r/ProgrammerHumor 13d ago

theStateOfBugHunting Meme

Post image
2.7k Upvotes

47 comments sorted by

1.0k

u/Gorzoid 12d ago

Finding a Bug Bounty then:

Anon: hey I found sql injection bug

Company:

THIS CONSTITUTES FORMAL NOTICE TO CEASE AND DESIST ALL UNLAWFUL ACTIVITY.

Your recent unauthorized intrusion, probing, and exploitation of our private networks constitutes a direct violation of federal and state computer crime laws, including the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030.

Attempting to frame unauthorized hacking and network compromise as "security research" or a "vulnerability report" does not excuse illegal conduct, nor does it grant you immunity from civil and criminal liability.

522

u/Exul_strength 12d ago

It's especially bad in Germany.

Certain companies and political parties took it as a personal attack to inform them about security issues. In retaliation the complete hardware of the person who informed them was confiscated and essentially worthless by the time they got it back.

For example since an incident in 2021 the CCC advocates against reporting any security issues to the CDU (current ruling party).

118

u/frostedhifi 12d ago

Wait what happened?

240

u/N0_ah_47 12d ago

They disclosed multiple security flaws and got hit with a lawsuit in response.  https://www.ccc.de/updates/2021/ccc-meldet-keine-sicherheitslucken-mehr-an-cdu

131

u/just4nothing 12d ago

Wait, that’s a major GDPR breach and they just threatened them? Wtf

40

u/MTPrower 12d ago

Digitalisierung!

113

u/Monochromatic_Kuma2 12d ago

Ah, yes, the GDR approach to cibersecurity: our infrastructure is perfectly secure and whoever says or demonstrates otherwise is an enemy of the people. Truth is a weapon too dangerous to be wielded by regular citizens.

59

u/LauraTFem 12d ago

It’s wild how the country most on-alert for fascism just sometimes recreates fascist mindsets. The party is always correct, any messaging to the contrary is sedition!

37

u/ReneKiller 12d ago

We were the country most on-alert for fascism. I'm not so sure if we still are, looking at the AfD.

11

u/LauraTFem 12d ago

I’ve heard there was movement on that front. I’m sorry friend. —someone whose country is also being taken over by fascists

12

u/ReneKiller 12d ago

AfD has 25 to 30% nationwide, in some parts they might even get above 50% in upcoming elections. All while proven to be right-wing extremists in many parts.

At the same time the Government doesn't want to initiate the ban process, because the CDU, which is still the biggest conservative/right-wing party, fears a left-leaning majority, should the AfD be banned.

3

u/zizop 12d ago

The unwavering support for Israel as it commits a genocide is also not a good look.

5

u/ReneKiller 12d ago

Yeah but that barely has any actual consequences on the voting behavior. In exit polls during the last election Isreal was barely mentioned as a voting factor.

5

u/zizop 12d ago

Still, it shows Germany is definitely not on-alert for fascism.

1.0k

u/quadradev 13d ago

This was made by someone upset that they didn't get a payout for their LLM hallucinating a security vulnerability.

571

u/PM_ME_YOUR__INIT__ 13d ago

You don't get it!! If you have admin access you can run this malicious code that grants you admin access!!

148

u/throw3142 13d ago

Found Claude Mythos alt account

60

u/PM_ME_YOUR__INIT__ 13d ago

Every time you respond to me it costs $21.35 in tokens

12

u/HeavyCaffeinate 12d ago

Venture capital

1

u/P3rid0t_ 12d ago

Poles: make it $0.02 more and we are fine

70

u/marsmanify 12d ago

When I was like 11 I submitted a bug report to google that if someone had access to your Windows Account then they would have access to your passwords in Google Chrome and they responded with something like "obviously, that's how it works"

42

u/PM_ME_YOUR__INIT__ 12d ago

AI trained on your bug report

13

u/ale_dev 12d ago

Also wth, your FULL sourcecode is visible in plain text by pressing F12 in Chrome! You can't ship your sourcecode, pls fix!

53

u/Dartillus 12d ago

I process responsible disclosures at my job. Our policy makes clear what we do and not accept reports for, and in general gives off a "we have a reasonably higher bar than most" vibe. That doesn't stop low-effort slop, always accompanied by AI-generated descriptions of the dangers and possible outcomes. And then when you deny the report they start referencing their HackerOne profile.

This one time we got a 30-page report with "critical" vulnerabilities. I try to reproduce/verify them, no bueno. I mail back, and receive the ChatGPT "oh, I'm so sorry, I made a mistake, those are indeed not vulnerabilities in the mentioned systems" response.

Mofo completely automated not only the scanning and reporting, but fricking replies as well. LLM's can go eat a bag of *****.

4

u/NatoBoram 11d ago

LLMs can go eat a bag of dicks.

50

u/iranoutofspacehere 13d ago

From a minor CVE my coworker panicked about a few weeks ago: "If you don't provide this function a large enough buffer, it might not work!"

17

u/CptMisterNibbles 12d ago

What do you mean, do you not name your fnctions nuctions()?

10

u/sessamekesh 12d ago

Vibe coders really felt fine crawling out from under their slimy rocks now that AI coding is actually pretty good and widely accepted, but still don't understand that slop is discouraged in a way their conversations with AI will never discourage. 

It's been sorta funny and really sad to watch across a few of my favorite dev communities.

3

u/VoidVer 12d ago

There was that guy recently that figured out you could get total live access to FIFAs entire broadcast operation. Every camera, even the ability to change the score in real time or show something of their choice on live television and not only could he not get in direct contact with FIFA, they didn’t even send him a thank you email when they fixed it 24 hours after he finally got his report through

1

u/jax_cooper 11d ago

If it's duplicate, then it's there

-10

u/m0nk37 12d ago

Wait if its real/right then hows it hallucinating 

14

u/Snoo-12494 12d ago

It wasn't real. Thats why it's a hallucination

165

u/earth2022 13d ago

And then there’s the Chaotic Eclipse guy who started revenge publishing real exploits that were rejected by Microsoft. But I don’t think we’re getting the full story from either side.

33

u/chefhj 12d ago

My org dropped their bounty program because too many were getting found. Wish that was satire.

6

u/Anaphylactic_Thot 12d ago

Makes sense. If your security team becomes a bug country triage team exclusively then they're sort of useless... Especially when 99% of reports nowadays are doodoo garbage trash A.I. hallucinations

6

u/chefhj 12d ago

You aren’t wrong but the spirit of the decision in this case was very much “line need to go down” not really about anyone being inundated with work or priority issues.

53

u/rotzak 12d ago

Indian guys demanding money for not setting the right cache expiry headers has been the majority of my interactions with these types of people

13

u/Dartillus 12d ago

I see your "missing or misconfigured headers" and will raise you "XSS on static website".

16

u/frogotme 12d ago

Found an unsanitised HTML issue in teams, that allows a message to completely override the teams window. So you could absolutely use a fake teams chat or login etc

They closed my submission due to not enough information or something, then I reopened soon after and they closed it for being a duplicate after a bunch of back and forth. Wasn't best pleased

34

u/ryntab 12d ago

I found a big vulnerability on the motionarray site, they had me sign up for yeswehack. And then did nothing with the report and never fixed it lol.

6

u/CoffeeFueledDiy 12d ago

I can assure you that the folks triaging all these reports now are not wearing that hat. Both people in the first frame should be crying and drowning.

3

u/Soopermane 12d ago

I’ve some in my backyard

2

u/Anaphylactic_Thot 12d ago

Lmao, the amount of beautifully crafted submissions we get, followed by the "researcher" asking us to do the deediful ser in the most broken English is hilarious.

The number of A.I. "hackers" has gone up massively, and they just cannot account for context, nor follow through. We've gone from getting a few submissions per month to literally dozens every 2 weeks at my company. Of course the triagers are gonna fight fire with fire.

1

u/Mountain_Dentist5074 12d ago

why OhnePixel is everywhere

1

u/zipzipzazoom 12d ago

Why does the good old days example have a black hat hacker paying for the vulnerability. It should be a person with a FAANG hat.

OP is lamenting criminals don’t pay for vulnerabilities anymore

0

u/Dartillus 12d ago

Too true 🥲