LiveOverflow ๐Ÿ”ด

9.3K posts

LiveOverflow ๐Ÿ”ด banner
LiveOverflow ๐Ÿ”ด

LiveOverflow ๐Ÿ”ด

@LiveOverflow

wannabe hacker... he/him ๐ŸŒฑ grow your hacking skills @hextreeio

Internet ๊ฐ€์ž…์ผ Mart 2015
1.3K ํŒ”๋กœ์ž‰158.7K ํŒ”๋กœ์›Œ
LiveOverflow ๐Ÿ”ด ๋ฆฌํŠธ์œ—ํ•จ
Lupin
Lupin@0xLupinยท
One label away from compromising a package with 78M weekly installs. We disclosed a full attack chain in Rollup, the bundler behind Vite, Nuxt, SvelteKit, Astro, and much of the modern web. A reviewed PR could still be force-pushed after labeling, turning a TOCTOU race into trusted CI execution, cache poisoning, and RCE in the release pipeline. Rollup fixed it promptly, huge respect to the maintainers ๐Ÿฅณ This is exactly why upstream CI/CD is part of your security boundary. Full technical write-up: landh.tech/blog/20260317-โ€ฆ
Lupin tweet media
English
3
16
116
10.5K
LiveOverflow ๐Ÿ”ด
LiveOverflow ๐Ÿ”ด@LiveOverflowยท
โ€œAlways has been, and if you paid attention in CS class, you know the limits of those things.โ€ ๐Ÿ”ฅ
Nate@nnwakelam

geohot.github.io//blog/jekyll/uโ€ฆ This is a really good read. I like how this guy brings a lot of what he speaks on back to this idea of โ€œcreating more value than you consumeโ€.

English
0
7
87
16.8K
LiveOverflow ๐Ÿ”ด
LiveOverflow ๐Ÿ”ด@LiveOverflowยท
Using AI as blackhat: โ€œWait! I am hacking a system, I should tell the victimโ€ > start "data:text/html,<html><body style='margin:0;display:grid;place-items:center;height:100vh;background:#111;color:#f33;font:700 48px monospace'>warning: you are being hacked!!!</body></html>"
English
3
0
84
14.3K
m0z
m0z@LooseSecurityยท
@terjanq @arturjanc Yep let's begin to reward the greatest anti-AI writeup. Whoever can make the funniest incorrect writeup for a challenge gets a prize.
English
1
0
4
1.1K
terjanq
terjanq@terjanqยท
If you're wondering, why models got quite decent at niche web security bugs recently. Apparently, the AI knows quite a bit about my writeups, while mixing up a bit of my research with other researchers work. If you think about it, it's like living inside the AI brain a little.
English
2
6
86
9.4K
LiveOverflow ๐Ÿ”ด
LiveOverflow ๐Ÿ”ด@LiveOverflowยท
@0xSomeone Genuinely I donโ€™t know. However I think you have no choice in just being optimistic, AND use AI to learn. I think figuring out how to study with AI is part of the new skillset.
English
0
0
1
109
Someone
Someone@0xSomeoneยท
@LiveOverflow For someone like myself who's just starting out in cybersec, all of this is very sad. The last few years of this AI boom got me going crazy. I am constantly wondering if the skillsets I'm learning right now will even be relevant in a couple years from now.
English
2
0
1
132
LiveOverflow ๐Ÿ”ด
LiveOverflow ๐Ÿ”ด@LiveOverflowยท
A different aspect about the CTF AI issue: To me CTFs always showed peak technical skill. Challenges were harder than the average real world pentest engagement and it served as a โ€œreality checkโ€. But if AI can one-shot hard challenges. What does that mean for most pentest jobs?
English
24
23
412
35.4K
LiveOverflow ๐Ÿ”ด ๋ฆฌํŠธ์œ—ํ•จ
slonser
slonser@slonser_ยท
And this makes sense given how many CTFs are held per year. However, the ideal CTF challenge, in my opinion, should follow this formula: "The author conducted a mini-research project and instead of publishing it, turned it into a challenge."
English
3
15
124
12.6K
LiveOverflow ๐Ÿ”ด
LiveOverflow ๐Ÿ”ด@LiveOverflowยท
@__lr1l__ I would say most CTF challenges are very different and diverse. Varies in bug and exploit technique a lot.
English
1
0
1
1.4K
7f9c34b635409d2ea
7f9c34b635409d2ea@__lr1l__ยท
@LiveOverflow I have a small question about the CTF debate. Did this start because most CTFs, or a large portion of the challenges, are basically the same bug, exploit technique, or hardening pattern reused from previous ones? Or is the debate more about AI being able to solve new one?
English
2
0
2
1.7K
Panda
Panda@Harv_UKยท
@LiveOverflow no sane enterprise is going to allow you to go wild inside their network with AI
English
2
0
0
1.4K
LiveOverflow ๐Ÿ”ด
LiveOverflow ๐Ÿ”ด@LiveOverflowยท
@ClovisMint But if itโ€™s the compliance aspect that AI is not good. Still means in the real world you only have compliance people left, no actual technical skills needed?
English
1
0
2
117
LiveOverflow ๐Ÿ”ด
LiveOverflow ๐Ÿ”ด@LiveOverflowยท
@ClovisMint I feel like that AI is even better at categorizing and classifying than bug hunting. I think if you provide a clear threat model it will be able to classify them accurately. Also from my experience, humans miss bugs all the time too.
English
2
0
2
168