5 ms·
Yeah, I discovered a flaw in SSH the other day, if my account on the remote server Is listed in the sudoers file I can escalate to root priviliges, as soon as I
by mutagen 7y ago
Yeah, I discovered a flaw in SSH the other day, if my account on the remote server Is listed in the sudoers file I can escalate to root priviliges, as soon as I create a snazzy logo I'm going to get myself a CVE.
Seriously though, security research is starting to drift into bizarro land, security contacts at companies are inundated with port-scans asking for bug bounties because there's an open port and now people are registering CVEs on expected and documented behavior.
- Hello71 7y agostarting? Raymond Chen has been blogging about bizarre vulnerability reports for almost 13 years now.
- tipsysquid 7y agoI assume you mean this Raymond Chen of Microsoft[0] [0] https://devblogs.microsoft.com/oldnewthing/author/oldnewthing https://devblogs.microsoft.com/oldnewthing/author/oldnewthin...
- dx87 7y agoA couple of years ago someone made a website about the "Grinch" vulnerability, saying it was going to be bigger than shellshock. The "vulnerability" was that members of the "wheel" admin group could use sudo to run commands as root without a password. Needless to say, RedHat replied that it was intended behavior, but not until the researcher got their 15 minutes of fame on a bunch of tech websites. https://access.redhat.com/articles/1298913 https://access.redhat.com/articles/1298913
- userbinator 7y agosecurity research is starting to drift into bizarro land Remember that these people are essentially trying to earn a living by finding vulnerabilities, so it's no surprise that they'll try to spin anything as one, regardless of any other considerations. I've used the term "security vultures" before in reference to such things. It's unfortunate that a lot of companies misunderstand or obey their requests, and in the process useful features are destroyed and software becomes more user-hostile.
- cestith 7y agoPerhaps I'm naive, but I think it is surprising anyone wants to be taken seriously as a researcher in any field and proceeds to publish information that in on its face and with no effort provably false.
- ncmncm 7y agoThrow enough at the wall, some of it might stick. People who have no reputation tend to worry less about their reputation.
- cestith 7y agoI can't reasonably say that doesn't happen. Obviously it does. It may even be a useful tactic in the very short term. It however does not appear to be a very useful decision for a long term career or hobby.
- lucb1e 7y agoSecurity vulture, nice. I'll steal that one! Am a security dude myself but I hadn't heard that one before; it sounds quite apt.
- lucb1e 7y ago> asking for bug bounties Yeah that's just not done. Dutch: kinderen die vragen worden overgeslagen (it rhymes nicely) - kids that ask will be skipped/passed. I.e., if you ask for a reward (or sweets, in a kids' case), you certainly won't get any. If you reward people that report silly stuff and then ask for money, that would be bizarro land indeed.