Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
niklasb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Exploit writeup: macOS Safari sandbox escape and kernel privilege escalation
(phoenhex.re)
3 points
by
niklasb
7y ago
|
1 comments
2.
▲
by
niklasb
8y ago
By that time that researcher had already been paid by the company running the SecuriTeam program. Admittedly Oracle did release the patch too early, but this was clearly by accident, since they usually never release security patches outside
3.
▲
by
niklasb
8y ago
To give a bit of context to this discussion: Oracle does not and has never had a bug bounty program. Honestly Oracle does not even play a big role in this. From my experience with reporting VirtualBox bugs to them, they usually handle them
4.
▲
by
niklasb
8y ago
The bug is in the VirtualBox code that emulates an Intel E1000 device. There is no driver code involved.
5.
▲
by
niklasb
8y ago
I think the author is referring to third parties which buy and disclose vulnerabilities. Very hard to monetize. There is already a flourishing market for undisclosed vulnerabilities, for obvious reasons.
6.
▲
Fuzzing Counter-Strike: Global Offensive Maps Files with AFL
(phoenhex.re)
2 points
by
niklasb
8y ago
|
0 comments