HNHacker News
TopNewBestAskShowJobs

unknownhad

66 karma · joined August 1, 2013

submissionscomments
unknownhad··on I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table
Hello OP here I was one of the 1100 people impacted by the recent layoff. Thats when I started looking into offensive security/exploit writing more closely and actively. I have been doing blue teaming/defender's work for over a decade. While I knew about and had explored exploit writing, I had never done it as my day job (mostly for fun and CTF events). As I had no job and some downtime, I started looking into it.

My 1st blog post was about a V8 exploit: https://blog.himanshuanand.com/2026/08/i-had-some-free-time-... This is the 2nd one, about kernel exploitation.

My aim is always to write in a way that people without much hands on experience with exploit dev can still understand and learn from. Feel free to share your questions/comments or ways I can make these blogs even more reader/beginner friendly. m happy to answer any technical questions, though I believe HN folks know much more than I do about the Linux kernel.

unknownhad··on Inclusive Syntax: outdated tech terms and clearer alternatives
It's a Smol side project additions/updates welcome.
unknownhad··on Kernel Kill Switch
This looks like an interesting proposal. My previous post : https://blog.himanshuanand.com/2026/05/the-90-day-disclosure... Highlight the issues some of these can be fixed by these, IIRC BSD already had similar feature.
unknownhad··on The 90 Day disclosure policy is dead
I think this assumes software is a static target (Which it is not) . We are not just using LLMs to scan old code developers are using LLMs (like Copilot and others) to write new code and they are doing it by the shovel-load. The pace of shipping has gone up which means the pace of introducing new bugs has gone up right alongside it. The bug pool does not empty out because we keep refilling it every sprint.

Plus, the definition of the "easily found stuff" is a moving target. The AI models aren't static either. What takes a human reverse-engineer a week of deep insight today might just be a standard automated API call by 2027.

So while I would love for the dust to settle in a year, I think we are just looking at the new normal.

Thanks for reading the post and for the great counter-point!

unknownhad··on The 90 Day disclosure policy is dead
The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone. LLMs have compressed both timelines to near-zero. I have seen it first hand, and so has everyone else paying attention. This post lays out why the old model is broken, with real stories, and makes one ask to the industry: treat every critical security issue as P0 and patch it immediately.
unknownhad··on Ask HN: Are you missing daily email alerts from HN?
I have received an Email today. I was using https://www.hndigest.com/ Kudos to the person behin.
unknownhad··on Ask HN: Are you missing daily email alerts from HN?
All the Emails were from `hello @ hndigest.com` W00ps, My understanding was this is from HN.
unknownhad··on I Found a Europa.eu Compromise
While looking for a way to stream the India vs Pakistan cricket match on 14th September 2025, I stumbled across a suspicious search result on a europa.eu dev subdomain. It was being abused for blackhat SEO and redirecting users to scam streaming sites. I traced similar behavior across other high-profile domains, reported the issue to CERT-EU via email (after some Twitter help) and the problem was later confirmed as fixed on 6th November 2025. This post walks through how I found it, how I reported it and what we can learn from it.
unknownhad··on Look mom HR application, look mom no job – phishing using Zoom docs
A phishing campaign that uses Zoom's document share flow as the initial trust vector.

It forces victims through a fake "bot protection" gate, then shows a Gmail-like login. When someone types credentials, they are pushed out to the attacker over a WebSocket and the backend validates them.

unknownhad··on Prompt Injection Detection
This is something like AI Firewall, currently only checking for requests, can be used for responses. (And that will add lag and as response is streamed so not implemented yet, lazy me)
unknownhad··on Did Google just removed all the HTTP://chatgpt.com/share indexed pages?
Sharing twitter link with image in it.
unknownhad··on I found a 0day in libpng(11 years after it got patched)
100% correct. Couple of reasons

1) I felt like I made it sounded like I am leaking a 0 day , which it isn't.

2) AI agent thought it was AI generated

I like LLM's but broo I spent a little too much time on this and don't want AI to claim it as AI generated content.

unknownhad··on CoinMarketCap Client-Side Attack: A Comprehensive Analysis by C/Side
Thanks.
unknownhad··on Weaponized Google OAuth Triggers Malicious WebSocket
This looks interesting, This trick is good for hiding the bad code and to bypass the CSP.
unknownhad··on 10k WordPress Websites Found Delivering macOS and Microsoft Malware
The most interesting part of this particular attack was the attackers delivering cross platform malware. SocGholish is a well known commercial malware previously seen to be associated with infecting victims with ransomware while Atomic macOS Stealer is new.
unknownhad··on ButterCMS unreported downtime and security concerns
There are several red flags in this situation:

1) ButterCMS should have informed their customers/users about what they missed. 2) The way the issue was introduced could have led to a significant supply chain vulnerability. 3) I haven't found any analysis or communication from ButterCMS addressing the issue with their customers. 4) There’s still no downtime indicator on their website.

unknownhad··on My Personal LLM
I recently stumbled upon Cloudflare's newly launched AI workers and decided to give it a whirl. To my astonishment, setting up a personal LLM model was a breeze. It took me a mere 2 minutes; the entire process from sign-up to running your personal LLM shouldn’t take more than 5 minutes.

The process was incredibly streamlined, requiring just three clicks to have my personal LLM up and running. It is hosted over here for anyone interested to validate the ease and speed of the setup: https://llm.himanshuanand.com/.

Cloudflare’s AI workers seem to have broken down barriers.

Check out Cloudflare’s official blog post for more insights: https://blog.cloudflare.com/workers-ai/.

unknownhad··on LegallyBlocked: Discover Blocked Websites and mobile apps
Introducing LegallyBlocked: Discover Blocked Websites & Alternatives Worldwide, Powered by Cloudflare's Edge Network

Hey Hacker News community! We're Himanshu Anand (https://twitter.com/anand_himanshu) and Dolly Agarwal (https://uk.linkedin.com/in/dolly-agarwal-179406121), a husband and wife team passionate about making the internet a more open and accessible space for all.

A couple of weeks back, we were in the UAE when we discovered that WhatsApp was partially blocked. After searching the internet, we found out that the app was restricted by the UAE government. We realized that information about blocked websites and applications was scattered and there was no centralized source to find such details. This inspired us to create LegallyBlocked, a platform that helps you find out which websites and applications are blocked in countries around the world, and offers alternatives to keep you connected!

Our application is built entirely on Cloudflare's technology stack, leveraging the power of Cloudflare Pages, Workers, and D1 to provide a lightning-fast, serverless experience. Thanks to the edge network deployment, our service is not only fast, but also scalable and reliable.

Key Features:

Backend written in Node.js, hosted on Cloudflare Workers for seamless serverless functionality Database powered by Cloudflare D1, ensuring optimal data storage and retrieval Static frontend hosted on Cloudflare Pages for a blazing fast user experience Search functionality based on country name and application name

We're committed to keeping our database up-to-date, but we need your help to make it even better. We encourage you to share feedback, report any discrepancies, or suggest improvements by emailing us at contact@legallyblocked.website. Your input will help us refine our platform and ensure we're providing the most accurate and comprehensive data possible.

In the future, we plan to expand our offerings by providing suggestions for alternative websites and applications that can be used in a given location, ensuring that you always have options even when your preferred service is unavailable.

Stay updated on the latest LegallyBlocked developments by following us on Twitter: https://twitter.com/blocked21250

We'd love to see this project reach the front page of Hacker News and hear your thoughts on LegallyBlocked. Let's start a conversation in the comments, and don't hesitate to reach out to us with any questions or suggestions. Together, we can create a powerful resource for the internet community.

Check out LegallyBlocked now: http://legallyblocked.website/

unknownhad··on Ask HN: How chat GPT is/will impact you?
That's a good use case, as far as I have used chat GPT I can see something like this happening in near future. Though 911 is one such use case where it is really easy to misinterpret the situation by something like AI. Not sure how true is this situation but I think it would be hard for AI to judge the situation in such cases.

https://www.quora.com/Can-you-actually-call-emergency-servic...

unknownhad··on Ask HN: How chat GPT is/will impact you?
My apologies for not writing this clear enough : "What do you think about chat GPT and how do you think it will transform your future?"

Essentially translates to : (Without AI ATM :) ) HN thoughts about chat GPT and how they think it can impact their industry/rule/life.

unknownhad··on Tracking UK strikes using Cloudflare and ChatGPT
Track UK strikes using chatGPT and Cloudflare workers.

Created this fun project on my time off from work.

Code and how-to: https://github.com/unknownhad/UkStrikeCalendar

unknownhad··on Show HN: Minio – S3 Compatible Object Storage
Wow this looks interesting. Nice job team minio
unknownhad··on How to Really Complete a project?
I am glad you asked,

I am not an electronics guy, so for every new I have to buy it myself, sometimes it is ok for small projects, but in the long run it is not that easy.

For example, I bought Kinect then I have to buy Arduino boards, then Rasberrypi the whole electronics kit and all these things are very small but after that I felt like I needed to test Google glass, but that was too costly that I can afford the same thing with 3D printer too so I tried to build one for myself. This might Sound like few not so costly things, but when they all add up I am all over with my funds, Last thing is travelling after development of some prototyping to get the subject's view for that. All these things do delays the project and in most of the cases the project became dead.

unknownhad··on [dead]
Some logos are like "Kill Me Now, Please"
unknownhad··on [dead]
Page not found :-S
unknownhad··on Ask HN: who can i hire to hack my platform
Hey, I think I can help you. PM me off list. @anand_himanshu