Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. the rm -rf's will continue until morale improves

the rm -rf's will continue until morale improves

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
123 Indlæg 85 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • benaveling@infosec.exchangeB This user is from outside of this forum
    benaveling@infosec.exchangeB This user is from outside of this forum
    benaveling@infosec.exchange
    wrote sidst redigeret af
    #83

    If you ask a human to explain an action, they think back to what they were thinking at the time. LLMs don't do that, because LLM's don't think.

    GenAI engines are chatbots. They generate text. They match your prompt against some subset of the billions of rules they have and the combination of rules that trigger most strongly determines the response, one word at a time.

    The only honest explanation for “why this behaviour and not that behaviour” would be “these rules triggered more strongly than those rules”.

    @bartholin @neurovagrant

    tessarakt@mastodon.socialT 1 Reply Last reply
    0
    • paco@infosec.exchangeP paco@infosec.exchange

      @neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran drop table users; via injection.

      Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.

      tattie@eldritch.cafeT This user is from outside of this forum
      tattie@eldritch.cafeT This user is from outside of this forum
      tattie@eldritch.cafe
      wrote sidst redigeret af
      #84

      @paco and without ever learning any valuable lessons
      @neurovagrant

      1 Reply Last reply
      0
      • womble@infosec.exchangeW womble@infosec.exchange

        @jrdepriest @jztusk @paco @neurovagrant "oh, it's only data exfil, that's not so bad" Some people have very limited imaginations, and need an unequivocal demonstration.

        drwho@masto.hackers.townD This user is from outside of this forum
        drwho@masto.hackers.townD This user is from outside of this forum
        drwho@masto.hackers.town
        wrote sidst redigeret af
        #85

        @womble @jrdepriest @jztusk @paco @neurovagrant "Limited?"

        1 Reply Last reply
        0
        • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

          @jztusk @womble @paco @neurovagrant

          Like leaving an empty file called pwned on /.

          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.town
          wrote sidst redigeret af
          #86

          @jrdepriest @jztusk @womble @paco @neurovagrant Also fun.

          1 Reply Last reply
          0
          • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

            @jztusk @womble @paco @neurovagrant

            Mission accomplished with the table drop, then?

            drwho@masto.hackers.townD This user is from outside of this forum
            drwho@masto.hackers.townD This user is from outside of this forum
            drwho@masto.hackers.town
            wrote sidst redigeret af
            #87

            @jrdepriest @jztusk @womble @paco @neurovagrant Yep. Sometimes that's the only way to make them understand. Or using a loop and ssh to power down an entire rack.

            "Are you sure? This is fatal," during a meeting with a client is not an idle threat, and a lot of clients think we're bluffing.

            1 Reply Last reply
            0
            • rail@social.flufftech.netR rail@social.flufftech.net

              @paco @neurovagrant wouldn't that be a criminal offense at that point as well

              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.town
              wrote sidst redigeret af
              #88

              @rail @paco @neurovagrant Depends on how aggro the client wants to be.

              benaveling@infosec.exchangeB 1 Reply Last reply
              0
              • adamhotep@infosec.exchangeA adamhotep@infosec.exchange

                @neurovagrant people still haven't learned after all that ransomware. Back it up and/or employ snapshots. I'm a big fan of ZFS snapshots.

                drwho@masto.hackers.townD This user is from outside of this forum
                drwho@masto.hackers.townD This user is from outside of this forum
                drwho@masto.hackers.town
                wrote sidst redigeret af
                #89

                @adamhotep @neurovagrant Because they were lucky enough to have usable backups.

                Stress "lucky."

                1 Reply Last reply
                0
                • quinn@social.circl.luQ quinn@social.circl.lu

                  @Viss @neurovagrant Letsss goooooo

                  drwho@masto.hackers.townD This user is from outside of this forum
                  drwho@masto.hackers.townD This user is from outside of this forum
                  drwho@masto.hackers.town
                  wrote sidst redigeret af
                  #90

                  @quinn @Viss @neurovagrant

                  viss@mastodon.socialV 1 Reply Last reply
                  0
                  • drwho@masto.hackers.townD drwho@masto.hackers.town

                    @quinn @Viss @neurovagrant

                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.social
                    wrote sidst redigeret af
                    #91

                    @drwho @quinn @neurovagrant so i just went and squinted at the screenshot inside the screenshot

                    dude doesnt know what a sandbox is.

                    if the shit can reach your home directory, its not in a sandbox.

                    drwho@masto.hackers.townD 1 Reply Last reply
                    0
                    • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                      the rm -rf's will continue until morale improves

                      p@hj.9fs.netP This user is from outside of this forum
                      p@hj.9fs.netP This user is from outside of this forum
                      p@hj.9fs.net
                      wrote sidst redigeret af
                      #92
                      #neverslop
                      1 Reply Last reply
                      0
                      • dch@bsd.networkD dch@bsd.network

                        @neurovagrant also, people still not doing backups/restore testing, no zfs, no jails / containers / other restrictions. Kids these days.

                        drwho@masto.hackers.townD This user is from outside of this forum
                        drwho@masto.hackers.townD This user is from outside of this forum
                        drwho@masto.hackers.town
                        wrote sidst redigeret af
                        #93

                        @dch @neurovagrant There are folks who don't even know what removable storage is, let alone file systems or files.

                        "Just rebuild."

                        Great. That's the OS. What about the data?

                        There's probably a "chased by an angry goose" meme to make here.

                        1 Reply Last reply
                        0
                        • viss@mastodon.socialV viss@mastodon.social

                          @drwho @quinn @neurovagrant so i just went and squinted at the screenshot inside the screenshot

                          dude doesnt know what a sandbox is.

                          if the shit can reach your home directory, its not in a sandbox.

                          drwho@masto.hackers.townD This user is from outside of this forum
                          drwho@masto.hackers.townD This user is from outside of this forum
                          drwho@masto.hackers.town
                          wrote sidst redigeret af
                          #94

                          @Viss @quinn @neurovagrant Given his previous business history, this surprises not at all.

                          quinn@social.circl.luQ 1 Reply Last reply
                          0
                          • drwho@masto.hackers.townD drwho@masto.hackers.town

                            @Viss @quinn @neurovagrant Given his previous business history, this surprises not at all.

                            quinn@social.circl.luQ This user is from outside of this forum
                            quinn@social.circl.luQ This user is from outside of this forum
                            quinn@social.circl.lu
                            wrote sidst redigeret af
                            #95

                            @drwho @Viss @neurovagrant he probably makes more in a month than i will ever make

                            viss@mastodon.socialV drwho@masto.hackers.townD 2 Replies Last reply
                            0
                            • quinn@social.circl.luQ quinn@social.circl.lu

                              @drwho @Viss @neurovagrant he probably makes more in a month than i will ever make

                              viss@mastodon.socialV This user is from outside of this forum
                              viss@mastodon.socialV This user is from outside of this forum
                              viss@mastodon.social
                              wrote sidst redigeret af
                              #96

                              @quinn @drwho @neurovagrant oh, hes a cryptobro. no wonder

                              1 Reply Last reply
                              0
                              • quinn@social.circl.luQ quinn@social.circl.lu

                                @drwho @Viss @neurovagrant he probably makes more in a month than i will ever make

                                drwho@masto.hackers.townD This user is from outside of this forum
                                drwho@masto.hackers.townD This user is from outside of this forum
                                drwho@masto.hackers.town
                                wrote sidst redigeret af
                                #97

                                @quinn @Viss @neurovagrant Same.

                                1 Reply Last reply
                                0
                                • paco@infosec.exchangeP paco@infosec.exchange

                                  @neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran drop table users; via injection.

                                  Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.

                                  me@mastodon.seahousen.euM This user is from outside of this forum
                                  me@mastodon.seahousen.euM This user is from outside of this forum
                                  me@mastodon.seahousen.eu
                                  wrote sidst redigeret af
                                  #98

                                  @paco @neurovagrant imho, if LLMs are what make developers finally care about cybersecurity, that's the first thing about them one might consider 'good'

                                  1 Reply Last reply
                                  0
                                  • drwho@masto.hackers.townD drwho@masto.hackers.town

                                    @rail @paco @neurovagrant Depends on how aggro the client wants to be.

                                    benaveling@infosec.exchangeB This user is from outside of this forum
                                    benaveling@infosec.exchangeB This user is from outside of this forum
                                    benaveling@infosec.exchange
                                    wrote sidst redigeret af
                                    #99

                                    Also depends on how well written your contact with the client is.

                                    @drwho @rail @paco @neurovagrant

                                    1 Reply Last reply
                                    0
                                    • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                                      the rm -rf's will continue until morale improves

                                      catboycody@tech.lgbtC This user is from outside of this forum
                                      catboycody@tech.lgbtC This user is from outside of this forum
                                      catboycody@tech.lgbt
                                      wrote sidst redigeret af
                                      #100

                                      @neurovagrant I'm pushed to use claude at work... Three possible takeaways from this:

                                      1. Don't use auto mode and review the commands.
                                      2. Sandbox claude so that the fallout of such an oppsie is more limited.
                                      3. Do nothing and have a claude-free afternoon while I restore my profile.

                                      1 Reply Last reply
                                      0
                                      • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

                                        @jztusk @paco @neurovagrant

                                        A simple select * from users would've been fine just to prove the point.

                                        jackeric@beige.partyJ This user is from outside of this forum
                                        jackeric@beige.partyJ This user is from outside of this forum
                                        jackeric@beige.party
                                        wrote sidst redigeret af
                                        #101

                                        @jrdepriest @jztusk @paco @neurovagrant that shows access but not, whatsit, that the injected query has `drop table` privileges, I forget the term for it

                                        1 Reply Last reply
                                        0
                                        • computernut43@nexto.myC computernut43@nexto.my

                                          @neurovagrant thats why dev machines are VM's for me and before I start to "dev" you make a backup. I think its time we teach about backups now.

                                          epic_null@infosec.exchangeE This user is from outside of this forum
                                          epic_null@infosec.exchangeE This user is from outside of this forum
                                          epic_null@infosec.exchange
                                          wrote sidst redigeret af
                                          #102

                                          @computernut43 @neurovagrant You mean one of the things that AI has just made unreasonably expensive?

                                          computernut43@nexto.myC 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper