HNHacker News
TopNewBestAskShowJobs

pbear2k23

89 karma · joined February 10, 2023

submissionscomments
pbear2k23··on Zero-day Bitcoin OOM crash
tl;dr https://pastebin.com/raw/qr8XWFkR - you f*cking ping faster than it pongs. this wasn't discovered until recently. sad.

i put this together. it also contains a mode for CVE-2023-33297 ('headers') which was recently patched - although i wasn't given credit because i have haters @ bitcoin-core and blockstream. they kinda run the show now. i'm even banned from contributing to the bitcoin-core github. much decentralization.

how to reproduce the vulnerability yourself:

1. install bitcoin

2. ./bitcoind

3. edit your ip into attack.go: https://pastebin.com/raw/qr8XWFkR

4. save attack.go

5. snap install go --classic

6. go build attack.go

7. ./attack

8. slow oom crash - enjoy the fireworks

screenshot: https://i.imgur.com/DA80ORS.png

happy to answer any questions

pbear2k23··on New Anti-Deepfake Strategy
that's... not at all a solution. "just use onfido" doesn't solve deepfakes. too much friction isn't true whatsoever it would just take some solid coders. and finally i don't suggest that anyone work with onfido. they fleeced me out of a $10k deposit in 2018 for kyc services that were falsely advertised as deeply international only for us to realize that wasn't the case at all. no refund. no partial refund. no access to credits anymore. $10k gone because onfido is shady.
pbear2k23··on New Anti-Deepfake Strategy
i came up with this. it has a lot of moving parts but it's viable. i understand the idea of "why not just publish transcripts in advance on whitehouse.gov" and the answer is because there are too many points of failure, like the risk of shells, rogue actors, dns hijacking, ddos, etc.

these issues are alleviated by multiple blockchains running byzantine fault tolerance against speeches that are monitored and authenticated by public facing figures both beforehand and during the live broadcast.

i know it seems complicated - but it needs to be.

happy to answer any questions if they aren't rude. i understand that this is a lofty proposal and the natural reaction is a knee-jerk "yeah ok" - but give it a read. play with it in chatgpt. this is about viability and computer science theory more so than a tangible effort in establishing a funded operation.

tl;dr blending bleeding edge technologies together to 360 noscope deepfakes.

pbear2k23··on 0day Bitcoin P2P Crash (OOM)
this is being privately disclosed - but i found it and attest to its authenticity. i'm happy to answer some, but not all, technical questions.
pbear2k23··on New Bitcoin DoS Exploit Code
if for instance the attack program was routed through tor i don't see why it wouldn't work at damaging capacity with a modified script
pbear2k23··on "Patched" Bitcoin DoS Still Vulnerable
Updated X link https://x.com/123456/status/1736023700057608352
pbear2k23··on CIA's Telegram Hijacked
>right, because so many people are typing in the incorrectly shortened URL instead of clicking on the link

it was clickable - and yes they dodged a bullet. the channel could have been perfectly reproduced, made to look real, and then used to intercept western intelligence. there was no manual "typing" of links

pbear2k23··on CIA's Telegram Hijacked
was me if anyone wants details - but it's pretty simple. not a hack. registered an available username so that opposition ic groups couldn't do the same - they could have dressed it up in a visually identical way and intercepted western intel as a best case scenario.

it's just an intelligence failure. those aren't new - nor is this really even that big of a deal - imo - it just could have hypothetically been a big deal - and i don't really care for hypotheticals

video demo of the ethical-hijacking of the cia tg https://x.com/123456/status/1714496858754576516?s=20

pbear2k23··on Doxing Has Become Spooky
so you didn't read it but are sharing meta-feedback?
pbear2k23··on Active Critical Bitcoin Exploit: A Financial Attack Swept Under the Rug
i discovered the issue if anyone would like for me to unpack anything.

content snippet + attack code:

the takeaway from pad vs bitcoin is that a botnet can remotely charge public listening node operators thousands of dollars.

that would snowball into a mass exodus of public nodes until all that remained were millions lost unexpectedly by thousands of node operators - and a network centralized by entities able to weather the cat 5 hurricane of upstream overage fees, like:

1. mining pools

2. exchanges

3. hnwis

4. governments

effectively centralizing the network and causing countless millions in damages. the ethos of bitcoin and the financial survival of its operators are at stake.

example attack code: https://github.com/visualbasic6/drain

pbear2k23··on Tumblr Phishing Attack (2011)
don't mind me - nonchalantly taking credit for various nonsense i did as a kid. way past the statue of limitations - and hopefully found interesting to someone
pbear2k23··on Phishing 2FA 25 years ago
> Taking over AOL “int” accounts was actually considered pretty basic at that time.

to the skillful it was considered basic - for sure. there was a lot of collaborative intelligence in the aol "hacking" scene, though. and you could do a lot on an int. even reading internal aol emails often returned a treasure trove of new tools and information

>The best was when Gosh

legend

>was fun to DoS entire rooms of users offline

yeah that could be done to older computers just by scrolling without rate limits as you mentioned. semi-related - i once found a dos in skype that made use of skype4com.dll to change your display name hundreds of times per second. if you had more memory on your computer than your contacts did you could dos hundreds of people at once. i remember it reminding me of some corny aol "hack"

pbear2k23··on I phished the hell out of Tumblr in 2011
It's been 11 years and I've left the blackhat life behind - so whatever - I did it.

Articles:

https://uk.pcmag.com/opinion/110826/massive-phishing-attack-...

https://www.adweek.com/performance-marketing/phishers-steal-...

https://www.silicon.co.uk/workspace/phishing-scam-harvests-t...

https://www.eweek.com/small-business/phishing-scam-on-tumblr...

https://www.crn.com/news/security/231000730/tumblr-hit-with-...

https://www.csoonline.com/article/531562/tumblr-hit-with-hug...

https://www.cnet.com/news/privacy/phishing-attack-nets-tumbl...

https://securelist.com/yet-another-phishing-attack-tumblr-us...

https://www.businessinsider.com/tumblr-hacked-phishing-2011-...

https://www.nbcnews.com/id/wbna43566344

pbear2k23··on Archive.org was quietly hacked in 2012
huh?

i'm an irish-american from maine. it's boring here

pbear2k23··on Archive.org was quietly hacked in 2012
tru

still had to crack into a top ~300 website and shell it before wall clipping into archive.org's wp and shelling that too

i'm of the opinion most everything has been shelled. indeed i was probably not the first nor will be the last.

pbear2k23··on Do Women Have Fewer Sex Partners Than Men?
at the very least - this is spectacular bait
pbear2k23··on How to disable the Bitcoin network with a botnet
they are
pbear2k23··on How to disable the Bitcoin network with a botnet
>Is there any way to detect if someone is doing this?

hope so

>Any idea if it'll work on ethereum?

hope not

this one might be bad

pbear2k23··on How to disable the Bitcoin network with a botnet
well - botnet operators don't care - and download is cheaper than upload
pbear2k23··on How to disable the Bitcoin network with a botnet
i found the "exploit"

it's pretty frightening how simple/easy this is

happy to answer questions and/or have this claim disproven

pbear2k23··on Blockchain Based Anti-Deepfake Proposal
Fast blockchains with sub-second block times actually fit. I agree that most implementations of blockchain are awful - but this just technically makes use of the nature of its immutability - and would showcase Ricardian contracts (600+ pages of text) versus smart contracts (garbled memos)
pbear2k23··on Blockchain Based Anti-Deepfake Proposal
The official white house website is vulnerable to being DNS hijacked or shelled.
pbear2k23··on Twitter Hack (2009)
some old articles about it:

https://www.nbcnews.com/id/wbna31610125

https://www.cnet.com/tech/services-and-software/hackers-blam...

https://www.billboard.com/music/music-news/spears-twitpic-ac...

https://www.theregister.com/Print/2009/06/29/spears_twitter_...

https://abcnews.go.com/Technology/story?id=7962624

https://www.mtv.com/news/0tc4mo/britney-spears-twitpic-accou...

pbear2k23··on Bitcoin Exploit
yes - that's why i never made the claim that the entire network was vulnerable to the attack. you are correct :thumbsup:
pbear2k23··on Bitcoin Exploit
the conclusion of your argument is "this has absolutely no chance of making any dent in the network as a whole" which is faulty. much of the network is hosted by providers that charge for upstream overage: https://bitnodes.io/nodes/?q=ipv4#networks-tab. if a pool's full node is tcp/8333 exposed or a conventional full node is attacked on a vuln host there will be financial/operational consequences. this attack is a "nothing-burger" until botnet skids demonstrate otherwise.
pbear2k23··on Bitcoin Exploit
you seem to be mixing up that mining pools expose tcp/8333 and if one pool's full node is attacked - many miners are caught in the crossfire unless in some type of special firewalled whitelist.
pbear2k23··on Bitcoin Exploit
>it's a minor issue with an impact that is greatly exaggerated or sensationalised by the person reporting it.

until, again, a botnet makes huge swaths of the bitcoin network unprofitable.

this is computer science - not how you feel about or faultily interpret an exploit.

pbear2k23··on Bitcoin Exploit
it's an issue. it shouldn't be possible to pull a range of 2000 block headers in an unthrottled way from a remote bitcoin node. while you make some valid points - i find it humorous that you have tasked yourself with defining what constitutes a security vulnerability. furthermore - you may want to examine https://bitnodes.io/nodes/ and come to a realistic figure of how many machines running bitcoind aren't accepting tcp/8333 from 0.0.0.0
pbear2k23··on Bitcoin Exploit
that's actually not correct. apples and oranges. we're talking about mining rigs - not websites and apps maintained by sysadmins who can apply a simple fix or waf during an upstream overage attack. if this was a non-issue they wouldn't be patching it https://github.com/dogecoin/dogecoin/issues/3243
pbear2k23··on Bitcoin Exploit
until a botnet makes mining unprofitable for huge swaths of the network - effectively turning the nodes offline
Page 1 of 2Next →