View Single Post
Old 01-17-2012, 07:40 PM   #103
geekmaster
Carpe diem, c'est la vie.
geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.
 
geekmaster's Avatar
 
Posts: 6,433
Karma: 10773670
Join Date: Nov 2011
Location: Multiverse 6627A
Device: K1 to PW3
Quote:
Originally Posted by yifanlu View Post
Calling someone a troll is like calling someone a racist. The term is overused so much it loses it's intended meaning and becomes a generic insult. Anything that uses "the unintended expanding of absolute paths by default when extracting tar files on the kindle" is what I call "the tar bug" and as I've said amazon will MOST LIKELY but not DEFINEATLY fix all use of this bug when they release a patch, so we should focus on finding new bugs instead of more uses for this one. Let ixtab have the credit for this one and we should all move on to looking for new bugs.

Now if I am wrong and your exploit makes no use of any variation of the tar bug, I sincerely apologize and hold my peace. Otherwise, I stand by my statement that we only have one exploit right now.
You are welcome to your narrow viewpoint and narrow definition of the word, if it suits your purpose. I have much larger goals in life, which require broader definitions that more closely match what the dictionaries have to say. To each his own...

I have used the tar bug in the past, and I have found long-repaired security loopholes show up all over again in code rewrites, which is why I suggested to you when we were discussing UTF-8 shellcodes to use your stack smash, before I had my own kindle Touch to test with, that perhaps you should test the tar root path bug "just in case". I took your word for it when you told me "that was fixed long ago". By the time I got my Touch, you had already released you MP3 exploit, so no need to test it then. When you said in the IRC channel right after ixtab announced his tar bug discovery and I mentioned our previous discussion, you said "but we BOTH agreed that it could not work". Actually, I learned long ago to never agree to anything without reading the fine print and testing everything myself. Because I had not Touch to test with during our previous discussion, it is absurd to claim that I could have agreed to such a thing. This is a hard rule that I rarely violate.

I am sorry about the Troll thing, but it seems that when I ask legitimate questions you have no time to answer me, but you are quick to challenge things that I post. This is irksome because I come from a different time than you, and word meanings evolve over time, and my experience gives me a much broader viewpoint than yours, which affects which definitions of technical jargon I choose to use. To me, arguing word definitions without supporting evidence or technical merit is akin to "trolling". Regarding word meanings, how can "troll" be akin to "racist" as you claimed above? Which ethnicity descended from Trolls? I have read many thousands of books, and I am not aware of any...
geekmaster is offline   Reply With Quote