03:27:13 hello! i was wondering what the hackerone bounties are, the reporting document links to a old page thats now a dead link which has the bounty pool amount (1500 xmr in apr 2025 was the last snapshot, wow) and i was wondering if there was like a new forum or anything for it 03:27:39 https://github.com/monero-project/meta/blob/master/VULNERABILITY_RESPONSE_PROCESS.md 03:28:19 luigi1111 i'd figure you'd know as your one of the security contacts :) 04:07:54 anyone here? 04:11:53 usagirabbit yeah, apparently... 04:14:49 The hackerone fund is more or less just case by case. A few xmr up to like 100+ depending on severity 04:16:43 i see thanks for letting me know 04:16:49 i reported a high severity :) 04:27:22 usagirabbit: what did you find? 04:27:26 high level? 04:27:33 RCE? or protocol issue 04:30:45 BoBeR182 im not too sure im supposed to disclose it, but its not a rce which would be critical :) 04:31:22 is it remotely exploitable 04:31:25 wdym 04:31:30 I'll shutdown my node until a patch comes out 04:31:35 oh noo 04:31:37 its not that scary 04:31:39 well 04:31:43 it involves nodes yes 04:31:44 but 04:31:45 yeah 04:31:50 im not gonna disclose more than that 04:31:55 so shutdown my node or not? 04:32:00 dont 04:32:05 it took me a while to discover it lmao 04:32:07 u should be sage 04:32:09 safe* 04:32:11 sounds like something an attacker would say 04:32:16 LOL 04:32:23 dont worry 04:32:26 there's agencies working 24/8 to compromise xmr 04:32:32 Im Totally Not State SponsoredTM 04:32:33 if you as a single user figured it out... 04:32:51 i submitted it to hackerone responsibly 04:32:59 im not a threat actor i swear!1!!!!!11 04:33:14 however i did use ai to look for potential weaknesses 04:33:21 (disclosed on the report, dont worry!) 04:33:26 so yeah 04:33:41 i just got like gpt 5.4 to scrape the entire codebase and look for stuff that could be high/critical 04:33:51 so far i havent found a critical yet, but only time will tell 04:33:55 were you able to reproduce it independently 04:34:00 or is it just theoretical 04:34:04 and a hallucination? 04:34:09 yes 04:34:14 i reproduced it independently 04:34:16 GPTslop has ruined many bug bounty programs 04:34:20 LOL 04:34:38 welp 04:34:41 did you offer a patch to fix it+? 04:34:43 yes 04:34:49 that is awesome! 04:34:59 well not really a patch 04:35:07 well go make one 04:35:08 i just told them what they could do to patch it 04:35:11 that would actually help 04:35:14 you should open the PR 04:35:16 it has a PoC and everything too 04:35:19 im not gonna open the pr cuz 04:35:24 i dont want it exposed 04:35:24 YET 04:35:27 it could take down uh 04:35:31 some nodes 04:35:34 forcefully 04:35:39 you can mark sensitive PRs 04:35:42 those exist in github 04:35:44 does it private it? 04:35:45 ahh 04:35:45 sounds like DoS 04:35:50 dang it! 04:35:52 ya figured it out LOL 04:36:06 that could be used to deanonymize certain actors 04:36:16 is it a memory corruption that can be DoS leading to RCE 04:36:26 uuhhhh 04:36:27 no 04:36:30 no code injection 04:37:01 the closest thing i can get into about it thats somewhat nontechnical is a ram leak 04:37:07 a threat actor can crash likee 04:37:09 a shit ton of nodes 04:37:13 esp if they are state sponsored 04:37:48 i think gpt 5.4 found another high/critical 04:38:20 but its kinda weird 04:38:38 its related to multisig 04:40:08 the first bug i found on monero is exactly CVSS 3 score 7.5! 04:53:25 There was multisig issue before 04:53:44 It was fixed 04:54:06 ahh 04:54:08 when? 04:54:14 yesterday? 04:54:20 And I think I already saw some monero DoS on hackerone before, like multiple of them 04:54:28 usagirabbit: Years ago 04:54:33 oh 04:54:36 years ago? 04:54:40 no these are recent 04:54:41 unpatched 04:54:44 ive tested them 04:54:49 @ufo808:matrix.org: But maybe I’m trippin balls 04:54:55 no ur right 04:55:03 i have the latest repo 04:55:06 for monero 04:55:07 from the github 04:55:09 it works 04:55:40 Interesting 04:55:51 a state actor can like 04:55:58 nuke a shit ton of nodes 04:56:03 if they are in the right place 04:56:08 so if they do a sustained attack of this 04:56:12 it can be basically wraps 04:56:13 soo 04:56:56 and i found another dos 04:56:57 omfl 04:57:41 Can you nuke spy nodes then? Thanks 04:57:48 i cant uhh 04:57:50 select them 04:57:53 its kinda indiscriminate 04:57:54 LOL 05:01:27 uhm 05:01:30 i think i found another one 05:01:32 Rough CVSS: 8.6 High 05:01:36 ih wait 05:01:43 i found the one i already reported 05:01:44 LOOOOOOOOL 05:01:49 profound stupidity 05:01:53 the good thing about spamming this chat is that you would have disclosed the vuln already and not eligible for reward 05:01:58 ? 05:01:59 wat 05:02:13 ohh 05:02:17 about the one im looking for 05:02:18 LOL 05:02:19 nah 05:02:21 if i found one 05:02:25 ill just say ill found one 05:02:34 i wont go into detail abt it if its that bad 05:02:40 your report is "gpt 5.4 to scrape the entire codebase and look for stuff that could be high/critical" 05:02:45 lol 05:02:53 😭😭 05:02:55 i mean 05:02:57 ur not wrong 05:05:19 you're welcome 05:07:59 broo 05:08:02 im using copilot write 05:08:10 dude 05:08:13 im genuinely fried 05:08:17 i just wrote right as write 05:08:23 yeah stop spamming 05:08:26 its 12 am😭💔 05:08:50 gpt 5.4 keeps stopping 05:08:58 #OPENAIISLYINGABOUTMULTIHOURCODEXRUNS 05:19:10 hes back 05:19:19 the nsa killed him and he ressurected 05:20:46 did you DoS me 05:21:00 yes i did bober 05:21:04 i work for the nsa 05:21:11 #rced #itswrapsforyou 05:21:24 (joke obviously) 05:42:36 hello 05:57:58 dos is high? 06:01:17 dos=high,umb 06:04:44 umb meaning? 06:05:42 Upper High Memory 06:05:51 oh non, Upper Memory Block... I think 06:08:12 and what does that mean 06:08:46 You too young 06:08:47 feel like you're trolling me 06:08:50 but i dont get it 06:09:10 😔 06:11:39 Back in the days, one would ideally want to load dos in HIGH and the left over in the UMB, that and as much drivers as possible. 06:11:39 The UMB where block of memory that could be freed Between A0000-FFFFF, usually between C8000-EFFFF. 06:11:39 Doing so would free conventional memory (the first 640K). So DOS games that need a lot of it would have enough memory 06:12:43 Things like QEMM would allow remapping the BIOS out of F0000-FFFFF, adding an extra 64KB 18:01:24 On my node I'm getting error "Transaction not found in pool" every minute or so. Is that cause for concern? 19:03:52 Are you mining? 19:21:06 Yeah, with p2pool connected to my node 19:28:56 Other p2pool peers are mining blocks that have txs that youe node doesnt have 19:29:34 Your node tries to broadcast them hut shows that error because your node is missing txs that are in the submitted block 19:37:42 What would cause that happen? Is that normal? Am I not syncing fast enough or something? 19:44:56 Selfish mining of txs 20:06:07 So it's other nodes that are causing that to appear? 20:30:56 Yes 20:58:57 Its p2pool peer's node that are causing it to appear* 20:59:17 Not nodes that your node is directly connected to