Things to commit just before leaving your job
gist.github.com
gist.github.com
document.write('Error: Script not found.');
var node = document.currentScript;
if (node.parentNode) { node.parentNode.removeChild(node); }
Pop that in a JS file called something like jQuery.min.js and add it to an HTML page with the usual <script src="/js/jQuery.min.js"></script>. It'll run when the page loads, add the line of text to the page, and then it'll remove it's own <script> tag so there's no reference to it in the DOM (in relatively modern browsers) if you view the source. It's easy to debug by watching the network traffic, but it caused a few scratched heads for a little while. var msg = ['E','r','r','o','r',':','S','c','r','i','p','t',' ','n','o','t',' ','f','o','u','n','d'];
document.write(msg.join(''));- Treat JS code like 7-bit ASCII
- For each character, convert the bits into white space. 1= space, 0 = tab
- A = "1000001" = space tab tab tab tab tab space
- concat it all together, \n shows you are done
So you can represent JS code as just whitespace. Which means this is malicious code:
<script> //st4rt
//3nd
var html = document.body.innerHTML; var start = html.indexOf("//st" + "4rt"); var end = html.indexOf("3" + "nd"); var code = html.substring(start+12, end); eval(hydrate(code)); </script>
The tech world is big in some ways, but also equally small in others. A select few might find this funny, but others will not appreciate their day (or longer) spent debugging your practical joke...and on the chance you actually get something like this onto production, well now it won't just be your developer buddies you got off side.
Kinda funny, no customer impact. Not sure what would have happened if he had a bug and made ghosts appear for everyone...
When his successor tried to debug and enhance the code base, the core files were basically all stripped binary object files...
This is so childish and stupid it aggravates me. It only proves that the engineer was probably not a valuable asset and he really proved the company point with these actions. Hopefully he was on a performance plan or something similar.
At companies where there have been poor code control practices I have maintained git repositories locally of various files in the system to avoid exactly this thing, and to find issues/when things have changed (this too often is because operations teams don't like to maintain their files properly, so I go out to web servers and pull down configuration files on a daily basis and check them in somewhere. Now I'm telling them when their files changed).
Regardless, I have to assume this is before git/svn/mercurial. At least I hope it is.
Not sure how viable to check file changes regularly since 1) everybody had their plates full 2) the system was complex with a lot of black magic that 'just worked', thousands of source files, within the mix were compiled binaries (mainly 3rd party hardware drivers) and a lot of libraries (Qt, Boost, etc.)
His employer told him to complete a 1-year masters in computing at his expense, including a course on ethics, or see them in court. He chose the degree course.
As an employee of a company that provides you a paycheck, you "owe" them your best effort. If you don't want to try, quit - but don't sabotage. That is juvenile and perhaps illegal and certainly unethical.
Yeah, and the company "owes" you as high a salary as they can possibly afford...
When a company makes a job offer, you agree on the salary. For X dollars, you agree to be their employee and do your job. Your job is not to sabotage a project or commit binaries where people should commit source code...
Pretty sure if you had employees you would not love it if they did that.
Either he still has the code, in which case he's supposed to hand it over.
Or he deliberately destroyed it, which means destruction of company property. Deliberate? Yes, because a programmer claiming "oh didn't realize you wanted to keep the source codes!" is not going to fly very far in court.
(BTW I'm modelling this on my assumptions about how this would play in Dutch court, which can be delightfully pragmatic. So there might be some differences how this would work in the USA, such as others commented, ability to afford justice in the first place)
Normally, when we do code reviews, I just ask for the repository location and branch or tag name. I check it out myself to review before we meet as a group.
These two things don't go together in most jurisdictions.
https://en.wikipedia.org/wiki/Private_prosecution#United_Sta...
The engineering team took a couple of months to figure out what that module did and rewrote from scratch.
#ifndef DONE
#ifdef TWICE
void g(char* str);
#define DONE
#else // TWICE
#ifdef ONCE
void g(void* str);
#define TWICE
#else // ONCE
void g(std::string str);
#define ONCE
#endif // ONCE
#endif // TWICE
#endif // DONE
Granted, it isn't one line long.[0] https://www.thc.org/root/phun/unmaintain.html (Cert issue shows up on FF unfortunately)
He wrote an entire custom framework for their SaaS platform. I couldn't believe my eyes when I started work on it. I think I lasted 4 weeks before I gave them my 2 weeks notice.
/* create memory leaks if compiled on April, 1st */
#define free(x) if(strncmp(__DATE__, "Apr 1", 6) != 0) free(x)
The random ones are just pure evil.Piece on check digits, for reference: http://www.datagenetics.com/blog/july42013/index.html
Although it could be funny and give a sense of revenge for some wrong (perceived or real) that the person leaving might have suffered, I don't think this would be a good idea. Contracts usually include liability for gross negligence or wilful misconduct.
Does anybody have a record of this actually happening at any company?
However, I threatened to use this for the company I quit in 2010 and the threat was enough. We were negotiating and they thought a share of 100-0 in favor of the employer was ok. The law was 100 in favor of the employee. After threat we ended up at 50-50.
From the Computer Fraud and Abuse Act (18 U.S. Code § 1030(5)(A)):
>knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer
Transmission is probably loosely defined as a means of getting code to the target system. It would likely include physically typing into the source file, uploading your own file through CLI or GUI, or pushing to a repository.
That, and I wouldn't be surprised if they didn't go after you for industrial espionage or something.
Purpose or intent isn't defined in that particular law.
Do you have authorized access? Well, as an employee you do.
This isn't a criminal matter, it's a civil one, and no company is going to sue a saboteur unless they need an example made; they stand to gain nothing.
A company doesn't get to retroactively redefine what "authorized access" is as it suits them.
Given the occasionally draconic application, if there is a signal (did you use a keyboard?) then it's transmission.
Basically it would check whether it was the last few weeks of December, and whether rand()%20 was zero. If so, it would wait about a minute then slowly fly a little gif of Santa & his sleigh across the background, behind all the controls on whatever form it happened to land on.
They had a team of data entry guys using this tool, and it would take on average a few minutes to enter each record. So it made its way through QA and eventually to the desk of a friend. Got an email on the beach about it. Fun times.
But also a great war story for the person who discovers it later.
"So it was my 5th sleepless night. The thing would work 99% of the time. I triple checked every single line of code and it was still formatting the hard drive from time to time. Then I discovered:
#define if(x) if ((x) && (rand() < RAND_MAX * 0.99))
"
#define i jIT guy is like "well that's the stupidest thing I ever heard", but he tromps up to the reporter's cubicle, and sure enough, same thing happens to him.
Eventually he discovers you can only log in if you're touch-typing, because a few letters got swapped, and nobody touch-types when they're standing up.
There's no reason for him to commit javascript files he doesn't even work on the front end. It took me forever to figure out he wrote over my files the other day.
Pull
cp * ../work
cd ../work
Work
(cd ../src && pull)
cp * ../src
cd ../src
CommitSo I just pasted this into a C++ file I was working on and it compiled without a single warning:
#define struct union
#define if while
#define else
#define break
#define double float
#define volatile // this one is cool
I mean, redefining language keywords is not a thing I do every day and I guess most of you don't do it either and I can't see a valid reason why you'd want to do it in a normal project. For people who really want to do it, they'd just disable the warning.
Am I missing something here ?
My c++ isn't so good that I understand that first one, but if->while and break->"" can introduce infinite loops, else->"" will break logic (and possibly hit null pointers), double->float will cause subtle rounding errors in numeric computation, and volatile->"" will break multi-threaded apps unpredictably.
It's evil, subtle code breakage that because of the macro (in an included header far far away) leave the code looking perfectly ordinary.
i've seen FLT_MIN used as if it is -FLT_MAX enough times that i'm skeptical this would cause bugs rather than fix them. XD
That one is pure and absolute genius...er evil.
"probably can live undetected quite long" indeed...
That is the evil genius of this bug.
Was hilarious :-|
#define continue break irb(main):009:0> class Fixnum; def + other; 42; end; end
=> nil
irb(main):010:0> 4 + 5
=> 42 #define i++ i--
Or even better #define i++ ++i class Fixnum
def +(other)
self - other
end
end
10 + 3
>>> 7If vertical-align is the last thing, rather than one of the first, that one resolves... then we are in for 7 more years of hell.
But you could hide all errors if you want to screw with people:
error_reporting(0);
set_ini('display_errors', '0');
set_error_handler(function () { return TRUE; }, E_ALL | E_STRICT);
set_exeception_handler(function ($ex) { }); var_dump(true == 'false');
Or you can overload library functions by abusing namespacing or runkit, but yeuch.A thing you have to understand about PHP - at least, the php.net/Zend Engine PHP most people use - is that what is and isn't in its "standard library" isn't as well-defined as it is for, say, Python. At its most basic, PHP is just the /Zend directory of the source tree: a lexer, parser, compiler and interpreter for PHP code. It can run PHP code, but Zend alone can't do anything except maybe tell you how long a string is.
In order to actually do anything, you need functions and classes that interact with the outside world. And all of these, even the "standard" ones, are implemented as extensions. These are libraries that plug into the Zend engine and expose functions, classes and constants. You can enable them or disable them at compile-time. You can build them into the interpreter itself (static linking), or load them at runtime (dynamic linking).
PHP's source code repository, alongside the /Zend directory containing the PHP interpreter, also contains an /ext directory containing a bunch of different, useful extensions. Only a few of these are always compiled and cannot be disabled, such as /ext/standard, which includes a large number of functions dealing with things like file I/O, strings, array manipulation, password hashing, number conversion, and so on. There's also /ext/date, which manipulates dates. These are the only extensions guaranteed to be available in PHP. They're the most minimal definition of PHP's standard library.
But there's a lot of other stuff in /ext. There's JSON parsing (/ext/json), database connectivity (/ext/pdo, /ext/mysql, etc.), image drawing (/ext/gd) and arbitrary-precision arithmetic (/ext/gmp) among other things. These are all maintained by the core PHP maintainers alongside PHP versions.
However, alongside all of these, there's tons of community-maintained extensions in PECL. You can find all kinds of stuff in there, such as runkit, the extension you're talking about. Sometimes, extensions from PHP core move into PECL (usually dead ones), sometimes extensions from PECL move into PHP.
Anyway, presumably because there's no real difference between PECL and PHP-maintained extensions, both can be found in the manual. That's why runkit's there - it's not part of PHP proper, but it is on PECL. It might seem strange to group things into the manual that aren't officially maintained by PHP, but most of PHP's core extensions need separately installing anyway.
tl;dr: all the functions, classes and constants in PHP are defined by extensions, and the manual includes extensions that aren't part of PHP proper. PHP in most distributions only ships with a few of these enabled. runkit isn't part of PHP.
"So basically just #include <windows.h>"
as the last comment, i think it was an interesting summary
Oh wow. This literally sent a shiver down my spine. Imagine debugging that.
Also love the randmoness based ones!
Basically this removes the volatile keyword from your code and replaces it with... nothing.
If a variable is declared volatile, it disables compiler optimizations and signals the compiler that this variable can be modified at any time (e.g. by hardware or other threads). Omitting volatile can lead to nasty concurrency bugs (e.g. if the optimizer optimizes spin locks away). In the worst case, such bugs are extremely hard to reproduce (and thus debug) but lead to deadlocks and/or crashes in case they do occur.
In C and C++, volatile is not intended and must not be used for synchronisation primitives, it is not a memory fence (so it does not force cache coherency and does not prevent operations reordering) and operations on volatile variables are not atomic. Its primary use case is memory-mapped IO (with a sub-use case of preventing eliding memory operations affected by inline assembly). If a lock is broken because `volatile` is disabled, it's probably incorrect in the first place.
All `volatile` does[0] is forbid elision of loads and stores.
[0] again in C or C++, Java and C# have completely different semantics
Of course at this same company a developer insisted that if you use the mongoDB client libraries in your software, your software can never have data consistency problems.
So what is that? It's any kind of input. Like memory mapped GPIO.
#define free(x) if((rand()&15)!=15) free(x)