Earlier quoted context omitted.
[flagged]
Why are you constantly responding to people like this? What makes you think you’re above the rest of HN?
I found a WordPress RCEs with GPT5.6 and $25
231–240 of 247 posts
Re: I found a WordPress RCEs with GPT5.6 and $25
#232Earlier quoted context omitted.
Why are you constantly responding to people like this? What makes you think you’re above the rest of HN?
You apparently work in the field. Do you take these "price lists" seriously?
But that’s besides the point. You straight up argued that one isn’t real in the most asinine way you could.
Even if you were right that would be ridiculous. The fact that you’re wrong and have multiple people telling you you are makes it even worse.
I’ve seen you replying in snide comments whenever someone disagrees with you before. Your status as…whatever you are doesn’t give you carte to treat randoms like they’re beneath you.
Re: I found a WordPress RCEs with GPT5.6 and $25
#233Earlier quoted context omitted.
> And since the WordPress foundation controls the extension marketplace, they can reliably determine which parts of the API surface are in use, or even invest a chunk of money every month to send AI-written patches to plugin maintainers to ease the transition. What WordPress foundation?
The, uh, WordPress Foundation[0]? [0]: https://wordpressfoundation.org
https://news.ycombinator.com/item?id=42689906
The foundation was, at some point in time when the drama was at its peak, mostly a feel-good non-profit initiative.
Re: I found a WordPress RCEs with GPT5.6 and $25
#234Earlier quoted context omitted.
You apparently work in the field. Do you take these "price lists" seriously?
They can be and they can not be depending on what you’re selling. But that’s besides the point. You straight up argued that one isn’t real in the most asinine way you could. Even if you were right that would be ridiculous. The fact that you’re wrong and have multiple people telling you you are makes it even worse. I’ve seen you replying in snide comments whenever someone disagrees with you before. Your status as…what…
Re: I found a WordPress RCEs with GPT5.6 and $25
#235Earlier quoted context omitted.
Bulk reply to all the people replying. bink is correct. The people who buy exploits are governments. There is very little interest in Wordpress or indeed any target that isn't a browser or a mobile. Browsers and mobiles are the only things that are perennially useful to an intelligence agency. Those two are reliable access vectors for the vast majority of things that interest government organisations.
> There is very little interest in Wordpress I'd disagree here. Still 41% of all sites use Wordpress [1]... and that means a lot of targets, and a lot of ways to target them. Your good ole' deface/ransomware extortion scheme, leaking data supposed to be confidential (such as account lists), trusted spreaders for exploits, or the latest hit, bets on "prediction markets" that have some Wordpress site set as oracle. Peo…
Re: I found a WordPress RCEs with GPT5.6 and $25
#236Earlier quoted context omitted.
They can be and they can not be depending on what you’re selling. But that’s besides the point. You straight up argued that one isn’t real in the most asinine way you could. Even if you were right that would be ridiculous. The fact that you’re wrong and have multiple people telling you you are makes it even worse. I’ve seen you replying in snide comments whenever someone disagrees with you before. Your status as…what…
I'm noticing you didn't answer my question.
This is how all of these sites work. You would not get 500k for every exploit obviously. You would get that (or more) for great exploits.
I’m noticing you haven’t addressed anything I mentioned at all. Is that just acceptance that it’s the truth or are you just having a bad day?
Edit: Actually, let me add that for a 0click exploit on mobile devices that leads to root level permissions you’re very likely sitting on millions of dollars.
Re: I found a WordPress RCEs with GPT5.6 and $25
#237I might be missing something, so perhaps someone can explain: Why are the steps in the middle of the exploit chain necessary? The writeup describes getting a SQL injection, then going from there to cache poisoning to exploiting various logic bugs, to eventually creating an admin account (and WordPress grants RCE to admin accounts by design). But if you have a SQL injection, why can't you use that to just create an ad…
Re: I found a WordPress RCEs with GPT5.6 and $25
#238Earlier quoted context omitted.
I'm noticing you didn't answer my question.
I did explicitly answer your question, yes. This is how all of these sites work. You would not get 500k for every exploit obviously. You would get that (or more) for great exploits. I’m noticing you haven’t addressed anything I mentioned at all. Is that just acceptance that it’s the truth or are you just having a bad day? Edit: Actually, let me add that for a 0click exploit on mobile devices that leads to root level…
https://securitycryptographywhatever.com/2024/06/24/mdowd/
It sounds like you're telling me you believe you might get six figures for a "great" WordPress core RCE. I believe that's false, and I believe that for reasons that probably indicate our premises are much too far apart to hash this out here.
I have open contempt for online price list "brokers" like Zerodium. I do not have contempt for other commenters here. I think it's important that you understand the distinction before coming at me the way you've been in this thread. Disagreeing with me, rebutting or refuting me, sharply or ungenerously: totally fine. Your weird psychoanalysis of me: not fine.
Re: I found a WordPress RCEs with GPT5.6 and $25
#239Earlier quoted context omitted.
I did explicitly answer your question, yes. This is how all of these sites work. You would not get 500k for every exploit obviously. You would get that (or more) for great exploits. I’m noticing you haven’t addressed anything I mentioned at all. Is that just acceptance that it’s the truth or are you just having a bad day? Edit: Actually, let me add that for a 0click exploit on mobile devices that leads to root level…
This is 2 years old, but goes deep into the details of how the "0 click" market works, roughly what kind of money you'd be sitting on, and what it takes to actually get that money: https://securitycryptographywhatever.com/2024/06/24/mdowd/ It sounds like you're telling me you believe you might get six figures for a "great" WordPress core RCE. I believe that's false, and I believe that for reasons that probably indica…
> Did you get mid-high 5 figures for a serverside vulnerability? I hear the Russians are paying $300k for Postfix! But the UAE might pay $400k through Crowdfense. These numbers are definitely real. How could they not be? They're right there on a web page.> Oh, you've done business with them then? Know someone who has?You’re replies have been snide and rude and you trying to pivot and say “you were merely talking about the brokers” is further showing you don’t care and feel entitled to continue.
Other users are calling you out on this behavior here and on other threads as well to the point that the comment you made starting this has stayed flagged.
Deflecting from someone calling out this consistent behavior is frankly ridiculous in the face of the receipts, especially trying to villainize the people calling you out for it.
Also, not even the main point anymore, but you’ve intentionally mischaracterized every argument others have put forwards including in your most recent response. I was extremely explicit about what kind of exploit commands a high price and you’ve chosen to again twist the argument to your desired conclusion:
> It sounds like you're telling me you believe you might get six figures for a "great" WordPress core RCEMy “psychoanalysis” was an attempt at giving you grace but you seem intent on proving that talking down to others and then trying to sidestep justified criticism are default behaviors that you’re entitled to.
Re: I found a WordPress RCEs with GPT5.6 and $25
#240Earlier quoted context omitted.
This is 2 years old, but goes deep into the details of how the "0 click" market works, roughly what kind of money you'd be sitting on, and what it takes to actually get that money: https://securitycryptographywhatever.com/2024/06/24/mdowd/ It sounds like you're telling me you believe you might get six figures for a "great" WordPress core RCE. I believe that's false, and I believe that for reasons that probably indica…
Absolutely not. > Did you get mid-high 5 figures for a serverside vulnerability? I hear the Russians are paying $300k for Postfix! But the UAE might pay $400k through Crowdfense. These numbers are definitely real. How could they not be? They're right there on a web page. > Oh, you've done business with them then? Know someone who has? You’re replies have been snide and rude and you trying to pivot and say “you were m…