What is a way to discuss Security???


Recommended Posts

Huh? This is what the forum rules say...

Quote

Do not post links to exploits, malware, or websites that produce undesired effects to our members.
This includes browser crashes, multiple pop-up screens, DOS attacks, or similar results. Links will be removed, threads closed, and members will be warned or suspended.

How does posting links that serve up malware, exploits, or crash my browser protect me or further my education? LOL

If you want to discuss how malware is designed/created there are much better dedicated forums for that.

  • Like 2
On 06/06/2024 at 08:44, Good Bot, Bad Bot said:

Huh? This is what the forum rules say...

How does posting links that serve up malware, exploits, or crash my browser protect me or further my education? LOL

If you want to discuss how malware is designed/created there are much better dedicated forums for that.

Posting discussions of malware that include links also puts our website in legal jeopardy, hence it is not permitted.

On 06/06/2024 at 15:44, Good Bot, Bad Bot said:

Huh? This is what the forum rules say...

How does posting links that serve up malware, exploits, or crash my browser protect me or further my education? LOL

If you want to discuss how malware is designed/created there are much better dedicated forums for that.

actually, it's not a weaponized exploit - i did it not to harm Your or Whoever else Security ==>> i just have pinpointed the Problem & 2nd stage is to discuss how to mitigate that threat.

On 06/06/2024 at 14:50, SarK0Y said:

actually, it's not a weaponized exploit - i did it not to harm Your or Whoever else Security ==>> i just have pinpointed the Problem & 2nd stage is to discuss how to mitigate that threat.

The hosting of the DISCUSSION can put the site into legally contentious grounds!

On 06/06/2024 at 04:23, SarK0Y said:

Forum's Rules forbid to post malware techniques. But how to fight those issues w/o Education & Sharing????  i'm totally confused...

Hello,

As someone whose day job is literally* to educate and share information about malicious software, I would say that it is far more helpful to explain how the malware works, and share information about to prevent, detect and remediate it, is far more valuable than the sharing of samples of said malware.

Regards,

Aryeh Goretsky
 


*I just had my semi-annual review about week and a half ago, and education and sharing figured prominently in it.  Without getting into numbers, management was very happy with my work during the covered timeframe.

On 07/06/2024 at 06:18, goretsky said:

Hello,

As someone whose day job is literally* to educate and share information about malicious software, I would say that it is far more helpful to explain how the malware works, and share information about to prevent, detect and remediate it, is far more valuable than the sharing of samples of said malware.

Regards,

Aryeh Goretsky
 


*I just had my semi-annual review about week and a half ago, and education and sharing figured prominently in it.  Without getting into numbers, management was very happy with my work during the covered timeframe.

frankly, i just follow the simple principle ==>> PoC is needed. 1st PoC is rather harmless, it uses aliases of fish/bash to hijack sudo, then prints silly prompt (partial solution is making  ~/.fishrc & ~/.bashrc only-read). 2nd PoC i made dedicated to just well-prepared Researchers, because it can really harm computer w/ overheating + mechanical damage for hdds is possible too.. Modern operating systems must seriously rethink the way of syscalls. However, most simple solution is downclocking hw, good-ol' bare metal is not that fragile. :)

On 08/06/2024 at 05:33, SarK0Y said:

frankly, i just follow the simple principle ==>> PoC is needed. 1st PoC is rather harmless, it uses aliases of fish/bash to hijack sudo, then prints silly prompt (partial solution is making  ~/.fishrc & ~/.bashrc only-read). 2nd PoC i made dedicated to just well-prepared Researchers, because it can really harm computer w/ overheating + mechanical damage for hdds is possible too.. Modern operating systems must seriously rethink the way of syscalls. However, most simple solution is downclocking hw, good-ol' bare metal is not that fragile. :)

Common sense says that this is not a place for linking to and using POC exploits to discuss security. 

  • Like 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Hello, I have used a few TEAM Group SSDs, USB flash drives, and Micro SDXC cards in the past. They all seemed to work fine. Regards, Aryeh Goretsky
    • "just $100 per TB"? Just? Are we trying to make this seem like the new normal? Kinda weird to make it sound like that is not a ridiculously expensive asking price.
    • The reviews you refer to mean nothing. Where there is no journalism there is no reason to call the gaming media's opinion pieces "reviews". For GP games there is indeed a metric for success - increasing subscriptions. Which turns in revenue. The only circumstance in which subs do not rise when great is being released is a Game Pass system where the company is close to fully saturated with customers in a subscription. However, in that case as the theory goes you spend aplenty in all kind of games - from shady live service cash cows and customer offending agitprop crap in purple colours to robust and entertaining single player games. And keep a solid level of profitability. Ignoring the simply innocuous but mid games MGS has released primarily of the second kind.
    • Report: Microsoft to use AWS to help GitHub deal with a major surge in demand by Pradeep Viswanathan Thanks to the surge of coding AI agents, GitHub's usage has skyrocketed over the past 12 months. To meet this demand, GitHub started with a plan in October 2025 to increase capacity by 10x. However, by early this year, the company realized that it needed 30x scale. This rapid growth has caused severe strain on the platform's reliability, resulting in several small outages over the past few months. In April, GitHub published a long blog post explaining the steps it is taking to resolve these reliability issues. In the post, the company also confirmed that it is working toward a multi-cloud architecture for better resilience. Today, Business Insider reported that GitHub is turning to Amazon Web Services to help deal with a major surge in AI-driven coding activity. It is important to note that GitHub is still in the process of moving completely to the Azure cloud. The current plan is to move the platform fully to Azure by 2027 so that it can scale better as per developer demand. Therefore, the current decision to utilize AWS might be part of a short-term plan to meet immediate demand. A Microsoft spokesperson confirmed that GitHub is using multiple cloud providers with the following statement: For Microsoft, the decision highlights the operational pressure behind the AI boom. GitHub has to stay reliable for developers at a time when rivals such as Codex, Cursor, Claude Code, and other AI coding tools are gaining attention. And the decision to use AWS for computing capacity seems practical given the circumstances.
    • It's growing on me, however, your right, it make better usability sense if the tabs were bellow the address bar.
  • Recent Achievements

    • Collaborator
      vjlex earned a badge
      Collaborator
    • Reacting Well
      Dys Topia earned a badge
      Reacting Well
    • Conversation Starter
      NovaEdgeX earned a badge
      Conversation Starter
    • One Year In
      Console General earned a badge
      One Year In
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      +Edouard
      182
    3. 3
      PsYcHoKiLLa
      106
    4. 4
      Steven P.
      88
    5. 5
      ATLien_0
      68
  • Tell a friend

    Love Neowin? Tell a friend!