8 ms·
I think you're right. If the vulnerability is there and we know about it, it should be straightforward to write a proof-of-concept that anyone on a vulnerable s
by moreira 4y ago
I think you're right. If the vulnerability is there and we know about it, it should be straightforward to write a proof-of-concept that anyone on a vulnerable system can experience for themselves.
e.g. If a JavascriptCore vulnerability allows RCE on a Mac running whatever old version, write something to exploit it and execute the "say" command on that Mac, so anyone running that version can go to that webpage and literally see "wow this is a real exploit that actually works and anyone can abuse".
I'd love to see that. Kind of like the XSS script alert triggers, stuff where you can just paste a bit of code and prove that it -is- exploitable, without it actually doing anything harmful.
- sph 4y agoAFAIK there is a proof of concept for Spectre or another one of those speculative bugs, but it's academic, so not actually malware on a shady website that tries to steal my bitcoin.