Skip to content

Optimize SchieldBreak to work in windows 10 - #4

Open
HackingRepo wants to merge 1 commit into
MSNightmare:mainfrom
HackingRepo:patch-1
Open

Optimize SchieldBreak to work in windows 10#4
HackingRepo wants to merge 1 commit into
MSNightmare:mainfrom
HackingRepo:patch-1

Conversation

@HackingRepo

Copy link
Copy Markdown

Hi, @MSNightmare

Windows 10 not supported but yeah, we improved the exoloit for windows 10 too do'nt worry, means will work in all windows versions

Hi, @MSNightmare Windows 10 not supported but yeah, we improved the exoloit for windows 10 too do'nt worry, means will work in all windows versions
@bytecategory

Copy link
Copy Markdown

Hi, @MSNightmare

Windows 10 not supported but yeah, we improved the exoloit for windows 10 too do'nt worry, means will work in all windows versions

That’s a nice change; I suggest testing it on Mars before bringing it back to Earth for pull.

@MSNightmare

Copy link
Copy Markdown
Owner

I'm catching a space shuttle to Mars next week, if this works there I'll push it.

@AkechiShiro

Copy link
Copy Markdown

Just my 2 cent, guys I think for this PR it's best to use the Moon as a QA env, then test on Mars for production use case.

Comment threadShieldBreak.cpp
#define ROWS 5
#define COLS 5

int main() {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice joke?

@HackingRepo

Copy link
Copy Markdown
Author

@MSNightmare can you stop dropping exploits, please, can you apoligze to microsoft or report them to a coordinator for coordinate with them for the next zero days

@HackingRepo

Copy link
Copy Markdown
Author

@MSNightmare many exploits are heavily exploited by threat actors, like SchieldBreak there was no patch at all, you putting users at risk can you apoligze to microsoft, if you report further findings to a coordinator and then the coordinator will coordinate with microsoft patch

@MSNightmare

Copy link
Copy Markdown
Owner

@HackingRepo Why won't Microsoft just patch those exploits if they are exploited by threat actors ? Are they just stupid ?

@Salah-Code-Lab

Copy link
Copy Markdown

@HackingRepo Why won't Microsoft just patch those exploits if they are exploited by threat actors ? Are they just stupid ?

No they do patch them but because you deploy your exploits right after a Patch Tuesday you maximize the time of the Vulnerability being Non-Terminated

and that time is abused by threat actors
that time that is abused by threat actors maximizes the time of bystanders getting hit basically
which i stated once is not good
second
You're a degenerate MSN

@AkechiShiro

AkechiShiro commented Aug 14, 2026

Copy link
Copy Markdown

Gotta love people defending Microsoft, but if this is critical they should deal with it, threat actors don't wait for Patch Tuesday to start using 0 days.

@MSNightmare at least shows everyone that Microsoft Windows 11 is insecure and publishes the proof for everyone to see and test.

EDRs/SIEM agents could probably attempt detection and block this behavior. (I doubt however that EDRs can run along Defender but I've seen it happen already due to probable some misconfiguration or bug).

Blue team could run this in a controlled lab to check for specific detection logs/forensic clues.

Finally, what if this 0 day was already in the hands of private threat actors and @MSNightmare found it by himself through pure technical skill and just burned it for free by publishing it, no matter how I look at this, this repository improves security awareness.

I do get that a coordinated report is better but Microsoft has been treating previous work of @MSNightmare pretty poorly until they deleted his account for vulnerability report. I dont think he should bother with MSRP again. Given what happened.

That Microsoft isn't patching this until the next Patch Tuesday => shows Microsoft doesn't have the means or will to patch it with a hotpatch, shows how much they care about their customer security.

@Salah-Code-Lab

Salah-Code-Lab commented Aug 14, 2026

Copy link
Copy Markdown

@AkechiShiro
no one is Dickriding for Microsoft
no one is glazing
Windows 11 is insecure but All Operating systems are insecure in their own way
second

Finally, what if this 0 day was already in the hands of private threat actors and @MSNightmare found it by himself through pure technical skill and just burned it for free by publishing it, no matter how I look at this, this repository improves security awareness.

Correct no one is denying his skills he is good but that doesn't mean that he should publish it and let threat actors use it just because of a Personal Feud if you see that he has the right to do that then you are Delusional
Hurting bystanders just because of something personal ?
what did they do ?
its like the factory denying a raise for someone
but because they denied it he just went in and nuked every single thing that makes the factory even work

that shit is personal and because you nuked the factory i am working in you did cut my way of making money

the same way it translates here
He has something personal with Microsoft
Instead of keeping it with himself only
he decided to release exploits that can be abused by threat actors
threat actors: Wipe, Encrypt, Extort you out of your money
is that what you want framed as research ?
didn't think so

Third

That Microsoft isn't patching this until the next Patch Tuesday => shows Microsoft doesn't have the means or will to patch it with a hotpatch, shows how much they care about their customer security.

Hot patching is a Terrible idea
Not because that it isn't coordinated Hot patching means speed and speed makes issues
these issues we aren't talking like basic issues we are talking the potential of
BSODS
Another LPE
Another Attack vector exposed
etc etc

now Engineers do make mistakes like how they didn't patch RoguePlanet correctly
But that is normal

When Dave Cutler did work on the NT Kernel and was released later
it was full of vulnerabilities and LPEs that is completely normal
Does it mean that he is stupid ? does it mean that he is a bad engineer ? Fuck no

so instead of saying
"Computer are full of assumption, acquiring knowledge of those is hard but necessary in security"
Know that when you reply and look at what the titans achieved before you criticize because they know better than me and better than you

when you attempt to criticize you'd attempt to criticize in a valid way

And not This way

Blue team could run this in a controlled lab to check for specific detection logs/forensic clues.
Finally, what if this 0 day was already in the hands of private threat actors and @MSNightmare found it by himself through
pure technical skill and just burned it for free by publishing it, no matter how I look at this, this repository improves security
awareness.
I do get that a coordinated report is better but Microsoft has been treating previous work of @MSNightmare pretty poorly
until they deleted his account for vulnerability report. I dont think he should bother with MSRP again. Given what happened.
That Microsoft isn't patching this until the next Patch Tuesday => shows Microsoft doesn't have the means or will to patch it > with a hotpatch, shows how much they care about their customer security.

PLUS your bio
Computer are full of assumption, acquiring knowledge of those is hard but necessary in security
If you did understand what you said, and what you meant you wouldn't had said this Bullshit

@AkechiShiro

Copy link
Copy Markdown

I stand by my point, I understand your argument, but listen, we wouldn't have been arguing had MSRP done its job properly.

Cultural change is needed, if that causes damage for customers, that's customers issues, they should raise their concern to Microsoft's way of treating 0 days researchers.

No one should be in support of a company actively closing cybersecurity researcher accounts when they report 0 days just to avoid paying them for their work, we can probably agree that's unfair.

If they keep doing it, you'll see more @MSNightmare than you ever want to, and arguing here isn't gonna change anything.

So keep working on your patch to fix ShieldBreak and apply for Microsoft Security Team, that way you can fix @MSNightmare 0 days as fast as he publishes them someday for sure.

@Salah-Code-Lab

Copy link
Copy Markdown

I stand by my point, I understand your argument, but listen, we wouldn't have been arguing had MSRP done its job properly.

Cultural change is needed, if that causes damage for customers, that's customers issues, they should raise their concern to Microsoft's way of treating 0 days researchers.

No one should be in support of a company actively closing cybersecurity researcher accounts when they report 0 days just to avoid paying them for their work, we can probably agree that's unfair.

If they keep doing it, you'll see more @MSNightmare than you ever want to, and arguing here isn't gonna change anything.

So keep working on your patch to fix ShieldBreak and apply for Microsoft Security Team, that way you can fix @MSNightmare 0 days as fast as he publishes them someday for sure.

i agree with some of your points but not all

Yes no one should be supporting a company that treats 0 day researchers badly i fully stand by that point
But what i don't stand for is
Publishing the 0 day for free open source Ready to compile (almost) when they treated you badly
what does that have to do with the bystanders ? if you ever studied Defense 101 and Defense Psychology you will see what i mean
its not about Microsoft it was never about Microsoft
it was always for these strangers that i would never know
"Customer Issues" ? what are you on about ?
if a Corperation took a Wrongful act
IS it MY PROBLEM ?
Is it the Civilians Problem ?
Is it the grandparent problem ?
is it Anyone's Problem ?
No then why would you go out of your way and deploy malware anyway ?

Arguing wont do any effect. You are Wrong
arguing exposes the individual infront of you and what it exposes is
That Individual manners
That Individual Motives
That Individual Knowledge

if you don't care about these then you'd never succeed
because with arguing there is ALWAYS knowledge transfer which is my main thing i am searching for
if you are never searching for knowledge if you are not making yourself understand it
if you are not going to push through
you will never learn
that is what i did once when i almost killed my self because of starvation just to learn this kernel this software
and i am a man of my word i never lied once

so what is your excuse next time ?
what is your motive in the reply next time ?
i don't know
by the time i know i wouldn't care about you anyway since you are already failing on multiple parts which you wont understand both ways

@AkechiShiro

Copy link
Copy Markdown

If a corporation is doing something bad, staying silent is not good IMO.

Finally, your main point stands, and I understand that researcher shouldn't do this AFAIK under optimal condition (where responsible disclosure works pretty well), but when responsible disclosure is not working for said researcher multiples times, he's not going to bother doing it more and more with a corporate company that deleted his own account for the responsible disclosure, that's all there is to it, you can open issues, argue with the researcher he's probably not gonna change his mind ever, that's what I meant when I said arguing is pointless here.

You don't need to argue here because you're not going to change @MSNightmare's mind or stance on this matter.

Only thing that could help is MSRP/MS adressing this publicly or privately by reaching out to @MSNightmare and discussing how they could rebuild the bridge of trust that was burned by their own hands.

@Salah-Code-Lab

Copy link
Copy Markdown

If a corporation is doing something bad, staying silent is not good IMO.

Finally, your main point stands, and I understand that researcher shouldn't do this AFAIK under optimal condition (where responsible disclosure works pretty well), but when responsible disclosure is not working for said researcher multiples times, he's not going to bother doing it more and more with a corporate company that deleted his own account for the responsible disclosure, that's all there is to it, you can open issues, argue with the researcher he's probably not gonna change his mind ever, that's what I meant when I said arguing is pointless here.

You don't need to argue here because you're not going to change @MSNightmare's mind or stance on this matter.

Only thing that could help is MSRP/MS adressing this publicly or privately by reaching out to @MSNightmare and discussing how they could rebuild the bridge of trust that was burned by their own hands.

if he never stops i would never stop until i am dead or he is dead
or i ran out of solutions or he ran out of solutions

Your Opinion would never stand because they never stayed silent anyway defender already does detect the signature of it anyway

second
If something doesn't work for you you unleash it against us ?
AND MAXIMIZE ITS TIME ?
again Wrong

he'd never change his mind
and i'd never change my mind i would be always the first one to ATTEMPT notice ATTEMPT
to mitigate

Build Trust ?
To him Trust is basically like a cup made out of glass
when it shatters it just shatters

the only problem of what he is doing is just
The Disclosure at the Worst time for us Best time for attackers

and
the Disclosure of it for free open source

I Am not saying that Microsoft was never wrong
but Neither is MSN MSN is even deeper in the wrong
and i would be waiting for you in a day where he;d pay for what he had done

so whatever what you say next is not going to change anything anyway

i am Ending it Here say whatever what you want to say
its not going to change my or his plans

I am waiting to see what is next MSN...

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@HackingRepo@bytecategory@MSNightmare@AkechiShiro@Salah-Code-Lab@Tower450