PoC or GTFO 15 [pdf]
alchemistowl.org
alchemistowl.org
So this file is a PDF that's also a ZIP, and the archive contains - among other things - a song in MP3, and another PDF that's also a Git repo. Oh, and the whole bundle is supposedly laser-projector-compatible (that fact I can't verify - I have no access to such equipment).
I love this <3.
I wrote an ILDA parser in Rust [1], and I also have a virtual EtherDream laser projection DAC (also in Rust [2]) that you can play this against if you're interested.
I'll try to fire this up tonight and see what renders.
> The polyglot file pocorgtfo10.pdf is valid as a PDF, as a ZIP file, and as an LSMV recording of a Tool Assisted Speedrun (TAS) that exploits Pokémon Red in a Super GameBoy on a Super NES. The result of the exploit is a chat room that plays the text of PoC‖GTFO 10:3. Run it in LSNES with the Gambatte plugin, the Japanese version of the Super Game Boy ROM and the USA/Europe version of Pokémon Red.
For anyone who wants to read the back issues: https://www.alchemistowl.org/pocorgtfo/
If the 0day in your familiar pastures dwindles, despair not! Rather, bestir yourself to where programmers are led astray from the sacred Assembly, neither understanding what their programming languages compile to, nor asking to see how their data is stored or transmitted in the true bits of the wire. For those who follow their computation through the layers shall gain 0day and pwn, and those who say “we trust in our APIs, in our proofs, and in our memory models and need not burden ourselves with confusing engineering detail that has no scientific value anyhow” shall surely provide an abundance of 0day and pwnage sufficient for all of us.
Estimated availability August 2017
Consistent with the journal's quirky, biblical style, this book comes with all the trimmings: a leatherette cover, ribbon bookmark, bible paper, and gilt-edged pages. The book features more than 80 technical essays from numerous famous hackers
Other mirrors:
You can see the filelisting directly in the browser here: https://ipfs.io/ipfs/QmSYPTz9Eg2HyStSzVtiyUzehPDT1J9LEenBqt3...
Edit: decided to mirror all of them, provided in QmcLWK1R4KK7mDwSDwAm5Ny5gs185vgMpXbnbWbxp44Dvm - https://ipfs.io/ipfs/QmcLWK1R4KK7mDwSDwAm5Ny5gs185vgMpXbnbWb...
$ ipfs pin add QmcLWK1R4KK7mDwSDwAm5Ny5gs185vgMpXbnbWbxp44Dvm
It'll start downloading and then seed about 700 MB of data as long as you have the daemon running.
QmNsMdUqiSy8dQ1pNxGL2CVvZXDaNY9Lu53HRKKoYZNM7w
$ git clone PDFGitPolyglot.pdf testrepo
Cloning into 'testrepo'...
Receiving objects: 100% (432/432), 622.40 KiB | 0 bytes/s, done.
Resolving deltas: 100% (270/270), done.
Within the repo you can find the raw PDF, and all the source files for that PDF (including .tex article) and scripts for turning it into a git repo.https://www.alchemistowl.org/pocorgtfo/ (Click "Spoiler" for some of the old ones)
- The relevant table-of-content of its data is located at the end, unlike most other file format. (You can put it near the begnning too, known as "optimized PDF" to make displaying the first page faster when downloading sequentially.)
- The PDF format is, surprisingly, text with embeeded byte streams which can contain any data.
- It does require a !PDF marker near the beginning, but it doesn't need to be first.
- It support natively ZIP compression, so embedding a ZIP inside is easy.
- ZIP allows "cheating" by not really compressing data, thus allowing data verbatim and allowing large chunks of arbitrary data, as long as you can control the first few bytes.
With these technical freedom, building a PDF that look like multiple file format is more accessible.
edit: title's been fixed, this is no longer relevant
It is amusing to read it as "People of Color || GTFO" as a statement demanding racial equality in companies' hiring practices.
I'm less clear on when PoC came into vogue, but I think it was likely in the 90s.
Edit: Actually, reading more carefully, you can find "proof of concept" at least as far back as 1967.
Well, almost nobody, because that's what I think of when people use these terms to degrade others.
If anything it describes a certain hegemony by these disaffected groups as they slowly claw more and more of language as their own...
Work hire tests are anonymous and unbiased. Either candidates can do the work, or they can't.
You have to set it up so that the work-hire test is all that matters, though, which ~nobody does.
This will get off-topic quickly, if we allow it to.
It's true that it grows the subthread, but the [-] button exists now.
Okay, that's a logistical objection to work-sample tests, which is easily rebutted with, "Simply don't assign _a ton_ of unpaid work" to your candidates.
The process we use for hiring software developers at my current employer:
1. Clone this git repository.
2. Build a trivial feature (e.g. adding a search feature to an
existing blog platform).
3. Send a patch or pull request.
Everyone who's being considered gets the same task, and we base our decision off of several factors: Did they implement a working solution? How much new code did they need to create (knowing that the framework does 99% of this already, and is documented)? If so, did they write unit-testable code? Did they write unit tests? Did they find any of the intentional vulnerabilities?It should, realistically, take most people 2-3 hours at most to complete this task successfully. If they're familiar with PHP development, probably 15-20 minutes. Furthermore, it can be completed at their leisure.
If that seems unreasonable, contrast it with the cost of taking a day off work to get dressed up and perform an in-person interview during business hours with complete strangers who are scrutinizing you for fitness, with a very high chance of not getting accepted.
The burden of work-sample tests shouldn't be on candidates; the burden should lie with the company to ensure they're collecting objective facts about candidates rather than making subjective decisions.
There are lots of ways any test which (ostensibly) aims to test raw ability can be very biased indeed. A lecturer of mine once told a story about a horrible experience he had during an exam trying to whisper an explanation of the rules of Checkers to a student who was from a country where the game was rarely played - the possibility hadn't even crossed his mind.
Declaring the interview style you use as "unbiased" from the start seems like a great way to get complacent and have large amounts of bias creep in unnoticed.
Or, explicitly require / assume that all applicants be fully familiar with your culture.
Or, define an industry standard artificial culture - whether implicit or explicit - and require everyone on both sides to be familiar with it. This could include things like suits and golf for execs, hoodies and beer for techies, social justice activism for webdevs, etc...
However, I can guarantee that resting on your laurels and calling your process "unbiased" from the start won't work.
If your company structure/culture is broken your "unbiased" test probably will be too.
Under US labour law, any test where minority candidates don't pass at four-fifths the rate of others is presumed to be racially biased unless proven otherwise in court.
Judges don't have to study stats and end up writing most of these laws.
https://www.prevuehr.com/resources/insights/adverse-impact-a...
Even if someone refuses to learn, educate everyone around them and let social pressure either break their stubbornness or isolate them.
Out of context this is a very ominous sentence.
Fortunately, there are no intentional racists in that title.
I guess it's in a different mental context...
I don't think it's surprising that people would read it that way.
edit: added link to what I thought PoC was in this context: https://marketdelta.com/how-to-plot-and-trade-naked-pocs-poi...
;)
EG... if today APPL traded at $105 for more shares than any other price, and tomorrow the price is $106, we would say the naked PoC is $105 until it was revisited.