Jernej Simončič �

@jernej__s@infosec.exchange
248 Followers
146 Following
21K Posts
@Razemix @nina_kali_nina Years and years ago I was playing with date command on my father's 286, and it let me set dates up to 2099…

We are almost there folks hang in there

2020 ▓▓▓▓▓▓▓▓▓▓▓▓▓░ 550%

We are at the midpoint of the half century. The year 2050 is now closer than the year 2000.

Time is a social construct

@mcc the tone may have been a little jokey here but I really cannot emphasize enough how seriously the vibe has shifted in industry. I perennially want to do more game dev but never really have the time, so I am always curious and asking around the industry to find out what I should learn. In 2019 there was broad consensus “you just gotta learn unity, no way around it”. Post pricing scandal, there’s 100% unanimity on “maybe godot, maybe unreal, under no circumstances even consider unity”
those cartoony looking drawings going up everywhere? thats gen ai. everyone knows its gen ai. you arent fooling anybody.
ngl: macOS 26 is Apple's "Windows Vista" moment. Big time.
@infoseclogger @mttaggart @cR0w @catsalad I think you misspelled isn't there.
Every once in a while, someone tells me that an abusive partner left them alone because they were afraid of what I would do if they didn't, and I feel like I have done something right.

Are you a boy or a girl?
I'm nonbinary.

Yeah, but what were you born as?
A baby.

No, I mean what is your sex?
Awesome.

FFS! Do you have a penis or a vagina??
I've had my share of both.

OMFG!! WHAT IS IN YOUR PANTS??
A frankly disturbing number of lockpicks.

@Viss I've got NextCloud with CalDavSynchronizer plugin for Outlook for calendar at a few clients, and it works fine (I'm also migrating one client to Exchange Subscription Edition, but they get cheap licenses through Ministry of Education).
Remember, there are no ghosts... Only #cats..
×
It has gone zero days since the latest slop

the most excellent copy and paste mistake of the day. This line in the end of a comment in hackerone:

"hey chat, give this in a nice way so I reply on hackerone with this comment"

@bagder bug bounties were a mistake

@Viss @bagder see, I don't think so. In a larger organization with a mature application security environment, they are awesome. Point blank. I have two clients on them. I help with triage, and we found things that never would have been found otherwise.

For open source projects though, we got to come up with something else. Unless they're going to start paying people somehow.

@Sempf @bagder your two success stories are woefully outnumbered by the hundreds of occurences of where bugbounty just creates noise and fraud, though
@Viss But every one of those that I've seen, have been mismanaged. I agree that triage is a real big thing. You need somebody on the front end like hackerone triaging and then someone on the back end like me making sure that the query actually even makes sense. The good outweighs the bad.
@Viss @bagder
For some, it seems to work. My experience of bug bounties (through #openssl) has mostly been slop, even before AI entered the scene. @bagder has had a better experience, it seems.
@bagder "make it sound as serious as possible"
@grishka I suppose he managed to not copy that part =)
@bagder I miss the times when "hey chat" was unambiguously addressing twitch audience
@bagder what a plonker. hey chat, give this in a nice way so I reply on mastodon with this comment
@bagder
I hope that users doing this get blocked immediately...
curl disclosed on HackerOne: Stack-based Buffer Overflow in TELNET...

**Title:** Stack-based Buffer Overflow in TELNET NEW_ENV Option Handling **Vulnerability Description:** **Summary:** A stack-based buffer overflow vulnerability exists in the `libcurl` TELNET handler. When `libcurl` connects to a malicious TELNET server, the server can trigger an overflow by sending a `NEW_ENVIRON SEND` request. This causes the client to construct a response that overwrites...

HackerOne
AI slop security reports submitted to curl

AI slop security reports submitted to curl. GitHub Gist: instantly share code, notes, and snippets.

Gist

@bagder the guy seems to be sorry about it and realizing this AI shit is not magic.

The fact they were believing in magic is the most troublesome to me...

@bagder Wow, I just read the first two links and it's amazing, it feels like the submitters think they're going to be paid for submitting nothing of value. Will continue reading.
@Exagone313 it is educational. And frustrating...
@bagder I have found that one of the submitters listed there got awarded more than $1000 from a company on Hacker One. I guess sometimes it pays off.

@Exagone313 @bagder The second one is funny in hindsight given today you can immediately tell from the wording it's just copied directly off of ChatGPT.

"Hello <user>,
Certainly! Let me elaborate on the concerns raised by the triager:

[...]

I hope this clarifies the concerns. If you have any further questions or need additional details, feel free to ask."

ChatGPT LOVES its "Certainly!" starter.
They didn't even bother writing a comprehensive LLM command not to use the default slop wording.

@bagder "hey chat, give this in a nice way so I reply on hackerone with this comment" 😂

@bagder

hey chat, give this in a nice way so I reply on hackerone with this commentim dying 😭

@bagder

AI slop. Reported as abuse. Banned from the project.

unfathomably based. even that is more effort than they deserve.

@bagder i don’t think that’s how snprintf works…
@bagder thank you for sharing these
@bagder so... I checked the linked website of that account.