Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Directory filtering needs to be fixed, one weird filename or symlink will make it BSOD.

    SSDT should probably have a lock. The chance of a race is ~low (higher under heavy sustained workloads) but it's too important to leave to chance.

    I'd probably do a rebuild of the directory lists in a separate buffer instead of working in place to avoid alignment fuckups.

    Yes I used LLMs, just like I did for all of the other vulns I've found or refined. As you can see from the source, this shit is tedious as hell. Doesn't change the value of knowing what to look/ask for

  • Thanks for posting! ~15k lines of code, a lot to poke around in. I was working on a Siemens S7 PLC project with a WINCC HMI for a power plant as I listened to the audio book[2] based on this ~12 years ago, entirely changed how I viewed critical infrastructure. One quote from the book that stuck with me was how you can only use a cyber weapon once at full potential, as it’ll either get patched and/or everyone can reverse engineer it to use.

    For those not familiar with Stuxnet, it’s a discovered cyber-weapon from 2010 which “reportedly destroyed almost one-fifth of Iran's nuclear centrifuges. ” and “ neither the United States nor Israel has openly admitted responsibility” but likely were the developers [1]

    [1-Wikipedia Entry](https://en.wikipedia.org/wiki/Stuxnet)

    [2-“Countdown To Zero Day” book if you liked the Wikipedia entry](https://www.audible.com/pd/Countdown-to-Zero-Day-Audiobook/B...)

    [3-“Zero Days” movie](https://www.imdb.com/title/tt5446858/)

Stuxnet – A reconstructed source code of the infamous cyber-weapon · Birbla