What is a way to discuss Security???


Recommended Posts

Huh? This is what the forum rules say...

Quote

Do not post links to exploits, malware, or websites that produce undesired effects to our members.
This includes browser crashes, multiple pop-up screens, DOS attacks, or similar results. Links will be removed, threads closed, and members will be warned or suspended.

How does posting links that serve up malware, exploits, or crash my browser protect me or further my education? LOL

If you want to discuss how malware is designed/created there are much better dedicated forums for that.

  • Like 2
On 06/06/2024 at 08:44, Good Bot, Bad Bot said:

Huh? This is what the forum rules say...

How does posting links that serve up malware, exploits, or crash my browser protect me or further my education? LOL

If you want to discuss how malware is designed/created there are much better dedicated forums for that.

Posting discussions of malware that include links also puts our website in legal jeopardy, hence it is not permitted.

On 06/06/2024 at 15:44, Good Bot, Bad Bot said:

Huh? This is what the forum rules say...

How does posting links that serve up malware, exploits, or crash my browser protect me or further my education? LOL

If you want to discuss how malware is designed/created there are much better dedicated forums for that.

actually, it's not a weaponized exploit - i did it not to harm Your or Whoever else Security ==>> i just have pinpointed the Problem & 2nd stage is to discuss how to mitigate that threat.

On 06/06/2024 at 14:50, SarK0Y said:

actually, it's not a weaponized exploit - i did it not to harm Your or Whoever else Security ==>> i just have pinpointed the Problem & 2nd stage is to discuss how to mitigate that threat.

The hosting of the DISCUSSION can put the site into legally contentious grounds!

On 06/06/2024 at 04:23, SarK0Y said:

Forum's Rules forbid to post malware techniques. But how to fight those issues w/o Education & Sharing????  i'm totally confused...

Hello,

As someone whose day job is literally* to educate and share information about malicious software, I would say that it is far more helpful to explain how the malware works, and share information about to prevent, detect and remediate it, is far more valuable than the sharing of samples of said malware.

Regards,

Aryeh Goretsky
 


*I just had my semi-annual review about week and a half ago, and education and sharing figured prominently in it.  Without getting into numbers, management was very happy with my work during the covered timeframe.

On 07/06/2024 at 06:18, goretsky said:

Hello,

As someone whose day job is literally* to educate and share information about malicious software, I would say that it is far more helpful to explain how the malware works, and share information about to prevent, detect and remediate it, is far more valuable than the sharing of samples of said malware.

Regards,

Aryeh Goretsky
 


*I just had my semi-annual review about week and a half ago, and education and sharing figured prominently in it.  Without getting into numbers, management was very happy with my work during the covered timeframe.

frankly, i just follow the simple principle ==>> PoC is needed. 1st PoC is rather harmless, it uses aliases of fish/bash to hijack sudo, then prints silly prompt (partial solution is making  ~/.fishrc & ~/.bashrc only-read). 2nd PoC i made dedicated to just well-prepared Researchers, because it can really harm computer w/ overheating + mechanical damage for hdds is possible too.. Modern operating systems must seriously rethink the way of syscalls. However, most simple solution is downclocking hw, good-ol' bare metal is not that fragile. :)

On 08/06/2024 at 05:33, SarK0Y said:

frankly, i just follow the simple principle ==>> PoC is needed. 1st PoC is rather harmless, it uses aliases of fish/bash to hijack sudo, then prints silly prompt (partial solution is making  ~/.fishrc & ~/.bashrc only-read). 2nd PoC i made dedicated to just well-prepared Researchers, because it can really harm computer w/ overheating + mechanical damage for hdds is possible too.. Modern operating systems must seriously rethink the way of syscalls. However, most simple solution is downclocking hw, good-ol' bare metal is not that fragile. :)

Common sense says that this is not a place for linking to and using POC exploits to discuss security. 

  • Like 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • PDF Shaper 15.6 by Razvan Serea PDF Shaper is a set of feature-rich PDF software that makes it simple to split, merge, watermark, sign, optimize, convert, encrypt and decrypt your PDF documents, also delete and move pages, extract text and images. The program is optimized for low CPU resource usage and operates in batch mode, allowing users to process multiple PDF files while doing other work on their computers. PDF Shaper is available in three editions - Free, Premium and Ultimate. Compare and pick edition which is suitable for you. Compatible with Windows 7, 8, 10, 11. Features: Convert PDFs to Word, text, or image files (and vice versa) Merge, split, and watermark documents with precision Insert, move, delete, rotate and crop pages/ranges Rename and organize PDF collections efficiently Encrypt with advanced AES password protection Apply multiple digital signatures for documents Extract text, images, or complete pages from any PDF Benefits: Easy-to-use, intuitive user interface Low CPU resource usage during any process, including conversion Free for personal use and for any non-commercial organization Supports Unicode characters Supports batch processing for any operation Small installation size PDF Shaper 15.6 changelog: Improved overall program performance. Improved image rendering in all tools. Improved XMP information extraction. Improved compatibility with ARM64 systems. Improved DOC to PDF conversion: Improved support for font files. Improved support for picture cropping. Improved support for list formatting. Improved support for text line spacing. Download: PDF Shaper 15.6 | 8.0 MB (Free for personal use only) Link: PDF Shaper Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Yeah, this is absolutely nothing new and EA have done it before. Burnout Paradise, released in 2008, had dynamic advertising billboards that were updated via the internet and targeted people based on location and what EA knew about them from their profile. It was particularly notable for the fact that the Obama presidential campaign ran ads in the game, in an attempt to reach a younger audience who didn't watch broadcast TV any more. It was by no means the first though. Battlefield 2142 from 2006 had the same thing. In fact, Neowin wrote a story about it back then. https://www.neowin.net/news/ba...-in-game-ads-clarification/
    • This is obviously aimed at the education where Apple has lost so much ground to Chromebooks in the last few years, but unless they come up with a comparable management system for education why would anyone switch back?
    • Here's how we arrived at that claim: Note that this is just Play Store downloads. The app is also available on the Galaxy App Store
    • Google Play states the app had more than 50 million downloads. What other metric do you suggest should be used?
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      531
    2. 2
      +Edouard
      206
    3. 3
      PsYcHoKiLLa
      130
    4. 4
      Steven P.
      90
    5. 5
      neufuse
      74
  • Tell a friend

    Love Neowin? Tell a friend!