CTO @crashappsec. Past: Cofounder and Chief Scientist @capsule8, Hacker-in-Residence @NYUTandon, and other research, reverse-engineering, and exploit dev roles.
@nudehaberdasher Alas it was a different time: the payout itself was another zeroday. And the hacker against whom I bet indeed made good on their end of the wager, dropping a kernel bug in the IRC channel for all to see! I'll see myself to the retirement home now.
🤔 I'd need to examine the bug, its setting, how much input/app state can be manipulated before I could say for sure.. but 3 bytes OOB is often 2 more than needed to get new primitives/code exec. I wonder if the team assessing this had any past experience manually shaping heaps?
@nudehaberdasher ... in IIS I think? Another hacker (whom I respect highly, left unnamed) bet me that the bug wouldn't see a real exploit written. It was unfair as I knew how close the exploit was. TL;DR it landed, and I worry the wisdom from that era is lost among the teams that need it most now