HN user

samuirai

165 karma

www.smrrd.de

Posts12
Comments13
View on HN

Several hours later, Google star vulnerability researcher Tavis Ormandy tweets(!) an embarrassing drive-by RCE in Aviator.

This bug was reported many months ago (though at that point it wasn't clear that it was actually a RCE). see:

In early 2014, the "Error138" is reported and disclosed first time.

Am I stupid or is this guy calling a XSS "Arbitrary Code Execution"? It also seems to be a self-xss (a XSS on his account profile, which only he can see).

How can you write so much text and be unclear about what you are doing? No wonder Paypal didn't understand anything.

Imo it's a very good thing that they have to spend a lot of time researching. Along the way they will see and learn many different things and in the end provides experience. Thus I agree with _almosnow.

That it's so interesting. A lot of people said that to me. But to me it felt more natural to highlight old code. Probably because I had this bias in the back of my mind that old code could be bad code.

I didn't want to make it look that way. The color indication is without any judgment. It's just interesting how code evolved over time. In fact you should reverse the color gradient or use different colours, so you can read code how you prefer it.

I thought about using OCR - just to over-engineer it. But I wanted to show how the characters are perfectly aligned and how clear the font is. I would like to understand, what he thought, why this Captcha is so special.