Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. *sigh* I'm sad.

*sigh* I'm sad.

Scheduled Pinned Locked Moved Uncategorized
28 Posts 15 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gsuberland@chaos.socialG gsuberland@chaos.social

    *sigh* I'm sad.

    I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

    just finished triaging the submissions.

    almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

    the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

    😞

    darthnull@infosec.exchangeD This user is from outside of this forum
    darthnull@infosec.exchangeD This user is from outside of this forum
    darthnull@infosec.exchange
    wrote last edited by
    #6

    @gsuberland Bummer. Half the fun of making challenges is seeing others have fun with it (and the other half is seeing them learn from the experience).

    Sounds like you got very little of either. 😞

    gsuberland@chaos.socialG 1 Reply Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    • gsuberland@chaos.socialG gsuberland@chaos.social

      really puts a damper on me wanting to put effort into these in future.

      da_667@infosec.exchangeD This user is from outside of this forum
      da_667@infosec.exchangeD This user is from outside of this forum
      da_667@infosec.exchange
      wrote last edited by
      #7

      @gsuberland motivated to do some work

      open up RSS feed

      every fucking story for the past week is AI horse shit.

      eyes the bottle of vodka in the kitchen

      neurovagrant@masto.deoan.orgN 1 Reply Last reply
      0
      • darthnull@infosec.exchangeD darthnull@infosec.exchange

        @gsuberland Bummer. Half the fun of making challenges is seeing others have fun with it (and the other half is seeing them learn from the experience).

        Sounds like you got very little of either. 😞

        gsuberland@chaos.socialG This user is from outside of this forum
        gsuberland@chaos.socialG This user is from outside of this forum
        gsuberland@chaos.social
        wrote last edited by
        #8

        @darthnull yeah it's pretty demotivating to see people lacking the curiosity to experiment and learn when someone gives them an opportunity to do so.

        in fact the answers I appreciated the most were the few that said "I have no idea but I'm looking forward to reading the writeup".

        xabean@infosec.exchangeX 1 Reply Last reply
        0
        • da_667@infosec.exchangeD da_667@infosec.exchange

          @gsuberland motivated to do some work

          open up RSS feed

          every fucking story for the past week is AI horse shit.

          eyes the bottle of vodka in the kitchen

          neurovagrant@masto.deoan.orgN This user is from outside of this forum
          neurovagrant@masto.deoan.orgN This user is from outside of this forum
          neurovagrant@masto.deoan.org
          wrote last edited by
          #9

          @da_667 @gsuberland i'm past the vodka and nearing the "huffing spraypaint in a parking lot" stage

          da_667@infosec.exchangeD 1 Reply Last reply
          0
          • gsuberland@chaos.socialG gsuberland@chaos.social

            @darthnull yeah it's pretty demotivating to see people lacking the curiosity to experiment and learn when someone gives them an opportunity to do so.

            in fact the answers I appreciated the most were the few that said "I have no idea but I'm looking forward to reading the writeup".

            xabean@infosec.exchangeX This user is from outside of this forum
            xabean@infosec.exchangeX This user is from outside of this forum
            xabean@infosec.exchange
            wrote last edited by
            #10

            @gsuberland @darthnull someone highlighted a difference that feels right to me based on what I've seen in myself and good friends I respect and trust:

            There's two classes of people, those who like the art/practice of software development and get enrichment out of that process, and those who enjoy building and shipping a thing.

            The former finds AI revolting, the other finds AI extremely enticing.

            1 Reply Last reply
            0
            • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

              @da_667 @gsuberland i'm past the vodka and nearing the "huffing spraypaint in a parking lot" stage

              da_667@infosec.exchangeD This user is from outside of this forum
              da_667@infosec.exchangeD This user is from outside of this forum
              da_667@infosec.exchange
              wrote last edited by
              #11

              @neurovagrant @gsuberland let's do whippets together to forget everything.

              neurovagrant@masto.deoan.orgN gary_alderson@infosec.exchangeG 2 Replies Last reply
              0
              • da_667@infosec.exchangeD da_667@infosec.exchange

                @neurovagrant @gsuberland let's do whippets together to forget everything.

                neurovagrant@masto.deoan.orgN This user is from outside of this forum
                neurovagrant@masto.deoan.orgN This user is from outside of this forum
                neurovagrant@masto.deoan.org
                wrote last edited by
                #12

                @da_667 @gsuberland i'm just coming to the conclusion that our problem is we have too many braincells, so it's time to punish them.

                rootwyrm@weird.autosR gary_alderson@infosec.exchangeG 2 Replies Last reply
                0
                • da_667@infosec.exchangeD da_667@infosec.exchange

                  @neurovagrant @gsuberland let's do whippets together to forget everything.

                  gary_alderson@infosec.exchangeG This user is from outside of this forum
                  gary_alderson@infosec.exchangeG This user is from outside of this forum
                  gary_alderson@infosec.exchange
                  wrote last edited by
                  #13

                  @da_667 @neurovagrant @gsuberland

                  Link Preview Image
                  1 Reply Last reply
                  0
                  • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                    @da_667 @gsuberland i'm just coming to the conclusion that our problem is we have too many braincells, so it's time to punish them.

                    rootwyrm@weird.autosR This user is from outside of this forum
                    rootwyrm@weird.autosR This user is from outside of this forum
                    rootwyrm@weird.autos
                    wrote last edited by
                    #14

                    @neurovagrant @da_667 @gsuberland just remember that punishing brain cells doesn't have to mean punishing your tongue. Get the *good* stuff. On the company card.

                    huronbikes@cyberplace.socialH 1 Reply Last reply
                    0
                    • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                      @da_667 @gsuberland i'm just coming to the conclusion that our problem is we have too many braincells, so it's time to punish them.

                      gary_alderson@infosec.exchangeG This user is from outside of this forum
                      gary_alderson@infosec.exchangeG This user is from outside of this forum
                      gary_alderson@infosec.exchange
                      wrote last edited by
                      #15

                      @neurovagrant @da_667 @gsuberland minor recreational drug use is not bad and in this economy probably mandatory #moderation #soft cell #precursors

                      1 Reply Last reply
                      0
                      • gsuberland@chaos.socialG gsuberland@chaos.social

                        *sigh* I'm sad.

                        I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

                        just finished triaging the submissions.

                        almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

                        the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

                        😞

                        moses_izumi@fe.disroot.orgM This user is from outside of this forum
                        moses_izumi@fe.disroot.orgM This user is from outside of this forum
                        moses_izumi@fe.disroot.org
                        wrote last edited by
                        #16
                        @gsuberland
                        Security research doesn't feel the same after I searched "how to exploit windows" and forgot the n at the end.
                        1 Reply Last reply
                        0
                        • gsuberland@chaos.socialG gsuberland@chaos.social

                          *sigh* I'm sad.

                          I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

                          just finished triaging the submissions.

                          almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

                          the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

                          😞

                          sharkfie@cyberplace.socialS This user is from outside of this forum
                          sharkfie@cyberplace.socialS This user is from outside of this forum
                          sharkfie@cyberplace.social
                          wrote last edited by
                          #17

                          @gsuberland would you feel comfortable linking it? I would like to read it even if I likely can't finish it

                          gsuberland@chaos.socialG 1 Reply Last reply
                          0
                          • gsuberland@chaos.socialG gsuberland@chaos.social

                            although if you're the person who cockily submitted the one declaring that it was done autonomously: lol, lmao, reality check time

                            gsuberland@chaos.socialG This user is from outside of this forum
                            gsuberland@chaos.socialG This user is from outside of this forum
                            gsuberland@chaos.social
                            wrote last edited by
                            #18

                            one person got the Linux challenge correct and then wrote "I'm not a Windows person but I'm really looking forward to seeing the writeup on this" for the Windows challenge.

                            this was by far my favourite answer and I am pushing to get them some swag to reward having an excellent attitude.

                            ams@infosec.exchangeA 1 Reply Last reply
                            0
                            • sharkfie@cyberplace.socialS sharkfie@cyberplace.social

                              @gsuberland would you feel comfortable linking it? I would like to read it even if I likely can't finish it

                              gsuberland@chaos.socialG This user is from outside of this forum
                              gsuberland@chaos.socialG This user is from outside of this forum
                              gsuberland@chaos.social
                              wrote last edited by
                              #19

                              @sharkfie https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/

                              sharkfie@cyberplace.socialS 1 Reply Last reply
                              0
                              • gsuberland@chaos.socialG gsuberland@chaos.social

                                although if you're the person who cockily submitted the one declaring that it was done autonomously: lol, lmao, reality check time

                                ra6bit@infosec.exchangeR This user is from outside of this forum
                                ra6bit@infosec.exchangeR This user is from outside of this forum
                                ra6bit@infosec.exchange
                                wrote last edited by
                                #20

                                @gsuberland The phenomena of people play acting GAI agents is weird

                                1 Reply Last reply
                                0
                                • gsuberland@chaos.socialG gsuberland@chaos.social

                                  really puts a damper on me wanting to put effort into these in future.

                                  drwho@masto.hackers.townD This user is from outside of this forum
                                  drwho@masto.hackers.townD This user is from outside of this forum
                                  drwho@masto.hackers.town
                                  wrote last edited by
                                  #21

                                  @gsuberland Same with a CTF I built back in '15. Zero interest from anyone who said they'd be interested.

                                  1 Reply Last reply
                                  0
                                  • gsuberland@chaos.socialG gsuberland@chaos.social

                                    @sharkfie https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/

                                    sharkfie@cyberplace.socialS This user is from outside of this forum
                                    sharkfie@cyberplace.socialS This user is from outside of this forum
                                    sharkfie@cyberplace.social
                                    wrote last edited by
                                    #22

                                    @gsuberland oh I do know appsec.guide, will have a look at the WDF specific stuff since I still use WDM in $current_year

                                    Dunno how much of a consolation it is but your efforts are appreciated.

                                    gsuberland@chaos.socialG 1 Reply Last reply
                                    0
                                    • sharkfie@cyberplace.socialS sharkfie@cyberplace.social

                                      @gsuberland oh I do know appsec.guide, will have a look at the WDF specific stuff since I still use WDM in $current_year

                                      Dunno how much of a consolation it is but your efforts are appreciated.

                                      gsuberland@chaos.socialG This user is from outside of this forum
                                      gsuberland@chaos.socialG This user is from outside of this forum
                                      gsuberland@chaos.social
                                      wrote last edited by
                                      #23

                                      @sharkfie I wrote the majority of the Windows C++ stuff in there, so feel free to poke if you have questions πŸ™‚

                                      1 Reply Last reply
                                      0
                                      • gsuberland@chaos.socialG gsuberland@chaos.social

                                        *sigh* I'm sad.

                                        I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

                                        just finished triaging the submissions.

                                        almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

                                        the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

                                        😞

                                        diami03@infosec.exchangeD This user is from outside of this forum
                                        diami03@infosec.exchangeD This user is from outside of this forum
                                        diami03@infosec.exchange
                                        wrote last edited by
                                        #24

                                        @gsuberland @darthnull I suspect this is the same feelings DMs feel when they write up their homebrew scenarios.....

                                        gsuberland@chaos.socialG 1 Reply Last reply
                                        1
                                        0
                                        • rootwyrm@weird.autosR rootwyrm@weird.autos

                                          @neurovagrant @da_667 @gsuberland just remember that punishing brain cells doesn't have to mean punishing your tongue. Get the *good* stuff. On the company card.

                                          huronbikes@cyberplace.socialH This user is from outside of this forum
                                          huronbikes@cyberplace.socialH This user is from outside of this forum
                                          huronbikes@cyberplace.social
                                          wrote last edited by
                                          #25

                                          @rootwyrm @neurovagrant @da_667 @gsuberland Remember that good Jenkem comes from the Jenkem region of the internet, otherwise it's just sparkling poop-gas.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups