Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Backing exploit PoCs out of patches, commit messages, and random overheard or over-read sentences is a practice as old as vulnerability research

True, but it used to take days or weeks of research, testing, and RE to get those PoCs.

Today the entire chain - reading commits, RE patch binaries, building exploit, scripting exploit scan, $profit - can be fully automated and happen in minutes or hours.

 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: