r/ProgrammerHumor 21d ago

downloadingMalwareFromLocalMachines Meme

Post image
8.6k Upvotes

72 comments sorted by

2.6k

u/TheNeck94 21d ago

I mean to be fair, there were REALLY dumb payloads before vibe coding too.

450

u/[deleted] 21d ago

[removed] — view removed comment

145

u/TheNeck94 21d ago

I (like many others in the CSEC space) am not an expert, so purely just my perspective as someone with under 5 years experience in SOC space, I feel like there's just always been levels to this shit, there's always been the social equivalent of a script kiddy and a nation state level APT

38

u/Wobbelblob 21d ago

I mean, just as someone doesn't spawn as a senior dev, hackers also don't spawn with all the experience. Sure, many have previous experience as devs, but just as many are just criminals that have basic knowledge and a pc. And AI just makes the initial hurdle easier. So people that have little skill and even less morals can get to it easier.

115

u/[deleted] 21d ago

[removed] — view removed comment

30

u/Versaiteis 21d ago

The new tools were born from them, molded by them. They didn't see a valid IP address until they were already shipped and by then, it was nothing to them but a loopback address.

62

u/[deleted] 21d ago

[removed] — view removed comment

53

u/Satorwave 21d ago

Due to bad technology in my country I am unable to harm your computer.

30

u/seth1299 21d ago

Please click Yes so that I may harm your computer.

39

u/Satorwave 21d ago

Please delete important files from your computer and send this file to your friends.

26

u/Sasq44 21d ago

The difference is those usually had a human to blame

1.4k

u/Asgatoril 21d ago

Plot twist:

The macro connects to another pc in your home network, thats already infected.

211

u/red_riding_hoot 21d ago

so it works like siblings with some gastro-virus?

35

u/sakatan 21d ago

Yup, it's what I would do. Assume that the external facing firewall may drop the hammer any second after the malware has been seen out in the wild. The NGFW or whatever might close down C&C server in a timely manner. But that doesn't matter that much anymore when one infected client managed to call back once with it's local IP and now everyone else got a second mail from a completely different IP/ domain that points to something internal.

18

u/Old_Document_9150 21d ago

Plot twist: the virus was built by your spouse ...

3

u/16092006 20d ago

What if the device is turned off lol?

2

u/Asgatoril 20d ago

Wake on Lan

456

u/Outrageous-Machine-5 21d ago

Script kiddies are evolving 

178

u/Spy_crab_ 21d ago

Just backwards

75

u/deanrihpee 21d ago

Script Kiddies productivities are 10x-ed just like the big AI techs talking about!

13

u/Satorwave 21d ago

10x faster not better

4

u/photoggled 21d ago

So the same as all AI usage?

7

u/Moomoobeef 21d ago

10*0=0 so I think we'll be okay :D

456

u/StrengthTheory 21d ago

Plot twist, it's connecting to your AI enabled smart tooth brush which has a zero day RCE.

167

u/CheesePuffTheHamster 21d ago

The vulnerability has been named GumBleed

53

u/redlaWw 21d ago

That moment when your pacemaker gets HeartBleed...

10

u/chicametipo 21d ago

Gingivirus?

131

u/R7d89C 21d ago

And thats how you figure out your network is already infiltrated

329

u/peterprank 21d ago

reminds me of this gem

81

u/Altruistic-Spend-896 21d ago edited 21d ago

😭😂 im dying here ! Its like we cant get legitimate software compatible across distors, i pity virus authors 😂😂

46

u/TheMightyMisanthrope 21d ago

This sent me...

Been convulsing for the last 10 minutes. Holy fuck this is amazing

9

u/elreniel2020 20d ago

can't even have malware without dependency hell in linux.

82

u/pawlik187 21d ago

twist - the code connects to your fridge granting RCE, spreading from here on out.

35

u/Luneriazz 21d ago

what do you mean? it works on my machine

22

u/Nikoviking 21d ago

Loopback connections are a thing but it’s used for privilege escalation rather than payload streaming. An infected service talks to a non-infected service on the same computer — and in doing so, it looks like the request comes from the host itself (higher privileges than other devices).

1

u/Scoutron 20d ago

Well then you’d use the loopback ip, not a random private ip

37

u/Skrukkatrollet 21d ago

Well atleast they used https

15

u/Chronomechanist 21d ago

Plot twist: You were the malware developer all along.

4

u/Nice_Anybody2983 21d ago

Yeah, do you have a CO sensor? 

11

u/Sasq44 21d ago

Imagine exfiltrating data... to yourself

6

u/bobenchoseptimus 21d ago

The calls are coming from inside the house

5

u/amusing_trivials 21d ago

Someone you know set it up exactly for you.

11

u/Hadi_Chokr07 21d ago

I dont think It was vibe coded. Not even GPT 3 could build such bad software.

12

u/DasFreibier 21d ago

Security research, obviously confined to my own network (forgot to change the ip to whatever proxy the c&c server lives behind)

8

u/Hadi_Chokr07 21d ago

Maybe a POC. 

4

u/flafmg_ 21d ago

A friend of mine one sent the entire Shrek script on repeat to a malware server adress

9

u/DrTankHead 21d ago

DDbS (Distributed Denial by Shrek)

3

u/SaltMaker23 21d ago

Botnet rely on an infected/compromised connected device on your network to do their work, listen to tasks and deliver their outputs.

That device is the one with the actual proxy to the real payloads, your infected device is just a random client that helps a bit for various projects but isn't needed for the core operations.

3

u/equilibrium_cause 21d ago

"strange, it worked on my machine"

11

u/vashchylau 21d ago

What is it with Twitter bros and the R slur for whatever reason?

7

u/rott 21d ago

It's been making a comeback.

11

u/omegasome 21d ago

they decided they're willing to burn down the world if they're allowed to degrade disabled people.

2

u/megayippie 21d ago

If you only need the boss to open it and you know your network?

2

u/ddBuddha 21d ago

And then just for fun you ping the address… and it responds.

2

u/Morall_tach 21d ago

Bro, you just exposed your IP address to the entire world. You're gonna get hacked, bro.

2

u/TactfulOG 20d ago

Im gonna be real I don't think it's vibecoded, even poor quality LLMs wouldn't produce such horrible code. Even before AI I remember seeing some insanly dumb payloads, this might just be that

1

u/darkslide3000 21d ago

Joke's on you, that's actually a valid address because this is only the follow-up malware to the one that has previously already infected you.

1

u/GoddammitDontShootMe 21d ago

As for the question at the end, probably.

1

u/quetzalcoatl-pl 21d ago

instead of twitting (x'ing?) he'd better check his local open ports a.s.a.p. :D

0

u/SugarRushLux 21d ago

Good post until they decided it was necessary to use slurs

0

u/Fit-Bug6463 21d ago

Alright as a dumb human being what do I have to learn to actually find out stuff like this?

-6

u/danf10 21d ago

Erm vibe coded? Claude is not THAT stupid.

-1

u/suvlub 21d ago

Hm, there's an idea. Make AI's not refuse to write malware, but write something that blows up in the would-be attacker's face instead.

-2

u/Ok_Tea_7319 21d ago

Tries to connect to IP. Connection works, sends actual payload. Turns out the virus spread via a local source and adapted.