Live data from Hacker News

Anonymous GitHub account mass-dropping undisclosed 0-days

github.com

231–240 of 407 posts

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#231

Do NOT, under any circumstances, use any material in this repository maliciously. This is good-faith, open-disclosure vulnerability research intended to get more people interested in exploring this area of cybersecurity. Reminds of the message in the The Anarchist Cookbook before one the recipes that essentially said: "This is really dangerous, don't ever do it, here is how you do it."

The old book didn't say "... maliciously." though?

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#232

Earlier quoted context omitted.

I said "doesn't matter" to someone once... the resulting lesson came in the form of a reply from the whitehat researcher ( waves , hi brian!) a 16step exploit chain resulting in a one click full account takeover. I'm equally annoyed and over the alarmist takes. But I don't think it's fair to group mine into it. I'm annoyed at seeing discard respect for others into the same void everyone is happy to toss quality. Do t…

That’s a whole lot of “we” to not mention which company you’re at that supposedly plays well with security researchers/has a proper bug bounty.

I say we, intentionally not naming the company, because 1) doing so tends to turn off people's brains and they default assume everything $company does is the correct way, but if I say something stupid I'd rather someone tell me, instead of assume someone at $company must know or couldn't possibly know. 2) I say we, because I'm speaking for myself, (and maybe a tiny bit) for my 2 friends still running the BB program at what possibly should describe as my former company, but then I've always exclusively been speaking for me, not about them...

So I'm still not gonna name them, it wouldn't be hard to figure out who they were, with a likely-trivial amount of effort if feel the need to know... but if you'd rather, I'd encourage you to imagine I work at the worst company you can name or imagine, so you can use that to discard anything I've said. Because I'd rather be judged on my argument, not who hired me that one time.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#233
I get the sense that folks here are assuming this could be the work of an AI practitioner or bot dumping a bunch of exploits. Assuming there are some serious exploits in this trove, what would the motive be to do it in this way - without reaching out to the various code maintainers in some way?

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#234
post #17

I took a look at the Ghidra ones (because I use Ghidra), and I'm unimpressed: https://github.com/bikini/exploitarium/blob/main/ghidra-12.1... The first requires being able to overwrite binaries in the Swift tool directory. Yes, if you overwrite binaries executed by ghidra, you can trigger code execution. This is not a surprise. The second, idk, I'm not familiar with TraceRMI (but it's probably worth noting that "RMI"…

A glance at the nmap one seems potentially high severity. It might be a nothing in practice, but it being around parser code means the chances of preparing something to jump around are pretty high. There'd be a certain irony being able to reverse shell anyone doing an nmap scan. If i had infinite tokens i'd throw claude on writing an exploit and dig through the history who made it possible because - if we take a mome…

These kind of tools have always had a broad attack surface. I've assumed state level actors already have exploits for them, mostly based on when I've used such tools for mundane network maintenance tasks and somehow do something that triggered an old-fashioned segfault.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#235
post #28

Earlier quoted context omitted.

Why is that surprising? LLMs can churn out arbitrary volumes of "documentation" in an instant.

This was sarcasm, meaning exactly what you wrote.

I can't see how it could possibly be read as sarcasm.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#236

Earlier quoted context omitted.

I used to be an em-dash user, but now my opinion is that I’d rather be perceived as someone who does not want to be confused with an LLM. So I’ve changed my writing style.

I don’t give a flying fuck what people think. Most colleges copied or adopted my (for a few semesters) school’s style guide, so LLMs are essentially copying me , and I won’t change my punctuation usage because they suck.

> I don’t give a flying fuck what people think.

So all your writings are private, then?

Do you have a motivation to communicate or publish? You're posting here on HN, so I think so.

Why do you do think you do it?

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#237
post #138

Earlier quoted context omitted.

They're just so handy! I do think LLMs tend to use them in a specific way, though. So maybe tweaking your usage (ex. no spaces around them) or using a technically incorrect en-dash might offer the desired effect while subtly signaling that your message isn't AI-generated. I still use them — mostly for pauses — but I'd like to think my voice sounds distinct enough from an AI that people can tell.

I've only ever been using "regular" dash, a minus, for that. How do you even type yours? If I ever needed differently-sized dashes (and I don't know the difference between them) I always used wiki to copy them. (disclaimer: I feel like this obsession with dashes is special to native English speakers, which I'm obviously not)

Only a small subset of native english speakers. Most don't use dashes at all, of those that do most just use minus for everything, some exceedingly small group cares about typographical details and thus distinguishes the different sorts of dashes.

It's an attention to detail thing that you'd definitely want to get right in a physical textbook or the like.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#238

Earlier quoted context omitted.

This is a pointless and infinitely losing arms race. LLMs will learn to use hyphens instead of em dashes, and so what? You’re going to start using em dashes again? Just focus on not producing slop.

At this point, I believe the LLM "style" is on purpose. Perhaps the labs want to be able to distinguish their slop from human content for future training; I don't know. But it feels very deliberate that they've kept the style so consistent for so long.

I agree. They're voluntarily adding fingerprints to images so I expect the default voice is intentional and it wouldn't surprise me at all (though I have no evidence of this) if the output text has a fingerprint stenographically embedded in it.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#239
post #167
post #138

Earlier quoted context omitted.

I've only ever been using "regular" dash, a minus, for that. How do you even type yours? If I ever needed differently-sized dashes (and I don't know the difference between them) I always used wiki to copy them. (disclaimer: I feel like this obsession with dashes is special to native English speakers, which I'm obviously not)

Depends on your OS. Mac is the easiest, it's just ---, Linux depends on your distro, if it uses KDE, it's --- —. Windows is a little awkward, I think you need +the code point.

I have mac, typed this --- again --- and nothing? Layout says U.S.

edit: another comment gave a mac shortcut – — - <--- one of these might be it

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#240
post #138

Earlier quoted context omitted.

I've only ever been using "regular" dash, a minus, for that. How do you even type yours? If I ever needed differently-sized dashes (and I don't know the difference between them) I always used wiki to copy them. (disclaimer: I feel like this obsession with dashes is special to native English speakers, which I'm obviously not)

Only a small subset of native english speakers. Most don't use dashes at all, of those that do most just use minus for everything, some exceedingly small group cares about typographical details and thus distinguishes the different sorts of dashes. It's an attention to detail thing that you'd definitely want to get right in a physical textbook or the like.

That's the same in my native language too I guess. It's used in books, sometimes in media, but not really in any casual setting I would say.
Post reply on HN