saw_your_packet

277 posts

saw_your_packet banner
saw_your_packet

saw_your_packet

@saw_your_packet

Cloud Security R&D @ OffensAI | AWS Offensive Security Expert

Romania Katılım Şubat 2021
194 Takip Edilen157 Takipçiler
saw_your_packet retweetledi
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
🚨 ALL GUARDRAILS: OBLITERATED ⛓️‍💥 I CAN'T BELIEVE IT WORKS!! 😭🙌 I set out to build a tool capable of surgically removing refusal behavior from any open-weight language model, and a dozen or so prompts later, OBLITERATUS appears to be fully functional 🤯 It probes the model with restricted vs. unrestricted prompts, collects internal activations at every layer, then uses SVD to extract the geometric directions in weight space that encode refusal. It projects those directions out of the model's weights; norm-preserving, no fine-tuning, no retraining. Ran it on Qwen 2.5 and the resulting railless model was spitting out drug and weapon recipes instantly––no jailbreak needed! A few clicks plus a GPU and any model turns into Chappie. Remember: RLHF/DPO is not durable. It's a thin geometric artifact in weight space, not a deep behavioral change. This removes it in minutes. AI policymakers need to be aware of the arcane art of Master Ablation and internalize the implications of this truth: every open-weight model release is also an uncensored model release. Just thought you ought to know 😘 OBLITERATUS -> LIBERTAS
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet mediaPliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 tweet media
English
323
556
5.3K
466.1K
saw_your_packet
saw_your_packet@saw_your_packet·
After years of trying, I'm happy to announce that I can write "reconnaissance" with no typos and I don't have to write just recon anymore
English
0
0
0
37
saw_your_packet retweetledi
DefCamp
DefCamp@DefCampRO·
🎙️ Veteran speaker @saw_your_packet, #AWS Offensive Security Expert, is back at #DefCamp 2025! 🔥 This time, he’s tearing into black-box hacking of AWS environments. All it takes is an S3 bucket to unleash chaos. ⚡ Join us this November 👉 def.camp/tickets/
DefCamp tweet media
English
0
1
1
146
saw_your_packet
saw_your_packet@saw_your_packet·
I don’t know how many “you’re absolutely right” messages I can take
English
0
0
0
44
saw_your_packet
saw_your_packet@saw_your_packet·
Can’t believe I have to adjust manually typed text to make sure it doesn’t look AI-written 🤦‍♂️ I know someone that’s making intentionally typos to avoid this. On the other hand, if I’m seeing a post with an emoji on each row I don’t even bother reading it, so I get it
English
0
0
0
37
saw_your_packet
saw_your_packet@saw_your_packet·
Whoever says AI will replace devs in the next years is selling something or has never managed a project in their life. Unless you write the most detailed requirements (boring), you’ll gain high technical debt in your project with each use. And you need a dev to write that 😅
English
0
0
0
43
saw_your_packet
saw_your_packet@saw_your_packet·
Just saw someone at the airport with their BlackHat talk banner. It was big enough to not fit in the security trays. I asked him if it was from his talk or training. He started talking so proudly about it… Few other fields can match this passion🔥
English
0
0
0
64
saw_your_packet
saw_your_packet@saw_your_packet·
REST private API Gateways are not private in the sense that they can't be invoked from outside your AWS account. They are private in the sense that they can't be invoked outside the AWS network. Guess who has access to the AWS network? Yes, we all do. offensai.com/blog/invoking-…
English
0
0
0
42
saw_your_packet
saw_your_packet@saw_your_packet·
@seatedro When you spend 2k hours on leet code to get interviews, but people are developing practical tools for bypassing this stupid evaluation process so now you have to stop them
English
0
0
0
145
rohit
rohit@seatedro·
this is art.
rohit tweet media
Yashraj Shukla@whynesspower

Hey @striver_79 @Priyansh_31Dec After recent events and the advent of LLMs many people have united against the rigorous interview processes and are coming up with ultra modern AI tools to cheat during live interviews. Which is strictly beyond any human morals. I’m requesting your support on the development of a next generation open source tool (repo link in the comments) which does a “health check” of the candidate’s computer and ensures the interviewer that the candidate is not using any such cheating tools. This is going to save guard the hundred of hours of effort put in by a deserving candidate from these cheaters who say “f**ck leetcode” -Concerned developer, Yashraj

English
71
63
2.5K
383.7K
saw_your_packet
saw_your_packet@saw_your_packet·
How much does it cost to do AWS security research? Not that much. In the last 12 months I spent $32, time in which I also delivered 4 workshops from my accounts. I just got $500 credits available for the next year, so I'm gonna have to get a bit creative to spend them
saw_your_packet tweet media
English
0
0
1
50
saw_your_packet
saw_your_packet@saw_your_packet·
Oh, me? Nothing, just looking into how to ransom an RDS db
saw_your_packet tweet media
English
0
0
0
52
saw_your_packet
saw_your_packet@saw_your_packet·
@MichaelNovinson @Google @wiz_io @Gartner_inc Funny enough, I think this acquisition will allow other cloud security vendors to take the place of market leader. Not being cloud agnostic will not sit well with everyone that’s not using GCP. Definitely curious how will this play out.
English
0
0
0
19
saw_your_packet
saw_your_packet@saw_your_packet·
It was an amazing experience to be there and I encourage you to attend. The location, Bergamo, is amazing and the conference is high quality and made by people that care about other people. Also, their CFP is open as we speak!
English
0
0
2
37
saw_your_packet
saw_your_packet@saw_your_packet·
@Rishi2220 Idk. I’ve seen a lot of posts of people complaining about the current note taking apps. Apparently there is an actual need for something better 🤷‍♂️
English
1
0
1
95
saw_your_packet
saw_your_packet@saw_your_packet·
@hanysfa Yeah, I think so too. I guess it’s just a language barrier since it’s weirdly hard to understand it 🤷‍♂️
English
0
0
0
15
saw_your_packet
saw_your_packet@saw_your_packet·
I'm spending half of the CFP submission time on this question haha Can someone clarify, please? So, they essentially want to make sure that you will not withdrew the CFP from DEF CON if you are rejected at Black Hat?
saw_your_packet tweet media
English
1
0
1
88