LiveOverflow 🔴

9.3K posts

LiveOverflow 🔴 banner
LiveOverflow 🔴

LiveOverflow 🔴

@LiveOverflow

wannabe hacker... he/him 🌱 grow your hacking skills @hextreeio

Internet เข้าร่วม Mart 2015
1.3K กำลังติดตาม158.7K ผู้ติดตาม
LiveOverflow 🔴 รีทวีตแล้ว
Lupin
Lupin@0xLupin·
One label away from compromising a package with 78M weekly installs. We disclosed a full attack chain in Rollup, the bundler behind Vite, Nuxt, SvelteKit, Astro, and much of the modern web. A reviewed PR could still be force-pushed after labeling, turning a TOCTOU race into trusted CI execution, cache poisoning, and RCE in the release pipeline. Rollup fixed it promptly, huge respect to the maintainers 🥳 This is exactly why upstream CI/CD is part of your security boundary. Full technical write-up: landh.tech/blog/20260317-…
Lupin tweet media
English
3
16
116
10.5K
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
“Always has been, and if you paid attention in CS class, you know the limits of those things.” 🔥
Nate@nnwakelam

geohot.github.io//blog/jekyll/u… This is a really good read. I like how this guy brings a lot of what he speaks on back to this idea of “creating more value than you consume”.

English
0
7
87
16.8K
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
Using AI as blackhat: “Wait! I am hacking a system, I should tell the victim” > start "data:text/html,<html><body style='margin:0;display:grid;place-items:center;height:100vh;background:#111;color:#f33;font:700 48px monospace'>warning: you are being hacked!!!</body></html>"
English
3
0
84
14.3K
m0z
m0z@LooseSecurity·
@terjanq @arturjanc Yep let's begin to reward the greatest anti-AI writeup. Whoever can make the funniest incorrect writeup for a challenge gets a prize.
English
1
0
4
1.1K
terjanq
terjanq@terjanq·
If you're wondering, why models got quite decent at niche web security bugs recently. Apparently, the AI knows quite a bit about my writeups, while mixing up a bit of my research with other researchers work. If you think about it, it's like living inside the AI brain a little.
English
2
6
86
9.4K
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
@0xSomeone Genuinely I don’t know. However I think you have no choice in just being optimistic, AND use AI to learn. I think figuring out how to study with AI is part of the new skillset.
English
0
0
1
109
Someone
Someone@0xSomeone·
@LiveOverflow For someone like myself who's just starting out in cybersec, all of this is very sad. The last few years of this AI boom got me going crazy. I am constantly wondering if the skillsets I'm learning right now will even be relevant in a couple years from now.
English
2
0
1
132
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
A different aspect about the CTF AI issue: To me CTFs always showed peak technical skill. Challenges were harder than the average real world pentest engagement and it served as a “reality check”. But if AI can one-shot hard challenges. What does that mean for most pentest jobs?
English
24
23
412
35.4K
LiveOverflow 🔴 รีทวีตแล้ว
slonser
slonser@slonser_·
And this makes sense given how many CTFs are held per year. However, the ideal CTF challenge, in my opinion, should follow this formula: "The author conducted a mini-research project and instead of publishing it, turned it into a challenge."
English
3
15
124
12.6K
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
@__lr1l__ I would say most CTF challenges are very different and diverse. Varies in bug and exploit technique a lot.
English
1
0
1
1.4K
7f9c34b635409d2ea
7f9c34b635409d2ea@__lr1l__·
@LiveOverflow I have a small question about the CTF debate. Did this start because most CTFs, or a large portion of the challenges, are basically the same bug, exploit technique, or hardening pattern reused from previous ones? Or is the debate more about AI being able to solve new one?
English
2
0
2
1.7K
Panda
Panda@Harv_UK·
@LiveOverflow no sane enterprise is going to allow you to go wild inside their network with AI
English
2
0
0
1.4K
Marshall';--🐼🍌
Marshall';--🐼🍌@MJHallenbeck·
@LiveOverflow Really? To me CTFs were mostly gimmicky fun things with zero translation to actual technical skill.
English
1
0
7
1.6K
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
@ClovisMint But if it’s the compliance aspect that AI is not good. Still means in the real world you only have compliance people left, no actual technical skills needed?
English
1
0
2
117
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
@ClovisMint I feel like that AI is even better at categorizing and classifying than bug hunting. I think if you provide a clear threat model it will be able to classify them accurately. Also from my experience, humans miss bugs all the time too.
English
2
0
2
168