-
usagirabbit
hello! i was wondering what the hackerone bounties are, the reporting document links to a old page thats now a dead link which has the bounty pool amount (1500 xmr in apr 2025 was the last snapshot, wow) and i was wondering if there was like a new forum or anything for it
-
usagirabbit
-
usagirabbit
luigi1111 i'd figure you'd know as your one of the security contacts :)
-
usagirabbit
anyone here?
-
br-m
<rottenwheel:unredacted.org> usagirabbit yeah, apparently...
-
luigi1111
The hackerone fund is more or less just case by case. A few xmr up to like 100+ depending on severity
-
usagirabbit
i see thanks for letting me know
-
usagirabbit
i reported a high severity :)
-
BoBeR182
usagirabbit: what did you find?
-
BoBeR182
high level?
-
BoBeR182
RCE? or protocol issue
-
usagirabbit
BoBeR182 im not too sure im supposed to disclose it, but its not a rce which would be critical :)
-
BoBeR182
is it remotely exploitable
-
usagirabbit
wdym
-
BoBeR182
I'll shutdown my node until a patch comes out
-
usagirabbit
oh noo
-
usagirabbit
its not that scary
-
usagirabbit
well
-
usagirabbit
it involves nodes yes
-
usagirabbit
but
-
usagirabbit
yeah
-
usagirabbit
im not gonna disclose more than that
-
BoBeR182
so shutdown my node or not?
-
usagirabbit
dont
-
usagirabbit
it took me a while to discover it lmao
-
usagirabbit
u should be sage
-
usagirabbit
safe*
-
BoBeR182
sounds like something an attacker would say
-
usagirabbit
LOL
-
usagirabbit
dont worry
-
BoBeR182
there's agencies working 24/8 to compromise xmr
-
usagirabbit
Im Totally Not State SponsoredTM
-
BoBeR182
if you as a single user figured it out...
-
usagirabbit
i submitted it to hackerone responsibly
-
usagirabbit
im not a threat actor i swear!1!!!!!11
-
usagirabbit
however i did use ai to look for potential weaknesses
-
usagirabbit
(disclosed on the report, dont worry!)
-
usagirabbit
so yeah
-
usagirabbit
i just got like gpt 5.4 to scrape the entire codebase and look for stuff that could be high/critical
-
usagirabbit
so far i havent found a critical yet, but only time will tell
-
BoBeR182
were you able to reproduce it independently
-
BoBeR182
or is it just theoretical
-
BoBeR182
and a hallucination?
-
usagirabbit
yes
-
usagirabbit
i reproduced it independently
-
BoBeR182
GPTslop has ruined many bug bounty programs
-
usagirabbit
LOL
-
usagirabbit
welp
-
BoBeR182
did you offer a patch to fix it+?
-
usagirabbit
yes
-
BoBeR182
that is awesome!
-
usagirabbit
well not really a patch
-
BoBeR182
well go make one
-
usagirabbit
i just told them what they could do to patch it
-
BoBeR182
that would actually help
-
BoBeR182
you should open the PR
-
usagirabbit
it has a PoC and everything too
-
usagirabbit
im not gonna open the pr cuz
-
usagirabbit
i dont want it exposed
-
usagirabbit
YET
-
usagirabbit
it could take down uh
-
usagirabbit
some nodes
-
usagirabbit
forcefully
-
BoBeR182
you can mark sensitive PRs
-
BoBeR182
those exist in github
-
usagirabbit
does it private it?
-
usagirabbit
ahh
-
BoBeR182
sounds like DoS
-
usagirabbit
dang it!
-
usagirabbit
ya figured it out LOL
-
BoBeR182
that could be used to deanonymize certain actors
-
BoBeR182
is it a memory corruption that can be DoS leading to RCE
-
usagirabbit
uuhhhh
-
usagirabbit
no
-
usagirabbit
no code injection
-
usagirabbit
the closest thing i can get into about it thats somewhat nontechnical is a ram leak
-
usagirabbit
a threat actor can crash likee
-
usagirabbit
a shit ton of nodes
-
usagirabbit
esp if they are state sponsored
-
usagirabbit
i think gpt 5.4 found another high/critical
-
usagirabbit
but its kinda weird
-
usagirabbit
its related to multisig
-
usagirabbit
the first bug i found on monero is exactly CVSS 3 score 7.5!
-
br-m
<ufo808:matrix.org> There was multisig issue before
-
br-m
<ufo808:matrix.org> It was fixed
-
usagirabbit
ahh
-
usagirabbit
when?
-
usagirabbit
yesterday?
-
br-m
<ufo808:matrix.org> And I think I already saw some monero DoS on hackerone before, like multiple of them
-
br-m
<ufo808:matrix.org> usagirabbit: Years ago
-
usagirabbit
oh
-
usagirabbit
years ago?
-
usagirabbit
no these are recent
-
usagirabbit
unpatched
-
usagirabbit
ive tested them
-
br-m
<ufo808:matrix.org> @ufo808:matrix.org: But maybe I’m trippin balls
-
usagirabbit
no ur right
-
usagirabbit
i have the latest repo
-
usagirabbit
for monero
-
usagirabbit
from the github
-
usagirabbit
it works
-
br-m
<ufo808:matrix.org> Interesting
-
usagirabbit
a state actor can like
-
usagirabbit
nuke a shit ton of nodes
-
usagirabbit
if they are in the right place
-
usagirabbit
so if they do a sustained attack of this
-
usagirabbit
it can be basically wraps
-
usagirabbit
soo
-
usagirabbit
and i found another dos
-
usagirabbit
omfl
-
br-m
<ufo808:matrix.org> Can you nuke spy nodes then? Thanks
-
usagirabbit
i cant uhh
-
usagirabbit
select them
-
usagirabbit
its kinda indiscriminate
-
usagirabbit
LOL
-
usagirabbit
uhm
-
usagirabbit
i think i found another one
-
usagirabbit
Rough CVSS: 8.6 High
-
usagirabbit
ih wait
-
usagirabbit
i found the one i already reported
-
usagirabbit
LOOOOOOOOL
-
usagirabbit
profound stupidity
-
plowsof
the good thing about spamming this chat is that you would have disclosed the vuln already and not eligible for reward
-
usagirabbit
?
-
usagirabbit
wat
-
usagirabbit
ohh
-
usagirabbit
about the one im looking for
-
usagirabbit
LOL
-
usagirabbit
nah
-
usagirabbit
if i found one
-
usagirabbit
ill just say ill found one
-
usagirabbit
i wont go into detail abt it if its that bad
-
plowsof
your report is "gpt 5.4 to scrape the entire codebase and look for stuff that could be high/critical"
-
plowsof
lol
-
usagirabbit
😭😭
-
usagirabbit
i mean
-
usagirabbit
ur not wrong
-
plowsof
you're welcome
-
usagirabbit
broo
-
usagirabbit
im using copilot write
-
usagirabbit
dude
-
usagirabbit
im genuinely fried
-
usagirabbit
i just wrote right as write
-
plowsof
yeah stop spamming
-
usagirabbit
its 12 am😭💔
-
usagirabbit
gpt 5.4 keeps stopping
-
usagirabbit
#OPENAIISLYINGABOUTMULTIHOURCODEXRUNS
-
usagirabbit
hes back
-
usagirabbit
the nsa killed him and he ressurected
-
BoBeR182
did you DoS me
-
usagirabbit
yes i did bober
-
usagirabbit
i work for the nsa
-
usagirabbit
#rced #itswrapsforyou
-
usagirabbit
(joke obviously)
-
Guest17
hello
-
br-m
<kiersten5821:matrix.org> dos is high?
-
br-m
<ravfx:xmr.mx> dos=high,umb
-
br-m
<kiersten5821:matrix.org> umb meaning?
-
br-m
<ravfx:xmr.mx> Upper High Memory
-
br-m
<ravfx:xmr.mx> oh non, Upper Memory Block... I think
-
br-m
<kiersten5821:matrix.org> and what does that mean
-
br-m
<ravfx:xmr.mx> You too young
-
br-m
<kiersten5821:matrix.org> feel like you're trolling me
-
br-m
<kiersten5821:matrix.org> but i dont get it
-
br-m
<kiersten5821:matrix.org> 😔
-
br-m
<ravfx:xmr.mx> Back in the days, one would ideally want to load dos in HIGH and the left over in the UMB, that and as much drivers as possible.
-
br-m
<ravfx:xmr.mx> The UMB where block of memory that could be freed Between A0000-FFFFF, usually between C8000-EFFFF.
-
br-m
<ravfx:xmr.mx> Doing so would free conventional memory (the first 640K). So DOS games that need a lot of it would have enough memory
-
br-m
<ravfx:xmr.mx> Things like QEMM would allow remapping the BIOS out of F0000-FFFFF, adding an extra 64KB
-
waks
On my node I'm getting error "Transaction not found in pool" every minute or so. Is that cause for concern?
-
br-m
<ofrnxmr:xmr.mx> Are you mining?
-
waks
Yeah, with p2pool connected to my node
-
br-m
<ofrnxmr:xmr.mx> Other p2pool peers are mining blocks that have txs that youe node doesnt have
-
br-m
<ofrnxmr:xmr.mx> Your node tries to broadcast them hut shows that error because your node is missing txs that are in the submitted block
-
waks
What would cause that happen? Is that normal? Am I not syncing fast enough or something?
-
br-m
<ofrnxmr:xmr.mx> Selfish mining of txs
-
waks
So it's other nodes that are causing that to appear?
-
br-m
<omurad:matrix.org> Yes
-
br-m
<ofrnxmr:xmr.mx> Its p2pool peer's node that are causing it to appear*
-
br-m
<ofrnxmr:xmr.mx> Not nodes that your node is directly connected to