NDevTK

338 posts

NDevTK banner
NDevTK

NDevTK

@ndevtk

Still pretending to be a security researcher.

انضم Eylül 2021
112 يتبع1.2K المتابعون
NDevTK
NDevTK@ndevtk·
@Tur24Tur Strange because could just reuse the same chat session maybe it allows for easier moderating. If true that's an very invasive setup.
English
0
0
0
17
Tur.js
Tur.js@Tur24Tur·
@ndevtk I have confirmed this across three chats once i receive approval i can proceed
English
1
0
2
70
Tur.js
Tur.js@Tur24Tur·
Many people messaged me that the solution I explained worked for them, but they still get the same error again, so here is what I found: The approval email you receive is tied only to the specific chat where the token was generated After filling out the form and getting approved, you can continue working in that same chat but this approval does not apply to new chats. From what I’ve seen, even after getting 4–5 approvals, the error still appears in future sessions, but for the approved session, I can continue working without issues. I think they may introduce a trusted cybersecurity program soon similar to the one announced by @OpenAI, where things will be more managed instead of submitting an application every time. #Anthropic #Claude #ClaudeCode
Tur.js tweet media
Tur.js@Tur24Tur

Finally @AnthropicAI approved my cyber use case in just 2h 25min upon submission For people getting rejected provide your profile: @Hacker0x01, @Bugcrowd, and a project with one of your github repos. Much appreciated, Anthropic team 🤎 #InfoSec #Anthropic #BugBounty

English
7
3
27
5.8K
NDevTK
NDevTK@ndevtk·
@0x464D @S1r1u5_ Security research does require exploit dev otherwise AI could just make it up. I got approved for a use case wonder if having a duck background image helps.
English
0
0
1
110
Florian Magin
Florian Magin@0x464D·
@S1r1u5_ Can you share what kind of task you are asking it to do? I got my request for less safeguards in Claude approved, but I might have not asked for enough to do straight up exploit dev
English
1
0
2
908
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
Thought of using codex and it doesn't even budge. How are you bypassing the guardrails on codex? we applied to cyber thing, got no response.
s1r1us (mohan) tweet media
s1r1us (mohan)@S1r1u5_

hi @AnthropicAI, our request to remove claude safeguards was denied. we would really appreciate a reconsider, we're not just any company. mythos access would be great too 😉 check the thread for our work securing AI & OSS products like Atlas, Antigravity, Windsurf 🧵👇

English
6
1
36
20.9K
NDevTK
NDevTK@ndevtk·
ndev.tk/htmldom/ got more complicated it now converts unsafe sinks to safe DOM API calls and traces taint from sources to sinks across files, functions, and control flow. Maybe can reuse code in extension :)
English
0
0
10
573
NDevTK
NDevTK@ndevtk·
@J0R1AN Nice I didn't spend much effort on making it look nice without JavaScript analysis the code required is a lot less.
English
0
0
0
92
Jorian
Jorian@J0R1AN·
@ndevtk I made a similar thing once when I was working on some docx generation, with a slightly different stylistic choice of using scopes to clearly show nesting: gist.github.com/JorianWoltjer/…
English
1
0
3
347
NDevTK
NDevTK@ndevtk·
I made a HTML/CSS to DOM API converter! ndev.tk/htmldom/ this project doesn't use Babel JS because I couldn't be bothered.
English
1
0
7
830
NDevTK
NDevTK@ndevtk·
The first version of APIClient has been released chromewebstore.google.com/detail/api-sec… it supports API learning with key tracking based on usage and Google/Swagger discovery documents plus XSS finding also replacement for postLogger extension. It's not perfect, create GitHub issues :)
English
0
3
14
1.3K
NDevTK
NDevTK@ndevtk·
github.com/NDevTK/APIClie… has been recovered does both API learning and XSS finding it's not perfect but I'm starting to get over it. Hopefully this time I will release and not delete it.
English
0
1
17
858
NDevTK
NDevTK@ndevtk·
Taint analyser is replaced with CodeQL Chrome github.com/NDevTK/codeql-… because trying to get AI to build a code graph then integrate it with an SMT was annoying. I asked something basic like trace the internals of jquery it made a fake version.
English
0
1
6
469
NDevTK
NDevTK@ndevtk·
@S1r1u5_ Arguably they could have been compensating with features for having a bad model but yeah the model is good not perfect but better than Gemini.
English
0
0
1
135
NDevTK
NDevTK@ndevtk·
@randomunkn36565 There's a share button for browsable intents but for the other intent types it would need ADB exports or its own deeplink system that prefills the fields (preferred by me) crashes in large apps is a problem will hopefully get better with updates.
English
0
0
0
34
Rand0m_Unk0wn
Rand0m_Unk0wn@randomunkn36565·
@ndevtk Just wanted to say, the apps amazing! It just sometimes crashes when analysing huge apps, but rest, it's amazing, I have, one suggestion maybe add something that allows you to build a poc easily. This app made it really easy for me to get into android bug hunting
English
1
0
1
79
NDevTK
NDevTK@ndevtk·
DroidProbe is getting an API client that supports Swagger and Google discovery documents. Based on past experience with a Minecraft server hosting app it's a good target for security issues.
English
1
0
3
555
Sarmad Hassan
Sarmad Hassan@JubaBaghdad·
@a7mad__n1 @GoogleVRP based on the info above your issue on `T3b` since it is `Execute code on the client (C0)` it means they bounty is `$200` so why you said i got `$$$$` is it fake or what!!
English
3
0
1
321
NDevTK
NDevTK@ndevtk·
A no-code web-based GUI for Chromium MojoJS security research with automated binding generation. Tempted to add an AI chat bot. github.com/NDevTK/MojoGUI
English
0
0
3
584