What is a way to discuss Security???


Recommended Posts

Huh? This is what the forum rules say...

Quote

Do not post links to exploits, malware, or websites that produce undesired effects to our members.
This includes browser crashes, multiple pop-up screens, DOS attacks, or similar results. Links will be removed, threads closed, and members will be warned or suspended.

How does posting links that serve up malware, exploits, or crash my browser protect me or further my education? LOL

If you want to discuss how malware is designed/created there are much better dedicated forums for that.

  • Like 2
On 06/06/2024 at 08:44, Good Bot, Bad Bot said:

Huh? This is what the forum rules say...

How does posting links that serve up malware, exploits, or crash my browser protect me or further my education? LOL

If you want to discuss how malware is designed/created there are much better dedicated forums for that.

Posting discussions of malware that include links also puts our website in legal jeopardy, hence it is not permitted.

On 06/06/2024 at 15:44, Good Bot, Bad Bot said:

Huh? This is what the forum rules say...

How does posting links that serve up malware, exploits, or crash my browser protect me or further my education? LOL

If you want to discuss how malware is designed/created there are much better dedicated forums for that.

actually, it's not a weaponized exploit - i did it not to harm Your or Whoever else Security ==>> i just have pinpointed the Problem & 2nd stage is to discuss how to mitigate that threat.

On 06/06/2024 at 14:50, SarK0Y said:

actually, it's not a weaponized exploit - i did it not to harm Your or Whoever else Security ==>> i just have pinpointed the Problem & 2nd stage is to discuss how to mitigate that threat.

The hosting of the DISCUSSION can put the site into legally contentious grounds!

On 06/06/2024 at 04:23, SarK0Y said:

Forum's Rules forbid to post malware techniques. But how to fight those issues w/o Education & Sharing????  i'm totally confused...

Hello,

As someone whose day job is literally* to educate and share information about malicious software, I would say that it is far more helpful to explain how the malware works, and share information about to prevent, detect and remediate it, is far more valuable than the sharing of samples of said malware.

Regards,

Aryeh Goretsky
 


*I just had my semi-annual review about week and a half ago, and education and sharing figured prominently in it.  Without getting into numbers, management was very happy with my work during the covered timeframe.

On 07/06/2024 at 06:18, goretsky said:

Hello,

As someone whose day job is literally* to educate and share information about malicious software, I would say that it is far more helpful to explain how the malware works, and share information about to prevent, detect and remediate it, is far more valuable than the sharing of samples of said malware.

Regards,

Aryeh Goretsky
 


*I just had my semi-annual review about week and a half ago, and education and sharing figured prominently in it.  Without getting into numbers, management was very happy with my work during the covered timeframe.

frankly, i just follow the simple principle ==>> PoC is needed. 1st PoC is rather harmless, it uses aliases of fish/bash to hijack sudo, then prints silly prompt (partial solution is making  ~/.fishrc & ~/.bashrc only-read). 2nd PoC i made dedicated to just well-prepared Researchers, because it can really harm computer w/ overheating + mechanical damage for hdds is possible too.. Modern operating systems must seriously rethink the way of syscalls. However, most simple solution is downclocking hw, good-ol' bare metal is not that fragile. :)

On 08/06/2024 at 05:33, SarK0Y said:

frankly, i just follow the simple principle ==>> PoC is needed. 1st PoC is rather harmless, it uses aliases of fish/bash to hijack sudo, then prints silly prompt (partial solution is making  ~/.fishrc & ~/.bashrc only-read). 2nd PoC i made dedicated to just well-prepared Researchers, because it can really harm computer w/ overheating + mechanical damage for hdds is possible too.. Modern operating systems must seriously rethink the way of syscalls. However, most simple solution is downclocking hw, good-ol' bare metal is not that fragile. :)

Common sense says that this is not a place for linking to and using POC exploits to discuss security. 

  • Like 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I think you meant the "ntfs3" driver, but yes there have been a lot of fixes for it in this release and previous releases, not 100% sure if the issue you mentioned is fixed though. In any case, the new "ntfs" driver in 7.1 doesn't have that issue (at least, no reports of such have come thru), but your kernel needs to explicitly enable support for the new driver first (like how CachyOS kernel has it), and you need to edit your mount points in /etc/fstab to use "ntfs" instead of the other drivers.
    • Epic Games says Unreal Engine 6 will help developers "build content faster" using AI models by Pulasthi Ariyasinghe Epic Games is rolling out the latest major update to Unreal Engine 5 today, and at the same time, the company also dropped some information on the next-generation version of the product, Unreal Engine 6. This was already revealed a few weeks ago alongside the new Rocket League upgrade reveal. The company says it is combining the features of Unreal Engine and Unreal Editor for Fortnite to create this new version of its popular media creation tool. On top of creating entire games, the new engine will also focus on letting developers operate large-scale live service titles more easily, whether by shipping content into their own ecosystems or into Fortnite. The use of large language models is also mentioned here, with Epic saying it will be a core part of the engine. "We see LLMs, generative AI models, and tools like Claude and Codex playing a central role in helping you build content faster while maintaining the creative control you need," adds the company. Here is the rundown of what's new about version 6 of Unreal Engine: With all these changes to the programming model, portability upgrades, and generative AI integration, Epic says the new version of the engine will "change a lot about how games are made." The company aims to ship Unreal Engine 6 into early access in late 2027, with a full release planned for 12-18 months later. Epic Games also dropped a lengthy blog post about the new Unreal Engine 5.8 update for game developers over here. The release is focused on delivering better performance, customization, and streamlined workflows for development teams. This will be the final major update for this version of the engine before Epic switches to focus fully on Unreal Engine 6's early access launch.
    • Watch Louis Rossmann's recent experience on YouTube about trying to get a warranty replacement from Samsung. It's crazy.
    • That is the thing, how many of these people don't realise they are using AI? If they use Google Search they have no choice but to use AI. So yes, maybe half of American adults do use and I expect a lot of Uk adults do to, but I bet most of them don't realise it. Myself, i avoid the rubbish.
    • They use FREE AI. They aren't paying for this meme-generating slopware...
  • Recent Achievements

    • One Month Later
      Vincian earned a badge
      One Month Later
    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      499
    2. 2
      +Edouard
      163
    3. 3
      PsYcHoKiLLa
      88
    4. 4
      Steven P.
      69
    5. 5
      neufuse
      65
  • Tell a friend

    Love Neowin? Tell a friend!