4 ms·
So I downloaded the files and poked around the Python code. The code looked positively amateurish, not in its functionality (I'm sure it works) but in the codi
by waterside81 10y ago
So I downloaded the files and poked around the Python code. The code looked positively amateurish, not in its functionality (I'm sure it works) but in the coding style. I'm not sure what I expected, but the formatting, the types of comments, it all looked like it was written by someone who just started out with Python. Maybe it was written very hastily, I don't know, but I encourage others to take a look. It's interesting to see the source for this kind of stuff.
- chinathrow 10y agoMaybe the coding style was done on purpose to defend against attribution?
- verroq 10y agoMost hardcore reversers/exploit devs are not software engineers.
- msane 10y agoBe careful what you say.
- angry_octet 10y agoSurely a better way to defend against that is to perform some automated program transformation? Like this minifier: https://liftoff.github.io/pyminifier/ https://liftoff.github.io/pyminifier/ It would be interesting to see how various stylistic fingerprints analysis points survive lexical washing, a la https://freedom-to-tinker.com/blog/aylin/anonymous-programmers-can-be-identified-by-analyzing-coding-style/ https://freedom-to-tinker.com/blog/aylin/anonymous-programme...
- StavrosK 10y agoHere's a sample: https://www.pastery.net/fcugdj/ https://www.pastery.net/fcugdj/
- klue07 10y agoMany people in infosec generally learn programming on their own and only code for their own need. They don't care about coding style, small optimizations, programming best practices, etc.
- DavidWanjiru 10y agoI'm curious if this has to do with their generally broken English, as I read on what I think was their blog post. Does English proficiency affect coding "fluency", seeing as you are coding in English?
- segmondy 10y agoIt looks exactly like I expect. It looks like what was written by a hacker. The end goal is to solve a problem. This code was not generated from a business requirements. It was not written for others to maintain. It's not going to be changing. It doesn't need tests. The author understands it and needs minimal comments. There is no need to make it object oriented, use design patterns or make it fancy. There are lots of such sources online. Here is an exploit for the stagefright/python code https://github.com/jduck/cve-2015-1538-1/blob/master/Stagefright_CVE-2015-1538-1_Exploit.py https://github.com/jduck/cve-2015-1538-1/blob/master/Stagefr... Here is another exploit in ruby, https://github.com/jduck/addjsif/blob/master/add_js_interface_mitm.rb https://github.com/jduck/addjsif/blob/master/add_js_interfac...
- MatthiasP 10y agoIf we assume that the code really comes from a member of the "Equation Team" and we trust the conclusion from Kaspersky that those people are among the upper echelons of NSA hacker groups it is maybe a good point in time that we give our expectations a reality check. What counts in the real world is that it gets the job done, unfortunately no time for fancy pythonic delicacies or experiments in functional coding paradigms. Sorry for the little rant and nothing personal, I just find critizicing other people's code without considering the constraints under it was created an extremely annoying habit among my fellow coders.