Skip to content

Source

Anil Madhavapeddy

1 item

Notes and weekly logs by Anil Madhavapeddy, a Cambridge computer science professor and OCaml maintainer. He writes from his own servers and projects, so a claim here is the first place it appears rather than a retelling of someone else's.

anil.recoil.org

OCAML, PATH HANDLING10 minfrom a public fix to a working exploit
Agentsstrong signal

A rumor of a bug is now enough for an agent to write the exploit

Anil Madhavapeddy fixed a path traversal issue in an OCaml library and opened the patch in public, the way maintainers have done for years. About 10 minutes later his own web server was logging probes for that exact pattern. His own agent had already built a working exploit from nothing but a rough description of where to look. The embargo model assumes that keeping the details quiet buys time, and that assumption has stopped holding.

Anil Madhavapeddyverified