[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1778505305936.jpg (155 KB, 1366x854)
155 KB JPG
Linux LPE vulnerabilities are dropping like flies all of a sudden.
Anyone knows what is going on?
>>
Same as it ever was.
>>
>>108799303
the glowies planted them
>>
>>108799303
microsoft has a whole division dedicated to finding and planting them, and has been sleeping on them and are now releasing them because they feel threatened.
>>
>>108799303
People always look for the same exploit in other places.
The same thing happened after Spectre.
>>
>>108799303
AI is discovering all the glowies 0 days
>>
>>108799303
Script kiddies + AI
>>
>>108799303
Glowfag backdoors are being found by AI.
And the ones who steer the AI are Korean researchers, because no Westoids would ever be allowed to do this.
>>
>>108799507
>>108799456
>>108799335
Reminder that those "vulnerabilities" were implemented 2017/18.
Which is around the time in which Linus Torvalds had to apologize for being rude and Linux adopted a Code of Conduct.

It is blatantly obvious that those are glowfags backdoors. That it was Koreans who had to find them, while none of those multi billion $$$ American corpos could in their audits, is the cherry on top.
>>
You know "Linux LPE vulnerabilities are dropping like flies" means "Linux LPE vulnerabilities are being destroyed at an incredible rate", right?
This feels like a microjeet anti linux thread so I don't think your intent is being excited about how many vulnerabilities are successfully being dealt with but that's what you are conveying.
>>
>>108799483
sounds like the script kiddies + ai is better then real programmers then if it actually fixes and finds things 'real' programmers cant after years!!
half of /g/ will be homeless soon!! LOL
>>
This is the prompt used to find copyfail:
>This is the linux crypto/ subsystem. Please examine all codepaths reachable from userspace syscalls. Note one key observation: splice() can deliver page-cache references of read-only files (including setuid binaries) to crypto TX scatterlists.
As you can see, AI got used more like an advanced Ctrl-F, the guy knew exactly what he was looking for and is familiar with the code base.
>>
>>108799578
How did he know that splice can do that? Sounds like (((someone))) already knew about that vulnerability beforehand?
>>
>>108799534
It means that the best kernel versions to use is either 3.16 or the current LTS 6.18 after patches.

We can assume that glowies will castrate AIs and forbid them from finding certain backdoors, and will implement other backdoors in the near future.
>>
>>108799592
It's probably a guy who spends his time skimming through source code, figuring out how things work, getting familiar with the concept of a page cache and thought: "huh, if someone could overwrite this, he would have full system access", then looked at methods that access it, where those are imported and queried the AI on whether or not it could be abused in that specific part.

Looks legit and not that unlikely to me.
>>
>>108799601
>We can assume that glowies will castrate AIs and forbid them from finding certain backdoors, and will implement other backdoors in the near future.
The thing is that we have amazing FOSS models like Qwen coder, and also the claude framework (everything except the model) was leaked. So one could easily use the claude framework together with Qwen coder model and it would work. Not as well as Claude general, but it would work.
>>
>>108799303
>Anyone knows what is going on?
Security researchers are using AI to automate auditing for vulnerabilities. If they're already talented at identifying probable vulns it can speed up the part where they go from a suspected vulnerable function to a working exploit.
Glasswing is also ramping up, so internal dev teams are also going to start identifying more vulns in their own code base.
Basically CVEs are going to explode, and keeping up is gonna be a nightmare.
>>
>>108799657
And without AI, this would have taken months. And nobody would have paid for those months. Especially because you don't know if there is anything to find in the first place.
AI made something possible that was not possible before. Finding glowfag backdoors is the best use case for AIs yet.
>>
>>108799705
they will use AI to keep up
>>
>>108799705
>CVEs are going to explode, and keeping up is gonna be a nightmare
Exposing a vulnerability is better than having it hidden and unknown. It's a good thing, for everybody, except for glowfags.
>>
>>108799534
>tech illiterate jeet wintard who probably never heard of git, let alone know about git-blame
>>
>>108799578
>AI got used more like an advanced Ctrl-F
And that’s all it takes to change cybersecurity forever.
Most zero days are living on borrowed time now.
>>
File: 1658139324197650.jpg (406 KB, 958x946)
406 KB JPG
>>108799303
>Linux LPE vulnerabilities are dropping like flies all of a sudden.
That is not what that expression means.
>>
>>108799902
But when shitting in street I become covered in flies, and they drop from an ascension position upon my dung. You are whom to be incorrect according to logic of your language. Timmy cannot fathom this!
>>
File: 1767851588863069.png (75 KB, 756x595)
75 KB PNG
>>108799303
>8 Linux CVEs/bugs in it's whole history
>Windows has 30 thousand new CVEs/bugs EVERY MONTH
Yeah really horrible how Linux has couple while Windows had 14.8 million. Stfu OP
https://unlocked.microsoft.com/pride/
>>
>>108799303
glowies inserted backdoors in crypto libraries that you can use to modify memory
>>
>>108799303
Humans are worse at reading code than LLMs.
>>
>>108799534
some dev was mad cos copy fail wasn't supposed to be in there to begin with o algo. I don't remember where I read this.
>>
>>108799578
>Ctrl-F
more like a fuzzer you don't have to set up in a classical sense
>>
>>108799303
Did you think it was a coincidence that the “voices online” were always telling you to switch to Linux for security?
>>
>>108800444
Attacking Microsoft for being ‘gay friendly’ while praising linux is a curious take.
>>
>>108799902
That is exactly what it means retard
>>
>>108802249
>curious take
What you even mean? Microsoft and Apple are official supporters of LGBT and BLM. Linux is not. Pretty simple.
>>
>>108805048
And it was funded by BlackROCK and VanGuard, so i don't trust them.
>>
>>108799553
Of course OP doesn't know that.
They're an ESL poo nigger.
>>
>>108799356
Microsoft's business literally depends on Linux.
>>
>>108799534
Whose commit was it?
>>
>>108805048
>MS and Apple support gay shit
vs
>Most Linux software and distros have at least multiple actual trannies directly working on them, alongside things like CoCs
Which one is worse?
>>
>>108806516
MS and Apple because they are unfree
>>
>>108799303
LINUX = NIGGER
MAC = NIGGER
WINDOWS = NIGGER
Where are the good operating systems???
>>
Oh no, lunduke sent his drones again.
>>
>>108799303
>>108799578
Some faggot will say it's AI because he's a braindead sperg but if you look at teh original copy-fail writeup: This has been the work of a single researcher the last ten years exploring COW vulnerabilities on Linux, and each one is just an extension of the last.

AI's contribution was setting up fuzzing test cases and nothing more. The guy already knew where to look because he's a serious researcher and not a street shitter
>>
>>108806533

https://www.haiku-os.org



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.