reporter submits a hackerone report against #curl that includes "a crash in function NNN" with lots of complicated details.
With the little detail that function NNN was made up and does not exist in real code.
reporter submits a hackerone report against #curl that includes "a crash in function NNN" with lots of complicated details.
With the little detail that function NNN was made up and does not exist in real code.
The obvious solution to AI slop is to have another AI that can detect AI slop!
But then they'll build an AI to get around the slop detecting AI
So you'll also need an AI that can detect the slop detecting defeating AI
Yes, this is all very reasonable
Buckle up, here it is:
**Penetration Testing Report: HTTP/3 Stream Dependency Cycle Exploit** --- # **0x00 Overview** A novel exploit leveraging stream dependency cycles in the HTTP/3 protocol stack was discovered, resulting in memory corruption and potential denial-of-service or remote code execution scenarios when used against HTTP/3-capable clients such as `curl` (tested on version 8.13.0). This report details...
@bagder Ha, could not find it with my phone but wasn‘t sure enough.
Sending an invoice to the guy?
@0xabad1dea @fubaroque I should have said more clearly "The cost to a bad-actor submitter".
But these things are hard, particularly if you wish to support and be nice to the good actors.
I have essentially never allowed user comments on any of my sites since the late 90s because SPAMming is too easy to attempt. (And I also have received ~10,000 SPAM email attempts per day for all that time.)
@domi let me spell this out as clearly, directly and literally as possible: You are being annoying. Sending useless, content-free objections to people you don't know, in reply to messages that weren't addressed to you, being told that it was annoying and then being like "you're welcome!" about it is a good way to get categorized as a troll and blocked.
I am sending this reply instead of blocking you because I think you might just sincerely be this non-practiced at communicating with other humans, and not malicious.
@bagder I need to write up a pull request that adds a securty hole and then a report of that hole...
Now if I could just figure out how ot make money doing that.
@bagder do you have a link?
EDIT: now I see it, please don't mind me