Scan a QR code, click the link --- aaaaand attacker has a shell on your phone.
17 karma · joined September 17, 2012
First thing in any lang: learn the tools available for debugging and quickly opening library code to trace execution. Set breakpoints; dive into stack traces.
Take the recent Java 1.7 vuln (3 weeks or so ago). Oracle released a patch 4 days after that exploit was rolled into Metasploit. I'm sure they'll tell you that's a coincidence, but it's still nice to see happen completely out-of-band from their normal patch process. Word around the campfire is that Oracle knew of that vuln for months w/out a patch. Then along comes big bad Metasploit and you've got a patch for everyone on Java 1.7. I call that a win.