Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nullcathedral
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
nullcathedral
6mo ago
I wouldn't be surprised if we saw a headline in a few years when we find out other actors (e.g. China, Russia) have been buying this data en-masse too.
2.
▲
by
nullcathedral
6mo ago
Yikes. Why are private organizations so happy to participate in mass surveillance.
3.
▲
by
nullcathedral
6mo ago
I got bored so I decided to take another look at Roundcube :)
4.
▲
Roundcube Webmail: three more sanitizer bypasses enable tracking and phishing
(nullcathedral.com)
2 points
by
nullcathedral
6mo ago
|
1 comments
5.
▲
by
nullcathedral
6mo ago
This was one of my most frustrating disclosures, feedback on the process is very welcome :)
6.
▲
Perfex CRM: Unauthenticated RCE via PHP's S: deserialization format
(nullcathedral.com)
1 points
by
nullcathedral
6mo ago
|
1 comments
7.
▲
by
nullcathedral
6mo ago
Did you request a SSL certificate? Those are public, actors use those to scan any newly requested website for known vulnerabilities and other misconfigurations. I suspect you're just looking at standard internet noise :)
8.
▲
by
nullcathedral
6mo ago
Sonnet 4.6 and Opus 4.6 are still available here. Pro+ subscription.
9.
▲
by
nullcathedral
6mo ago
Do you run a dedicated "AI SRE" instance for each customer or how do you ensure there is no potential for cross-contamination or data leakage across customers? Basically how do you make sure your "AI SRE" does not deviat
10.
▲
by
nullcathedral
6mo ago
I think the underlying point is valid. Agents are a potential tool to add to your arsenal in addition to "throw shit at the wall and see what sticks" tools like WebInspect, Appscan, Qualys, and Acunetix.
11.
▲
by
nullcathedral
7mo ago
The website gave it away for me, felt very AI generated
12.
▲
by
nullcathedral
7mo ago
One approach (Claude Code) is to evolve it over time. Start small and run /insights often and use that to refine the CLAUDE.md as needed. https://github.com/trailofbits/claude-code-config?tab=readme...
13.
▲
by
nullcathedral
7mo ago
Feel free to correct me, but the ML classifier appears to be rather bare. Less than 20 hardcoded payloads with randomized URL encoding as the only augmentation. How does this generalize to novel evasion techniques? Genuinely curious what yo
14.
▲
by
nullcathedral
7mo ago
Good suggestion! Thanks. I'll go write up a welcome post soon :)
15.
▲
by
nullcathedral
7mo ago
Author here! Are you referring to the "What’s inside this vendor’s VMware images?" on the about page? That is merely an illustration of what goes on inside my head. This is the first article on my blog.
16.
▲
by
nullcathedral
7mo ago
Author here! I have looked at Thunderbird. I'll go and look at some others as well, should have probably done that earlier.
17.
▲
Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
(nullcathedral.com)
175 points
by
nullcathedral
7mo ago
|
75 comments
18.
▲
by
nullcathedral
8mo ago
https://nullcathedral.com Just waiting on some vendors to patch bugs before I can drop the first set of posts :)
19.
▲
by
nullcathedral
8mo ago
I'd say I agree with you there for the low-hanging fruit. The deep research (there's an image filter here but we can bypass it by knowing some obscure corner of the SVG spec) is where they still fall over and need hand holding by
20.
▲
by
nullcathedral
8mo ago
Maybe in the future when labs train more specifically on offensive work, lots of hand holding needed right now. Even simple stuff like training the models to recognize when they're stuck and should just go clone a repo or pull up the j
21.
▲
by
nullcathedral
8mo ago
I work in this space. The productivity gains from LLMs are real, but not in the "replace humans" direction. Where they shine is the interpretive grunt work: "help me figure out where the auth logic is in this obfuscated blob&