Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

Scheduled Pinned Locked Moved Uncategorized
36 Posts 27 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

    RE: https://cyberplace.social/@GossiTheDog/116565662607962457

    The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

    The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

    miawinter@tech.lgbtM This user is from outside of this forum
    miawinter@tech.lgbtM This user is from outside of this forum
    miawinter@tech.lgbt
    wrote last edited by
    #4

    @0xabad1dea jesus fucking christ

    1 Reply Last reply
    0
    • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

      RE: https://cyberplace.social/@GossiTheDog/116565662607962457

      The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

      The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

      kallisti@infosec.exchangeK This user is from outside of this forum
      kallisti@infosec.exchangeK This user is from outside of this forum
      kallisti@infosec.exchange
      wrote last edited by
      #5

      @0xabad1dea

      How else would feds get the data of these pesky criminals?

      E 1 Reply Last reply
      0
      • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

        RE: https://cyberplace.social/@GossiTheDog/116565662607962457

        The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

        The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

        lediva@lediva.masto.hostL This user is from outside of this forum
        lediva@lediva.masto.hostL This user is from outside of this forum
        lediva@lediva.masto.host
        wrote last edited by
        #6

        @0xabad1dea I'm sure Copilot will be very apologetic once it's called out.

        1 Reply Last reply
        0
        • R relay@relay.publicsquare.global shared this topic
        • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

          RE: https://cyberplace.social/@GossiTheDog/116565662607962457

          The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

          The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

          rst@mastodon.socialR This user is from outside of this forum
          rst@mastodon.socialR This user is from outside of this forum
          rst@mastodon.social
          wrote last edited by
          #7

          @0xabad1dea The charitable interpretation also assumes that in choosing the trigger for this debug behavior, they'd select a filename including a very large number of apparently random digits.

          0xabad1dea@infosec.exchange0 1 Reply Last reply
          0
          • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

            RE: https://cyberplace.social/@GossiTheDog/116565662607962457

            The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

            The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

            zenrenji@kafeneio.socialZ This user is from outside of this forum
            zenrenji@kafeneio.socialZ This user is from outside of this forum
            zenrenji@kafeneio.social
            wrote last edited by
            #8

            @0xabad1dea it already stored the passkeys to the cloud and they give to authorities when asked i guess one bypass wasnt enough

            1 Reply Last reply
            0
            • rst@mastodon.socialR rst@mastodon.social

              @0xabad1dea The charitable interpretation also assumes that in choosing the trigger for this debug behavior, they'd select a filename including a very large number of apparently random digits.

              0xabad1dea@infosec.exchange0 This user is from outside of this forum
              0xabad1dea@infosec.exchange0 This user is from outside of this forum
              0xabad1dea@infosec.exchange
              wrote last edited by
              #9

              @rst well, yes actually, having seen tons of firmware code, that’s quite normal and non-suspicious functionality does this all the time. it’s presumably just a guid

              1 Reply Last reply
              0
              • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                coosis@mstdn.plusC This user is from outside of this forum
                coosis@mstdn.plusC This user is from outside of this forum
                coosis@mstdn.plus
                wrote last edited by
                #10

                @0xabad1dea i am sorry WHAT

                1 Reply Last reply
                0
                • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                  RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                  The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                  The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                  stonebear2@hachyderm.ioS This user is from outside of this forum
                  stonebear2@hachyderm.ioS This user is from outside of this forum
                  stonebear2@hachyderm.io
                  wrote last edited by
                  #11

                  @0xabad1dea It's microsoft. They get no charity at all; they should be paying alms to the lot of us, everyone who ever booted 95 or higher...

                  1 Reply Last reply
                  0
                  • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                    RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                    The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                    The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                    jbiserkov@mas.toJ This user is from outside of this forum
                    jbiserkov@mas.toJ This user is from outside of this forum
                    jbiserkov@mas.to
                    wrote last edited by
                    #12

                    @0xabad1dea
                    > windows 10 is not [affected]

                    🤗

                    1 Reply Last reply
                    0
                    • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                      RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                      The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                      The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                      somevegancheeseisok@mastodon.socialS This user is from outside of this forum
                      somevegancheeseisok@mastodon.socialS This user is from outside of this forum
                      somevegancheeseisok@mastodon.social
                      wrote last edited by
                      #13

                      @0xabad1dea shiiiiiiiiiit that's cool

                      1 Reply Last reply
                      0
                      • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                        RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                        The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                        The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                        jackemled@furry.engineerJ This user is from outside of this forum
                        jackemled@furry.engineerJ This user is from outside of this forum
                        jackemled@furry.engineer
                        wrote last edited by
                        #14

                        @0xabad1dea Maybe their new LLM forgot to remove the code before shipping a new production version.

                        1 Reply Last reply
                        0
                        • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                          RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                          The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                          The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                          oilheap@infosec.exchangeO This user is from outside of this forum
                          oilheap@infosec.exchangeO This user is from outside of this forum
                          oilheap@infosec.exchange
                          wrote last edited by
                          #15

                          @0xabad1dea this is what you get when you do disk encryption without user input 🤷

                          babble_endanger@freeradical.zoneB 1 Reply Last reply
                          0
                          • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                            RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                            The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                            The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                            csolisr@hub.azkware.netC This user is from outside of this forum
                            csolisr@hub.azkware.netC This user is from outside of this forum
                            csolisr@hub.azkware.net
                            wrote last edited by
                            #16
                            I already went through the hassle of configuring my laptop to get secure boot and encryption on my Windows and Linux partitions, and then I learned the NTFS encryption key gets automatically submitted to Microsoft so decrypting it is as easy as stealing my Outlook account. I'm yet to rekey my hard drive with a local-only key, as I fear I'd have to format and reinstall. Does this exploit make local-only keys equally unsafe, too?
                            1 Reply Last reply
                            0
                            • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                              RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                              The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                              The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                              landelare@mastodon.gamedev.placeL This user is from outside of this forum
                              landelare@mastodon.gamedev.placeL This user is from outside of this forum
                              landelare@mastodon.gamedev.place
                              wrote last edited by
                              #17

                              @0xabad1dea This would be pretty serious if BitLocker was a security feature, not a user annoyance one. 🙃

                              1 Reply Last reply
                              0
                              • kallisti@infosec.exchangeK kallisti@infosec.exchange

                                @0xabad1dea

                                How else would feds get the data of these pesky criminals?

                                E This user is from outside of this forum
                                E This user is from outside of this forum
                                equity7804@hostux.social
                                wrote last edited by
                                #18

                                @kallisti @0xabad1dea well by asking Microsoft nicely for the decryption keys they store in plain text among account data on their server of course 😵‍💫 (fck microsoft)

                                1 Reply Last reply
                                0
                                • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                                  RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                                  The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                                  The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                                  rrb@infosec.exchangeR This user is from outside of this forum
                                  rrb@infosec.exchangeR This user is from outside of this forum
                                  rrb@infosec.exchange
                                  wrote last edited by
                                  #19

                                  @0xabad1dea To be honest, I had a Huawei phone for a long time, because I trust the human rights record of the PRC more than I trust the US tech companies.

                                  energisch_@troet.cafeE 1 Reply Last reply
                                  1
                                  0
                                  • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                                    RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                                    The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                                    The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                                    energisch_@troet.cafeE This user is from outside of this forum
                                    energisch_@troet.cafeE This user is from outside of this forum
                                    energisch_@troet.cafe
                                    wrote last edited by
                                    #20

                                    @0xabad1dea MS has been known - from the start with their first windows versions that they distribute beta versions that come with bugs galore. The user/customer then hands in all those problematic situations which (with luck) get repaired and updated every other day. Those repair updates will happen as long as the version is distributed and only stop when there is a new and "better" version... again, of course, beta, full of bugs.
                                    Microsoft customers are used to being used as beta testers.

                                    1 Reply Last reply
                                    0
                                    • rrb@infosec.exchangeR rrb@infosec.exchange

                                      @0xabad1dea To be honest, I had a Huawei phone for a long time, because I trust the human rights record of the PRC more than I trust the US tech companies.

                                      energisch_@troet.cafeE This user is from outside of this forum
                                      energisch_@troet.cafeE This user is from outside of this forum
                                      energisch_@troet.cafe
                                      wrote last edited by
                                      #21

                                      @rrb Well you got a point there. At least it wouldn't be worse than a US tech phone @0xabad1dea

                                      rrb@infosec.exchangeR 1 Reply Last reply
                                      0
                                      • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                                        RE: https://cyberplace.social/@GossiTheDog/116565662607962457

                                        The chill I got when I downloaded the repo and realized the “exploit” was a zero byte file with a magic filename…

                                        The charitable interpretation is that Microsoft accidentally shipped an internal test build to global production. The less charitable one isn’t very pleasant

                                        capnthommo@c.imC This user is from outside of this forum
                                        capnthommo@c.imC This user is from outside of this forum
                                        capnthommo@c.im
                                        wrote last edited by
                                        #22

                                        @0xabad1dea oh I'm sure if was the merest accidental oversight and that they're very very sorry and feel so foolish now.😉

                                        1 Reply Last reply
                                        0
                                        • energisch_@troet.cafeE energisch_@troet.cafe

                                          @rrb Well you got a point there. At least it wouldn't be worse than a US tech phone @0xabad1dea

                                          rrb@infosec.exchangeR This user is from outside of this forum
                                          rrb@infosec.exchangeR This user is from outside of this forum
                                          rrb@infosec.exchange
                                          wrote last edited by
                                          #23

                                          @energisch_ @0xabad1dea and I don't live in China, so their ability to mess with me is limited

                                          energisch_@troet.cafeE 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups