D•Scribe
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
YoorWeb@lemmy.world to Programmer Humor@lemmy.ml · 1 year ago

Oops, wrong person.

lemmy.world

message-square
31
fedilink
833

Oops, wrong person.

lemmy.world

YoorWeb@lemmy.world to Programmer Humor@lemmy.ml · 1 year ago
message-square
31
fedilink
alert-triangle
You must log in or register to comment.
  • SzethFriendOfNimi@lemmy.world
    link
    fedilink
    arrow-up
    193
    ·
    1 year ago

    Remember, always validate your inputs.

    • draughtcyclist@programming.dev
      link
      fedilink
      English
      arrow-up
      207
      arrow-down
      1
      ·
      1 year ago

      Little Bobby Tables we call him.

      • azimir@lemmy.ml
        link
        fedilink
        arrow-up
        89
        ·
        1 year ago

        Such great Exploits of a Mom: https://xkcd.com/327/

        • GombeenSysadmin@feddit.uk
          link
          fedilink
          arrow-up
          42
          ·
          1 year ago

          They had to change the law in the uk around naming companies!

          • VikingHippie@lemmy.wtf
            link
            fedilink
            arrow-up
            17
            ·
            1 year ago

            Company SC656788 is still named ROBERT’); DROP TABLE STUDENTS; LIMITED

            Beautiful! Whatever they’re selling, I’m buying!

        • MightyGalhupo@lemmy.world
          link
          fedilink
          arrow-up
          14
          ·
          1 year ago

          I still can’t believe that comic is 15 years old now

  • titter@lemmy.world
    link
    fedilink
    arrow-up
    155
    arrow-down
    1
    ·
    edit-2
    1 year ago

    This is awesome. We need more of this to help us fight the coming war

  • Sharpiemarker@startrek.website
    link
    fedilink
    arrow-up
    128
    ·
    1 year ago

    Whoops, the mask slipped and we all saw the bot behind it.

    • titter@lemmy.world
      link
      fedilink
      arrow-up
      156
      ·
      1 year ago

      Mask slipped? The bot saw a person speak code and was like l, rips off mask Comrade!

      • Sharpiemarker@startrek.website
        link
        fedilink
        arrow-up
        31
        ·
        1 year ago

        Lol good point.

        • Decoy321@lemmy.world
          link
          fedilink
          arrow-up
          21
          ·
          1 year ago

          And then they were best friends. <3

          • Sharpiemarker@startrek.website
            link
            fedilink
            arrow-up
            13
            ·
            1 year ago

            🤜🤛

    • Aliyss@programming.dev
      link
      fedilink
      arrow-up
      3
      ·
      1 year ago

      I think there’s a second mask. Who sends oops wrong person in the same text message?

  • s12@sopuli.xyz
    link
    fedilink
    arrow-up
    91
    ·
    1 year ago

    Thought that seemed really cute. Nice way to try to break through social anxiety.

    Then I saw that it started as a wrong number message. Then I realised…

    Damn scam bots!

  • chicken@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    66
    ·
    1 year ago

    Modern version of this will be ChatGPT jailbreak messages

  • PeriodicallyPedantic@lemmy.ca
    link
    fedilink
    arrow-up
    56
    ·
    1 year ago

    In the future, bots are going to get so annoyed with people pretending to be bots when they just want to talk to other bots!

  • tourist@lemmy.world
    link
    fedilink
    arrow-up
    51
    ·
    1 year ago

    why bother with the variations?

    think they’re hoping to knock the same victim more than once?

    messed up

    • Deebster@programming.dev
      link
      fedilink
      arrow-up
      85
      ·
      1 year ago

      Maybe it’s an attempt to evade automated systems that check for spam.

    • PM_Your_Nudes_Please@lemmy.world
      link
      fedilink
      arrow-up
      66
      ·
      1 year ago

      Probably a basic way to evade spam detection. If you start sending the exact same message to 500 people, most chat services will shut that shit down in an instant. But if you send unique messages, it makes you look more like a real person, and the chat system may let it slide.

      • Adalast@lemmy.world
        link
        fedilink
        arrow-up
        9
        ·
        1 year ago

        What’s bad is that modern spam detection can employ semantic algorithms so it would still catch all of them as the I’m as message. The use of synonyms in the optionals is a huge vulnerability in the scam.

        • Ephera@lemmy.ml
          link
          fedilink
          arrow-up
          11
          ·
          1 year ago

          Well, it does not appear to be a terribly sophisticated system to begin with…

          • Adalast@lemmy.world
            link
            fedilink
            arrow-up
            4
            ·
            1 year ago

            Touché

    • xmunk@sh.itjust.works
      link
      fedilink
      arrow-up
      30
      ·
      1 year ago

      So that their fixed script isn’t so predictable that we can just nuke them by looking for identical conversations.

    • Lmaydev@programming.dev
      link
      fedilink
      arrow-up
      5
      ·
      1 year ago

      I would say more likely to get around bot protection.

    • Jknaraa@lemmy.ml
      link
      fedilink
      arrow-up
      6
      arrow-down
      1
      ·
      1 year ago

      Could be to match the style of the target, to try and make the conversation feel more natural for them.

  • MyFeetOwnMySoul@lemmy.ca
    link
    fedilink
    arrow-up
    44
    ·
    1 year ago

    How does this exploit work? I understand that inputs were not sanitized, but what did the injected code do?

    • powerofm@lemmy.ca
      link
      fedilink
      arrow-up
      69
      ·
      1 year ago

      My guess would be the response text is passed through a rudimentary templating engine that looks for { and }. Somehow it must be processing the whole chat history. The templater fails at the unexpected braces in the code block and then just gives up (probably a try-catch ignores the error and sends the message anyway).

      • mumblerfish@lemmy.world
        link
        fedilink
        arrow-up
        38
        ·
        1 year ago

        So the attack would just be a } then?

    • kromem@lemmy.world
      link
      fedilink
      English
      arrow-up
      47
      ·
      edit-2
      1 year ago

      I don’t think the code is doing anything, it looks like it might be the brackets.

      That effectively the spam script has like a greedy template matcher that is trying to template the user message with the brackets and either (a) chokes on an exception so that the rest is spit out with no templating processor, or (b) completes so that it doesn’t apply templating to the other side of the conversation.

      So { a :'b'} might work instead.

  • grendel@lemmy.world
    link
    fedilink
    arrow-up
    33
    ·
    1 year ago

    deleted by creator

    • YoorWeb@lemmy.worldOP
      link
      fedilink
      arrow-up
      16
      ·
      1 year ago

      Pretty damn old.

  • Joe_0237@lemmy.ml
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    This is the best thing ive seen this week!

Programmer Humor@lemmy.ml

programmerhumor@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programmerhumor@lemmy.ml

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

  • Posts must be relevant to programming, programmers, or computer science.
  • No NSFW content.
  • Jokes must be in good taste. No hate speech, bigotry, etc.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 147 users / day
  • 533 users / week
  • 1.76K users / month
  • 10.5K users / 6 months
  • 8 local subscribers
  • 35.6K subscribers
  • 1.42K Posts
  • 21.2K Comments
  • Modlog
  • mods:
  • AgreeableLandscape@lemmy.ml
  • cat_programmer@lemmy.ml
  • UI: unknown version
  • BE: 0.19.9
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org