why doesn't he sell those to someone like zerodium the bugs he is publishing are exactly the class of bugs that they would love to buy
Looks like Zerodium shut down last year
GitHub bans security researcher who posted zero-day Windows exploits
191–200 of 274 posts
Re: GitHub bans security researcher who posted zero-day Windows exploits
#192Shoot the messenger. That’ll fix it.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#193Re: GitHub bans security researcher who posted zero-day Windows exploits
#194Earlier quoted context omitted.
I.. just can't wrap my head around that. Once the notification is in and the shell demostrating it is up it should be immediate redeploy to a clean state, fix the hole, redeploy to a patched state. The shell disappears on step one. Instead some moron has the audacity to get all hurt because the broken system he is responsible for has not been patched back by the attackers? What is this lunacy?
It's at the minimum a bit impolite to leave the system more vulnerable in between sending the report and the report being received and acted on.
This is security, you have to have procedures for when you get owned; the bug bounty program is orthogonal to that.
If they wiped prod db and put up goatse on my site I would have still paid and said thank you provided I was told how that was done.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#195Earlier quoted context omitted.
Some may criticize regulations, but the EU-mandated cyber-resilience act (CRA) actually forced companies to have a clear contact point for vulnerabilities reporting, and to act upon it.
2026-09-11, save the date folks. That's when all companies selling products with digital elements in the EU have to have a reporting pipeline for actively exploited vulnerabilities and severe incidents.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#196Earlier quoted context omitted.
You now have the worst of both worlds. You report yourself to the police for trying to hack into a computer-system and you report yourself to the website that can now decide to sue you. All of that without any benefits.
Sir, this is not USA, don't assume stuff fucked up there is fucked up everywhere
Re: GitHub bans security researcher who posted zero-day Windows exploits
#197Earlier quoted context omitted.
Read the write up on YellowKey. [1] It sounds like, in at least some instances, he's publishing official Microsoft backdoors probably used by US intelligence agencies et al. It turns out that Bitlocker is insecure and backdoored. Something noooobody expected after TrueCrypt just mysteriously and suddenly shut their doors one day, removed all downloads, and recommended everybody move to Microsoft's BitLocker. lol. [1]…
If you were using bitlocker to replace truecrypt, you'd have a boot password and this would not affect you at all. I'm still far from thinking this is a backdoor. It tricks the boot environment into deleting a file and then it doesn't ask for a password. The exploit is nowhere near bitlocker, the problem is that bitlocker without a boot password requires the whole OS to preserve security from boot through the login s…
Maybe it was on GitHub/GitLab before the author was banned by both Microsoft and GitLab, not really sure we'd know. The authors last post on their blog is from yesterday (28th of May, https://deadeclipse666.blogspot.com/) so seems they aren't fully gone. But yeah, been a lot of "promises" but besides the initial 0days, not so much released AFAIK.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#198Re: GitHub bans security researcher who posted zero-day Windows exploits
#199Earlier quoted context omitted.
Is this sarcasm? Or are you saying that the onus of providing proof is not on the those making the claim, but instead that the onus of proof is on those who did not make the claim?
Sure you can provide an alternative explanation? Otherwise, that's the best we have.