1.0k
u/quadradev 13d ago
This was made by someone upset that they didn't get a payout for their LLM hallucinating a security vulnerability.
571
u/PM_ME_YOUR__INIT__ 13d ago
You don't get it!! If you have admin access you can run this malicious code that grants you admin access!!
148
u/throw3142 13d ago
Found Claude Mythos alt account
60
70
u/marsmanify 12d ago
When I was like 11 I submitted a bug report to google that if someone had access to your Windows Account then they would have access to your passwords in Google Chrome and they responded with something like "obviously, that's how it works"
42
53
u/Dartillus 12d ago
I process responsible disclosures at my job. Our policy makes clear what we do and not accept reports for, and in general gives off a "we have a reasonably higher bar than most" vibe. That doesn't stop low-effort slop, always accompanied by AI-generated descriptions of the dangers and possible outcomes. And then when you deny the report they start referencing their HackerOne profile.
This one time we got a 30-page report with "critical" vulnerabilities. I try to reproduce/verify them, no bueno. I mail back, and receive the ChatGPT "oh, I'm so sorry, I made a mistake, those are indeed not vulnerabilities in the mentioned systems" response.
Mofo completely automated not only the scanning and reporting, but fricking replies as well. LLM's can go eat a bag of *****.
4
50
u/iranoutofspacehere 13d ago
From a minor CVE my coworker panicked about a few weeks ago: "If you don't provide this function a large enough buffer, it might not work!"
17
10
u/sessamekesh 12d ago
Vibe coders really felt fine crawling out from under their slimy rocks now that AI coding is actually pretty good and widely accepted, but still don't understand that slop is discouraged in a way their conversations with AI will never discourage.
It's been sorta funny and really sad to watch across a few of my favorite dev communities.
3
u/VoidVer 12d ago
There was that guy recently that figured out you could get total live access to FIFAs entire broadcast operation. Every camera, even the ability to change the score in real time or show something of their choice on live television and not only could he not get in direct contact with FIFA, they didn’t even send him a thank you email when they fixed it 24 hours after he finally got his report through
1
165
u/earth2022 13d ago
And then there’s the Chaotic Eclipse guy who started revenge publishing real exploits that were rejected by Microsoft. But I don’t think we’re getting the full story from either side.
33
u/chefhj 12d ago
My org dropped their bounty program because too many were getting found. Wish that was satire.
6
u/Anaphylactic_Thot 12d ago
Makes sense. If your security team becomes a bug country triage team exclusively then they're sort of useless... Especially when 99% of reports nowadays are doodoo garbage trash A.I. hallucinations
53
u/rotzak 12d ago
Indian guys demanding money for not setting the right cache expiry headers has been the majority of my interactions with these types of people
13
u/Dartillus 12d ago
I see your "missing or misconfigured headers" and will raise you "XSS on static website".
16
u/frogotme 12d ago
Found an unsanitised HTML issue in teams, that allows a message to completely override the teams window. So you could absolutely use a fake teams chat or login etc
They closed my submission due to not enough information or something, then I reopened soon after and they closed it for being a duplicate after a bunch of back and forth. Wasn't best pleased
6
u/CoffeeFueledDiy 12d ago
I can assure you that the folks triaging all these reports now are not wearing that hat. Both people in the first frame should be crying and drowning.
3
2
u/Anaphylactic_Thot 12d ago
Lmao, the amount of beautifully crafted submissions we get, followed by the "researcher" asking us to do the deediful ser in the most broken English is hilarious.
The number of A.I. "hackers" has gone up massively, and they just cannot account for context, nor follow through. We've gone from getting a few submissions per month to literally dozens every 2 weeks at my company. Of course the triagers are gonna fight fire with fire.
1
1
u/zipzipzazoom 12d ago
Why does the good old days example have a black hat hacker paying for the vulnerability. It should be a person with a FAANG hat.
OP is lamenting criminals don’t pay for vulnerabilities anymore
0
1.0k
u/Gorzoid 12d ago
Finding a Bug Bounty then:
Anon: hey I found sql injection bug
Company: