Earlier quoted context omitted.

It keeps casual users (which most bots masquerade as) out. For frequent users of that site it is a solve once access forever.

I don't get it, it briefly flashed up on my iphone , about quarter second maybe, then passed on. Does the same in private mode. Maybe it uses other heuristics like detecting if someone lives in the AI agent world

Took like 2.5-3 minutes on my regular desktop browser. Nothing AI related

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#252
post #46
post #35

Earlier quoted context omitted.

Unrelated to the submitted link -- just checked your comment history and all of your comments are AI-generated like this one. What's the motivation for this?

He won’t reply, he’s busy promoting himself and his peojects with AI.

Also haven't done any self promo, but yeah i'll stop running my posts thru chat

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#253

Earlier quoted context omitted.

Oddly enough I can’t access that site, it just heats up my phone solving hashes. Gave up after about a minute and anubis had only made it less than halfway through. I doubt the real bots have any trouble bypassing it.

It's puzzling how mild the reactions are to Anubis compared to the people reacting to seeing one singular Cloudflare captcha checkbox. I'd much rather a checkbox than a brief CPU-intensive hashing session.

Well, Anubis actually lets me through eventually and most are very fast. Even this one is minimal compared to Cloudflare, which before I had to block its scripts entirely would just max out one CPU indefinitely (or at least a few hours, I found by accident, with no indication of stopping).

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#255

Earlier quoted context omitted.

Oddly enough I can’t access that site, it just heats up my phone solving hashes. Gave up after about a minute and anubis had only made it less than halfway through. I doubt the real bots have any trouble bypassing it.

It's puzzling how mild the reactions are to Anubis compared to the people reacting to seeing one singular Cloudflare captcha checkbox. I'd much rather a checkbox than a brief CPU-intensive hashing session.

The Cloudflare captcha checkbox fingerprints the crap out of your browser. It's an opaque risk-based thing, which is the worst. Anubis just makes your browser brute force hashes, that's it.

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#256

Earlier quoted context omitted.

I think when people are complaining about Captcha they're complaining about yet another "pick 6-20 pictures of traffic lights/school busses/stairs/stop signs/bicycles."

If they want to train an AI they should pay for it like everyone else. Modern bots have zero problems solving these, it's just free training for them.

Does the bot include the rider when identifying bicycles? When is an ebike a motorcycle/no longer a bicycle? The support structure for a traffic light or just the coloured light bits?

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#257
post #89

Am I missing something? Who cares? This isn't a security issue, it's just an unexploitable crash on bad data.

that’s the issue with these newer models. they are able to string together a sequence of “not-serious” bugs in a system that ultimately results in some serious vulnerabilities.

it may not be an issue for ffmpeg, but it might be for an application that bundles ffmpeg.

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#259

OP here: for those interested is not that an LLM found the bugs the fuzzer found them. My take on this matter was to implement as much information theory algorithms as possible, and try to extract as much structure with statistical importance from the binary being fuzzed. Also port as much features from other fuzzers and whie papers on the mater (llms are good at connecting dots across vast codebases and papers). I h…

I can't speak to the quality of the fuzzer since I haven't used it or looked at it thoroughly, but it does seem to cover a lot of ground on features and interesting concepts. I'll definitely be reading more into what you have here.

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#260

Earlier quoted context omitted.

[flagged]

It's Anubis and it's actually cool and loved project here. It's an open-source Captcha that filters out bots, and it doesn't track you around the web, unlike Google or cloudflare captcha.

Speak for yourself.
Post reply on HN