TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The day I trolled the entire internet: accidental research project CVE-2020-1350

56 pointsby beefhashalmost 5 years ago

10 comments

kerngalmost 5 years ago
This post requires a lot of context to make sense out of. Unless you are in the security space and familiar with what happened last 36 hours, it probably won&#x27;t make much sense quickly.<p>1) Microsoft has a critical flaw in DNS server<p>2) A security company publishes the info - no public exploit available at this point<p>3) Someone creates a fake exploit - playing a prank on hackers and other security companies<p>4) Lots of people ran the prank code or helped spread the existence of the fake exploit<p>Not sure if this makes it easier to understand- at least I tried. :)
speedgoosealmost 5 years ago
This is very difficult to read and understand.
评论 #23850857 未加载
评论 #23851052 未加载
评论 #23850665 未加载
stedanielsalmost 5 years ago
Took one glance at the shell script piping curl to bash and red flags went up everywhere! Not only piping curl to bash, but doing it via a bit.ly link. Then Twitter and the media started to pick it up and pass it on unverified. I should have been shocked, but I wasn&#x27;t. I&#x27;d love to see the bit.ly stats for the short URLs added to the article.
3pt14159almost 5 years ago
I&#x27;m sure people are stupid, I&#x27;ve seen it myself too many times to count, but how does he know that these weren&#x27;t executed in a VM? A couple hundred shells isn&#x27;t so much that I&#x27;d rule out that some non-trivial fraction of them were under analysis.
petercooperalmost 5 years ago
I imagine the reason this doesn&#x27;t happen too often in serious domains is because the next time the person says&#x2F;posts anything, will they be believed without checking their claims? Of course, in security, this may even be a good thing?(!) :-)
Sodmanalmost 5 years ago
I think the interesting thing here is that outlets like Vulcan picked it up and wrote about it with authority. Linking to the repo from these &quot;trusted&quot; sources likely gave it a lot more credibility than it would otherwise have received.
dapidsalmost 5 years ago
Is the blog post fake too? Seriously, this was hard to read...
floatingatollalmost 5 years ago
I was unable to scroll this article on mobile to read it. It seems like it could be interesting, but it’s too bad about the technical obstacles to doing so.
_tk_almost 5 years ago
With the numbers shown &quot;the entire internet&quot; is really more than exaggerated and thus the title seems pretty clickbait-y.
curiousgalalmost 5 years ago
TL;DR: posted fake PoC on GitHub. (I think, the post is littered with embedded tweets and memes, super hard to read or make sense of any of it)
评论 #23850695 未加载