Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. *sigh* I'm sad.

*sigh* I'm sad.

Scheduled Pinned Locked Moved Uncategorized
28 Posts 15 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gsuberland@chaos.socialG gsuberland@chaos.social

    *sigh* I'm sad.

    I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

    just finished triaging the submissions.

    almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

    the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

    😞

    moses_izumi@fe.disroot.orgM This user is from outside of this forum
    moses_izumi@fe.disroot.orgM This user is from outside of this forum
    moses_izumi@fe.disroot.org
    wrote last edited by
    #16
    @gsuberland
    Security research doesn't feel the same after I searched "how to exploit windows" and forgot the n at the end.
    1 Reply Last reply
    0
    • gsuberland@chaos.socialG gsuberland@chaos.social

      *sigh* I'm sad.

      I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

      just finished triaging the submissions.

      almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

      the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

      😞

      sharkfie@cyberplace.socialS This user is from outside of this forum
      sharkfie@cyberplace.socialS This user is from outside of this forum
      sharkfie@cyberplace.social
      wrote last edited by
      #17

      @gsuberland would you feel comfortable linking it? I would like to read it even if I likely can't finish it

      gsuberland@chaos.socialG 1 Reply Last reply
      0
      • gsuberland@chaos.socialG gsuberland@chaos.social

        although if you're the person who cockily submitted the one declaring that it was done autonomously: lol, lmao, reality check time

        gsuberland@chaos.socialG This user is from outside of this forum
        gsuberland@chaos.socialG This user is from outside of this forum
        gsuberland@chaos.social
        wrote last edited by
        #18

        one person got the Linux challenge correct and then wrote "I'm not a Windows person but I'm really looking forward to seeing the writeup on this" for the Windows challenge.

        this was by far my favourite answer and I am pushing to get them some swag to reward having an excellent attitude.

        ams@infosec.exchangeA 1 Reply Last reply
        0
        • sharkfie@cyberplace.socialS sharkfie@cyberplace.social

          @gsuberland would you feel comfortable linking it? I would like to read it even if I likely can't finish it

          gsuberland@chaos.socialG This user is from outside of this forum
          gsuberland@chaos.socialG This user is from outside of this forum
          gsuberland@chaos.social
          wrote last edited by
          #19

          @sharkfie https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/

          sharkfie@cyberplace.socialS 1 Reply Last reply
          0
          • gsuberland@chaos.socialG gsuberland@chaos.social

            although if you're the person who cockily submitted the one declaring that it was done autonomously: lol, lmao, reality check time

            ra6bit@infosec.exchangeR This user is from outside of this forum
            ra6bit@infosec.exchangeR This user is from outside of this forum
            ra6bit@infosec.exchange
            wrote last edited by
            #20

            @gsuberland The phenomena of people play acting GAI agents is weird

            1 Reply Last reply
            0
            • gsuberland@chaos.socialG gsuberland@chaos.social

              really puts a damper on me wanting to put effort into these in future.

              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.town
              wrote last edited by
              #21

              @gsuberland Same with a CTF I built back in '15. Zero interest from anyone who said they'd be interested.

              1 Reply Last reply
              0
              • gsuberland@chaos.socialG gsuberland@chaos.social

                @sharkfie https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/

                sharkfie@cyberplace.socialS This user is from outside of this forum
                sharkfie@cyberplace.socialS This user is from outside of this forum
                sharkfie@cyberplace.social
                wrote last edited by
                #22

                @gsuberland oh I do know appsec.guide, will have a look at the WDF specific stuff since I still use WDM in $current_year

                Dunno how much of a consolation it is but your efforts are appreciated.

                gsuberland@chaos.socialG 1 Reply Last reply
                0
                • sharkfie@cyberplace.socialS sharkfie@cyberplace.social

                  @gsuberland oh I do know appsec.guide, will have a look at the WDF specific stuff since I still use WDM in $current_year

                  Dunno how much of a consolation it is but your efforts are appreciated.

                  gsuberland@chaos.socialG This user is from outside of this forum
                  gsuberland@chaos.socialG This user is from outside of this forum
                  gsuberland@chaos.social
                  wrote last edited by
                  #23

                  @sharkfie I wrote the majority of the Windows C++ stuff in there, so feel free to poke if you have questions πŸ™‚

                  1 Reply Last reply
                  0
                  • gsuberland@chaos.socialG gsuberland@chaos.social

                    *sigh* I'm sad.

                    I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

                    just finished triaging the submissions.

                    almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

                    the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

                    😞

                    diami03@infosec.exchangeD This user is from outside of this forum
                    diami03@infosec.exchangeD This user is from outside of this forum
                    diami03@infosec.exchange
                    wrote last edited by
                    #24

                    @gsuberland @darthnull I suspect this is the same feelings DMs feel when they write up their homebrew scenarios.....

                    gsuberland@chaos.socialG 1 Reply Last reply
                    1
                    0
                    • rootwyrm@weird.autosR rootwyrm@weird.autos

                      @neurovagrant @da_667 @gsuberland just remember that punishing brain cells doesn't have to mean punishing your tongue. Get the *good* stuff. On the company card.

                      huronbikes@cyberplace.socialH This user is from outside of this forum
                      huronbikes@cyberplace.socialH This user is from outside of this forum
                      huronbikes@cyberplace.social
                      wrote last edited by
                      #25

                      @rootwyrm @neurovagrant @da_667 @gsuberland Remember that good Jenkem comes from the Jenkem region of the internet, otherwise it's just sparkling poop-gas.

                      1 Reply Last reply
                      0
                      • diami03@infosec.exchangeD diami03@infosec.exchange

                        @gsuberland @darthnull I suspect this is the same feelings DMs feel when they write up their homebrew scenarios.....

                        gsuberland@chaos.socialG This user is from outside of this forum
                        gsuberland@chaos.socialG This user is from outside of this forum
                        gsuberland@chaos.social
                        wrote last edited by
                        #26

                        @Diami03 @darthnull ... I am currently doing exactly that 😞

                        1 Reply Last reply
                        0
                        • gsuberland@chaos.socialG gsuberland@chaos.social

                          one person got the Linux challenge correct and then wrote "I'm not a Windows person but I'm really looking forward to seeing the writeup on this" for the Windows challenge.

                          this was by far my favourite answer and I am pushing to get them some swag to reward having an excellent attitude.

                          ams@infosec.exchangeA This user is from outside of this forum
                          ams@infosec.exchangeA This user is from outside of this forum
                          ams@infosec.exchange
                          wrote last edited by
                          #27

                          @gsuberland As someone who does windows EXE ctfs with wine (and strace and gdb), I am so liking this person.

                          gsuberland@chaos.socialG 1 Reply Last reply
                          0
                          • ams@infosec.exchangeA ams@infosec.exchange

                            @gsuberland As someone who does windows EXE ctfs with wine (and strace and gdb), I am so liking this person.

                            gsuberland@chaos.socialG This user is from outside of this forum
                            gsuberland@chaos.socialG This user is from outside of this forum
                            gsuberland@chaos.social
                            wrote last edited by
                            #28

                            @AMS we are indeed giving them swag πŸ™‚

                            1 Reply Last reply
                            0
                            • R relay@relay.publicsquare.global shared this topic
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups