<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://cyberplace.social/@GossiTheDog/116565662607962457" rel="nofollow noopener"><span>https://</span><span>cyberplace.social/@GossiTheDog</span><span>/116565662607962457</span></a></p><p>The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…</p><p>The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant</p>]]></description><link>https://board.circlewithadot.net/topic/5bd22dce-1add-4ce5-b8a6-fdb17e26ba95/the-chill-i-got-when-i-downloaded-the-repo-and-realized-the-exploit-was-a-zero-byte-file-with-a-magic-filename</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 23:26:36 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/5bd22dce-1add-4ce5-b8a6-fdb17e26ba95.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 13 May 2026 11:57:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 19:01:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> Looks like one of the files causes winpeshl.ini on the ramdrive to be deleted, which eventually results in command prompt to be spawned instead of the usual UI.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/jernej__s/statuses/116568812272540893</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/jernej__s/statuses/116568812272540893</guid><dc:creator><![CDATA[jernej__s@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 19:01:57 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 18:08:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/babble_endanger%40freeradical.zone">@<span>babble_endanger</span></a></span> <span><a href="/user/oilheap%40infosec.exchange">@<span>oilheap</span></a></span> if you have a password on bitlocker itself (as opposed to your Windows account) then yes, this debug backdoor cannot work.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/0xabad1dea/statuses/116568600543963838</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/0xabad1dea/statuses/116568600543963838</guid><dc:creator><![CDATA[0xabad1dea@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 18:08:07 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 17:55:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/oilheap%40infosec.exchange">@<span>oilheap</span></a></span> <span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> yeah i was wondering that... So this exploit only works if you don't use a password or pin?</p>]]></description><link>https://board.circlewithadot.net/post/https://freeradical.zone/users/babble_endanger/statuses/116568552003356447</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://freeradical.zone/users/babble_endanger/statuses/116568552003356447</guid><dc:creator><![CDATA[babble_endanger@freeradical.zone]]></dc:creator><pubDate>Wed, 13 May 2026 17:55:46 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 17:17:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> I feel certain that FileVault also has some kind of magic bypass. Either of the ‘haha nobody will ever discover the arcane incantation needed to put this developer test mode’ or more likely requested by a three letter agency.</p>]]></description><link>https://board.circlewithadot.net/post/https://vmst.io/users/slyborg/statuses/116568399681740525</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://vmst.io/users/slyborg/statuses/116568399681740525</guid><dc:creator><![CDATA[slyborg@vmst.io]]></dc:creator><pubDate>Wed, 13 May 2026 17:17:02 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 17:05:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/energisch_%40troet.cafe">@<span>energisch_</span></a></span> <span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> And this is unrelated to a former student of mine working on security for Huawei, because another student is managing security for Microsoft</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/rrb/statuses/116568353697605344</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/rrb/statuses/116568353697605344</guid><dc:creator><![CDATA[rrb@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 17:05:20 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 15:45:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange" rel="nofollow noopener">@<span>0xabad1dea</span></a></span> </p><blockquote><p>Also for whatever reason, only windows 11 (+Server 2022/2025) are affect, windows 10 is not.<br />another win 10 w!!!!!!!!!!!!!!!!</p></blockquote>]]></description><link>https://board.circlewithadot.net/post/https://wetdry.world/users/glitchy404/statuses/116568038425769032</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://wetdry.world/users/glitchy404/statuses/116568038425769032</guid><dc:creator><![CDATA[glitchy404@wetdry.world]]></dc:creator><pubDate>Wed, 13 May 2026 15:45:09 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 15:33:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span></p>

<div class="row mt-3"><div class="col-12 mt-3"><div class="ratio ratio-16x9">
<video controls width="228" height="276">
<source src="https://cdn.masto.host/mastodongamedevplace/media_attachments/files/116/567/991/753/569/777/original/aac002c69ff790e5.mp4" type="video/mp4"></source>
</video>
</div></div></div>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.gamedev.place/users/shana/statuses/116567993334885522</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.gamedev.place/users/shana/statuses/116567993334885522</guid><dc:creator><![CDATA[shana@mastodon.gamedev.place]]></dc:creator><pubDate>Wed, 13 May 2026 15:33:41 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 15:28:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/jernej__s%40infosec.exchange">@<span>jernej__s</span></a></span> they're just empty log files (a header plus megabytes of zeroes), presumably because if they're missing entirely, something errors out before the flag gets processed</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/0xabad1dea/statuses/116567972957574723</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/0xabad1dea/statuses/116567972957574723</guid><dc:creator><![CDATA[0xabad1dea@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 15:28:30 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 15:27:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> There's also about 20 MB of other files.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/jernej__s/statuses/116567967541578101</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/jernej__s/statuses/116567967541578101</guid><dc:creator><![CDATA[jernej__s@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 15:27:08 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 15:14:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> How did they come by the content of these files?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/crazyeddie/statuses/116567919295015002</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/crazyeddie/statuses/116567919295015002</guid><dc:creator><![CDATA[crazyeddie@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 15:14:51 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 15:11:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/pa27%40mastodon.social">@<span>pa27</span></a></span> that's why I was quick to download it <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f602.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--joy" style="height:23px;width:auto;vertical-align:middle" title="😂" alt="😂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/0xabad1dea/statuses/116567904536081662</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/0xabad1dea/statuses/116567904536081662</guid><dc:creator><![CDATA[0xabad1dea@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 15:11:06 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 15:07:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> Kind of ironic that this is posted on github!!</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/pa27/statuses/116567891056268063</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/pa27/statuses/116567891056268063</guid><dc:creator><![CDATA[pa27@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 15:07:41 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 14:50:52 GMT]]></title><description><![CDATA[<p><span><a href="/user/rrb%40infosec.exchange">@<span>rrb</span></a></span> exactly! <span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://troet.cafe/users/energisch_/statuses/116567824963672779</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://troet.cafe/users/energisch_/statuses/116567824963672779</guid><dc:creator><![CDATA[energisch_@troet.cafe]]></dc:creator><pubDate>Wed, 13 May 2026 14:50:52 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 14:48:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/energisch_%40troet.cafe">@<span>energisch_</span></a></span> <span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> and I don't live in China, so their ability to mess with me is limited</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/rrb/statuses/116567817460908244</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/rrb/statuses/116567817460908244</guid><dc:creator><![CDATA[rrb@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 14:48:58 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 14:42:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> oh I'm sure if was the merest accidental oversight and that they're very very sorry and feel so foolish now.<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title="😉" alt="😉" /></p>]]></description><link>https://board.circlewithadot.net/post/https://c.im/users/capnthommo/statuses/116567792533080545</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://c.im/users/capnthommo/statuses/116567792533080545</guid><dc:creator><![CDATA[capnthommo@c.im]]></dc:creator><pubDate>Wed, 13 May 2026 14:42:37 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 14:41:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/rrb%40infosec.exchange">@<span>rrb</span></a></span> Well you got a point there. At least it wouldn't be worse than a US tech phone <span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://troet.cafe/users/energisch_/statuses/116567787413585385</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://troet.cafe/users/energisch_/statuses/116567787413585385</guid><dc:creator><![CDATA[energisch_@troet.cafe]]></dc:creator><pubDate>Wed, 13 May 2026 14:41:19 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 14:32:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> MS has been known - from the start with their first windows versions that they distribute beta versions that come with bugs galore. The user/customer then hands in all those problematic situations which (with luck) get repaired and updated every other day. Those repair updates will happen as long as the version is distributed and only stop when there is a new and "better" version... again, of course, beta, full of bugs.<br />Microsoft customers are used to being used as beta testers.</p>]]></description><link>https://board.circlewithadot.net/post/https://troet.cafe/users/energisch_/statuses/116567751258275719</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://troet.cafe/users/energisch_/statuses/116567751258275719</guid><dc:creator><![CDATA[energisch_@troet.cafe]]></dc:creator><pubDate>Wed, 13 May 2026 14:32:07 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 14:13:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> To be honest, I had a Huawei phone for a long time, because I trust the human rights record of the PRC more than I trust the US tech companies.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/rrb/statuses/116567679248581891</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/rrb/statuses/116567679248581891</guid><dc:creator><![CDATA[rrb@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 14:13:49 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 13:52:34 GMT]]></title><description><![CDATA[<p><span><a href="/user/kallisti%40infosec.exchange">@<span>kallisti</span></a></span> <span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> well by asking Microsoft nicely for the decryption keys they store in plain text among account data on their server of course <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f635.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--dizzy_face" style="height:23px;width:auto;vertical-align:middle" title="😵" alt="😵" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f4ab.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--dizzy" style="height:23px;width:auto;vertical-align:middle" title="💫" alt="💫" /> (fck microsoft)</p>]]></description><link>https://board.circlewithadot.net/post/https://hostux.social/users/Equity7804/statuses/116567595720096059</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hostux.social/users/Equity7804/statuses/116567595720096059</guid><dc:creator><![CDATA[equity7804@hostux.social]]></dc:creator><pubDate>Wed, 13 May 2026 13:52:34 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 13:43:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> This would be pretty serious if BitLocker was a security feature, not a user annoyance one. <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f643.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--upside_down_face" style="height:23px;width:auto;vertical-align:middle" title="🙃" alt="🙃" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.gamedev.place/users/landelare/statuses/116567561893041238</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.gamedev.place/users/landelare/statuses/116567561893041238</guid><dc:creator><![CDATA[landelare@mastodon.gamedev.place]]></dc:creator><pubDate>Wed, 13 May 2026 13:43:58 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 13:40:17 GMT]]></title><description><![CDATA[I already went through the hassle of configuring my laptop to get secure boot and encryption on my Windows and Linux partitions, and then I learned the NTFS encryption key gets automatically submitted to Microsoft so decrypting it is as easy as stealing my Outlook account. I'm yet to rekey my hard drive with a local-only key, as I fear I'd have to format and reinstall. Does this exploit make local-only keys equally unsafe, too?]]></description><link>https://board.circlewithadot.net/post/https://hub.azkware.net/objects/6e2ecb8d-406a-047f-41ac-e52207602723</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hub.azkware.net/objects/6e2ecb8d-406a-047f-41ac-e52207602723</guid><dc:creator><![CDATA[csolisr@hub.azkware.net]]></dc:creator><pubDate>Wed, 13 May 2026 13:40:17 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 13:39:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> this is what you get when you do disk encryption without user input <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title="🤷" alt="🤷" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/oilheap/statuses/116567545521281033</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/oilheap/statuses/116567545521281033</guid><dc:creator><![CDATA[oilheap@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 13:39:48 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 13:32:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange" rel="nofollow noopener">@<span>0xabad1dea</span></a></span> Maybe their new LLM forgot to remove the code before shipping a new production version.</p>]]></description><link>https://board.circlewithadot.net/post/https://furry.engineer/users/jackemled/statuses/116567517165955355</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://furry.engineer/users/jackemled/statuses/116567517165955355</guid><dc:creator><![CDATA[jackemled@furry.engineer]]></dc:creator><pubDate>Wed, 13 May 2026 13:32:35 GMT</pubDate></item><item><title><![CDATA[Reply to The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename… on Wed, 13 May 2026 13:23:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/0xabad1dea%40infosec.exchange">@<span>0xabad1dea</span></a></span> shiiiiiiiiiit that's cool</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/SomeVeganCheeseIsOk/statuses/116567480487760881</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/SomeVeganCheeseIsOk/statuses/116567480487760881</guid><dc:creator><![CDATA[somevegancheeseisok@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 13:23:16 GMT</pubDate></item></channel></rss>