logoalt Hacker News

Tiberiumyesterday at 3:47 PM2 repliesview on HN

Are they all actually 0-day? I think a lot of them are from disclosed CVEs/code that were already fixed upstream. It often seems like the term "0-day" has lost most of its meaning today and people often use it to refer to any exploits.


Replies

tempest_yesterday at 4:03 PM

Repo claims

> A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.

Which is roughly the definition of zero day. Whether the contents of the repo reflect the above claim is something else entirely.

show 1 reply
pooploop64yesterday at 5:40 PM

RCE has no meaning either in these situations. The "remote" part is usually an ssh root session if it means anything at all.