Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. *sigh* I'm sad.

*sigh* I'm sad.

Scheduled Pinned Locked Moved Uncategorized
28 Posts 15 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gsuberland@chaos.socialG gsuberland@chaos.social

    *sigh* I'm sad.

    I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

    just finished triaging the submissions.

    almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

    the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

    ๐Ÿ˜ž

    demize@unstable.systemsD This user is from outside of this forum
    demize@unstable.systemsD This user is from outside of this forum
    demize@unstable.systems
    wrote last edited by
    #3

    @gsuberland ;~;

    1 Reply Last reply
    0
    • gsuberland@chaos.socialG gsuberland@chaos.social

      I already checked ahead of time that an LLM couldn't solve it, because I knew that people would try it.

      gsuberland@chaos.socialG This user is from outside of this forum
      gsuberland@chaos.socialG This user is from outside of this forum
      gsuberland@chaos.social
      wrote last edited by
      #4

      really puts a damper on me wanting to put effort into these in future.

      gsuberland@chaos.socialG da_667@infosec.exchangeD drwho@masto.hackers.townD 3 Replies Last reply
      0
      • gsuberland@chaos.socialG gsuberland@chaos.social

        really puts a damper on me wanting to put effort into these in future.

        gsuberland@chaos.socialG This user is from outside of this forum
        gsuberland@chaos.socialG This user is from outside of this forum
        gsuberland@chaos.social
        wrote last edited by
        #5

        although if you're the person who cockily submitted the one declaring that it was done autonomously: lol, lmao, reality check time

        gsuberland@chaos.socialG ra6bit@infosec.exchangeR 2 Replies Last reply
        0
        • gsuberland@chaos.socialG gsuberland@chaos.social

          *sigh* I'm sad.

          I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

          just finished triaging the submissions.

          almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

          the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

          ๐Ÿ˜ž

          darthnull@infosec.exchangeD This user is from outside of this forum
          darthnull@infosec.exchangeD This user is from outside of this forum
          darthnull@infosec.exchange
          wrote last edited by
          #6

          @gsuberland Bummer. Half the fun of making challenges is seeing others have fun with it (and the other half is seeing them learn from the experience).

          Sounds like you got very little of either. ๐Ÿ˜ž

          gsuberland@chaos.socialG 1 Reply Last reply
          1
          0
          • R relay@relay.infosec.exchange shared this topic
          • gsuberland@chaos.socialG gsuberland@chaos.social

            really puts a damper on me wanting to put effort into these in future.

            da_667@infosec.exchangeD This user is from outside of this forum
            da_667@infosec.exchangeD This user is from outside of this forum
            da_667@infosec.exchange
            wrote last edited by
            #7

            @gsuberland motivated to do some work

            open up RSS feed

            every fucking story for the past week is AI horse shit.

            eyes the bottle of vodka in the kitchen

            neurovagrant@masto.deoan.orgN 1 Reply Last reply
            0
            • darthnull@infosec.exchangeD darthnull@infosec.exchange

              @gsuberland Bummer. Half the fun of making challenges is seeing others have fun with it (and the other half is seeing them learn from the experience).

              Sounds like you got very little of either. ๐Ÿ˜ž

              gsuberland@chaos.socialG This user is from outside of this forum
              gsuberland@chaos.socialG This user is from outside of this forum
              gsuberland@chaos.social
              wrote last edited by
              #8

              @darthnull yeah it's pretty demotivating to see people lacking the curiosity to experiment and learn when someone gives them an opportunity to do so.

              in fact the answers I appreciated the most were the few that said "I have no idea but I'm looking forward to reading the writeup".

              xabean@infosec.exchangeX 1 Reply Last reply
              0
              • da_667@infosec.exchangeD da_667@infosec.exchange

                @gsuberland motivated to do some work

                open up RSS feed

                every fucking story for the past week is AI horse shit.

                eyes the bottle of vodka in the kitchen

                neurovagrant@masto.deoan.orgN This user is from outside of this forum
                neurovagrant@masto.deoan.orgN This user is from outside of this forum
                neurovagrant@masto.deoan.org
                wrote last edited by
                #9

                @da_667 @gsuberland i'm past the vodka and nearing the "huffing spraypaint in a parking lot" stage

                da_667@infosec.exchangeD 1 Reply Last reply
                0
                • gsuberland@chaos.socialG gsuberland@chaos.social

                  @darthnull yeah it's pretty demotivating to see people lacking the curiosity to experiment and learn when someone gives them an opportunity to do so.

                  in fact the answers I appreciated the most were the few that said "I have no idea but I'm looking forward to reading the writeup".

                  xabean@infosec.exchangeX This user is from outside of this forum
                  xabean@infosec.exchangeX This user is from outside of this forum
                  xabean@infosec.exchange
                  wrote last edited by
                  #10

                  @gsuberland @darthnull someone highlighted a difference that feels right to me based on what I've seen in myself and good friends I respect and trust:

                  There's two classes of people, those who like the art/practice of software development and get enrichment out of that process, and those who enjoy building and shipping a thing.

                  The former finds AI revolting, the other finds AI extremely enticing.

                  1 Reply Last reply
                  0
                  • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                    @da_667 @gsuberland i'm past the vodka and nearing the "huffing spraypaint in a parking lot" stage

                    da_667@infosec.exchangeD This user is from outside of this forum
                    da_667@infosec.exchangeD This user is from outside of this forum
                    da_667@infosec.exchange
                    wrote last edited by
                    #11

                    @neurovagrant @gsuberland let's do whippets together to forget everything.

                    neurovagrant@masto.deoan.orgN gary_alderson@infosec.exchangeG 2 Replies Last reply
                    0
                    • da_667@infosec.exchangeD da_667@infosec.exchange

                      @neurovagrant @gsuberland let's do whippets together to forget everything.

                      neurovagrant@masto.deoan.orgN This user is from outside of this forum
                      neurovagrant@masto.deoan.orgN This user is from outside of this forum
                      neurovagrant@masto.deoan.org
                      wrote last edited by
                      #12

                      @da_667 @gsuberland i'm just coming to the conclusion that our problem is we have too many braincells, so it's time to punish them.

                      rootwyrm@weird.autosR gary_alderson@infosec.exchangeG 2 Replies Last reply
                      0
                      • da_667@infosec.exchangeD da_667@infosec.exchange

                        @neurovagrant @gsuberland let's do whippets together to forget everything.

                        gary_alderson@infosec.exchangeG This user is from outside of this forum
                        gary_alderson@infosec.exchangeG This user is from outside of this forum
                        gary_alderson@infosec.exchange
                        wrote last edited by
                        #13

                        @da_667 @neurovagrant @gsuberland

                        Link Preview Image
                        1 Reply Last reply
                        0
                        • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                          @da_667 @gsuberland i'm just coming to the conclusion that our problem is we have too many braincells, so it's time to punish them.

                          rootwyrm@weird.autosR This user is from outside of this forum
                          rootwyrm@weird.autosR This user is from outside of this forum
                          rootwyrm@weird.autos
                          wrote last edited by
                          #14

                          @neurovagrant @da_667 @gsuberland just remember that punishing brain cells doesn't have to mean punishing your tongue. Get the *good* stuff. On the company card.

                          huronbikes@cyberplace.socialH 1 Reply Last reply
                          0
                          • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                            @da_667 @gsuberland i'm just coming to the conclusion that our problem is we have too many braincells, so it's time to punish them.

                            gary_alderson@infosec.exchangeG This user is from outside of this forum
                            gary_alderson@infosec.exchangeG This user is from outside of this forum
                            gary_alderson@infosec.exchange
                            wrote last edited by
                            #15

                            @neurovagrant @da_667 @gsuberland minor recreational drug use is not bad and in this economy probably mandatory #moderation #soft cell #precursors

                            1 Reply Last reply
                            0
                            • gsuberland@chaos.socialG gsuberland@chaos.social

                              *sigh* I'm sad.

                              I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

                              just finished triaging the submissions.

                              almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

                              the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

                              ๐Ÿ˜ž

                              moses_izumi@fe.disroot.orgM This user is from outside of this forum
                              moses_izumi@fe.disroot.orgM This user is from outside of this forum
                              moses_izumi@fe.disroot.org
                              wrote last edited by
                              #16
                              @gsuberland
                              Security research doesn't feel the same after I searched "how to exploit windows" and forgot the n at the end.
                              1 Reply Last reply
                              0
                              • gsuberland@chaos.socialG gsuberland@chaos.social

                                *sigh* I'm sad.

                                I wrote a really cool Windows kernel exploitation challenge for $employer's blog. I put a ton of work into designing and validating it.

                                just finished triaging the submissions.

                                almost everyone who submitted a response used an LLM and did no further analysis. none of these submissions solved the fun parts of the challenge.

                                the few people who didn't obviously use an LLM mostly sent in a 2-3 sentence summary of the bug, and didn't solve the fun parts of the challenge.

                                ๐Ÿ˜ž

                                sharkfie@cyberplace.socialS This user is from outside of this forum
                                sharkfie@cyberplace.socialS This user is from outside of this forum
                                sharkfie@cyberplace.social
                                wrote last edited by
                                #17

                                @gsuberland would you feel comfortable linking it? I would like to read it even if I likely can't finish it

                                gsuberland@chaos.socialG 1 Reply Last reply
                                0
                                • gsuberland@chaos.socialG gsuberland@chaos.social

                                  although if you're the person who cockily submitted the one declaring that it was done autonomously: lol, lmao, reality check time

                                  gsuberland@chaos.socialG This user is from outside of this forum
                                  gsuberland@chaos.socialG This user is from outside of this forum
                                  gsuberland@chaos.social
                                  wrote last edited by
                                  #18

                                  one person got the Linux challenge correct and then wrote "I'm not a Windows person but I'm really looking forward to seeing the writeup on this" for the Windows challenge.

                                  this was by far my favourite answer and I am pushing to get them some swag to reward having an excellent attitude.

                                  ams@infosec.exchangeA 1 Reply Last reply
                                  0
                                  • sharkfie@cyberplace.socialS sharkfie@cyberplace.social

                                    @gsuberland would you feel comfortable linking it? I would like to read it even if I likely can't finish it

                                    gsuberland@chaos.socialG This user is from outside of this forum
                                    gsuberland@chaos.socialG This user is from outside of this forum
                                    gsuberland@chaos.social
                                    wrote last edited by
                                    #19

                                    @sharkfie https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/

                                    sharkfie@cyberplace.socialS 1 Reply Last reply
                                    0
                                    • gsuberland@chaos.socialG gsuberland@chaos.social

                                      although if you're the person who cockily submitted the one declaring that it was done autonomously: lol, lmao, reality check time

                                      ra6bit@infosec.exchangeR This user is from outside of this forum
                                      ra6bit@infosec.exchangeR This user is from outside of this forum
                                      ra6bit@infosec.exchange
                                      wrote last edited by
                                      #20

                                      @gsuberland The phenomena of people play acting GAI agents is weird

                                      1 Reply Last reply
                                      0
                                      • gsuberland@chaos.socialG gsuberland@chaos.social

                                        really puts a damper on me wanting to put effort into these in future.

                                        drwho@masto.hackers.townD This user is from outside of this forum
                                        drwho@masto.hackers.townD This user is from outside of this forum
                                        drwho@masto.hackers.town
                                        wrote last edited by
                                        #21

                                        @gsuberland Same with a CTF I built back in '15. Zero interest from anyone who said they'd be interested.

                                        1 Reply Last reply
                                        0
                                        • gsuberland@chaos.socialG gsuberland@chaos.social

                                          @sharkfie https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/

                                          sharkfie@cyberplace.socialS This user is from outside of this forum
                                          sharkfie@cyberplace.socialS This user is from outside of this forum
                                          sharkfie@cyberplace.social
                                          wrote last edited by
                                          #22

                                          @gsuberland oh I do know appsec.guide, will have a look at the WDF specific stuff since I still use WDM in $current_year

                                          Dunno how much of a consolation it is but your efforts are appreciated.

                                          gsuberland@chaos.socialG 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups