Loading video...

Video Failed to Load

Go Home

Exploiting llama.cpp’s RPC Server - From Null Buffer to RCE Against PIE + Full RELRO + NX | CVE-2026-34159: The vulnerability is a one-line logic bug in the RPC server’s tensor deserialization pipeline. Youtube: Blog:

19,539 views • 3 months ago •via X (Twitter)

0 Comments

No comments available

Comments from the original post will appear here

Related Videos

someone built an AI RED TEAM that maps your entire attack surface as a knowledge graph, finds every vulnerability, then EXPLOITS them to root access AUTONOMOUSLY its called RedAmon, 9,000 templates. 17 node types, actual Metasploit shells, not reports, no pentesters needed 6 phases of autonomous recon: subdomain discovery, port scanning, http probing, resource enumeration, vulnerability scanning, MITRE mapping every finding stored in a Neo4j graph with 17 node types and 20+ relationship types. the AI reasons about the graph, finds attack paths, and runs actual Metasploit exploits, actual shells stress-tested with zero vulnerability data, zero exploit modules, one instruction find a CVE and exploit it, it went from empty database to root-level RCE in 20 steps, researched the exploit on the web, crafted a custom deserialization payload, debugged itself when the first attempt failed next try, the server responded with root access, the highest privilege level on any Linux system. full control over everything the target was running node-serialize 0.0.4, a package with a critical deserialization flaw (CVE-2017-5941, CVSS 9.8), the server takes your cookie, decodes it, and passes it straight into unserialize() which executes any code inside it, the AI figured this out on its own with no hints built on LangGraph + MCP tool servers for naabu, nuclei, curl, metasploit. hunts leaked secrets across GitHub repos, 40+ regex patterns for AWS keys, Stripe tokens, database creds

chiefofautism

70,129 views • 5 months ago

Enough is enough! Time to hold trolls responsible! Libelous statements, unsubstantiated accusations, ad hominem and below the belt attacks! For years, the Duterte social media influencers dominated the space as if they were invincible — they would attack whomever that would go against who they are supporting. Myself included. All these relentless attacks can silence those who are fighting the good fight and they were successful, enough for politicians to be afraid of all these one way or another. I set myself to a different standard of social media use, I make sure that everything I write here has a basis… publicly available citations and links for further reading of those who are following me on this platform. I can face the Dutertes anytime, anywhere and defend whatever I write here, that’s how confident I am with what I choose to post here. “This has been happening for years without let up. They get away with it that is why they continue to thrive. It is a business that has become so profitable, without having to pay taxes, no liability, and with the pleasure of being able to ruin people’s reputation without having to worry about getting caught and punished,” -Rep Ace Barbers Aside from requesting the National Bureau of Investigation to look into this, Rep. Ace Barbers through the privilege speech formally asked the House plenary to conduct an investigation regarding all these. IMAGINE MY RELIEF! I thank the chairman of the House Quad Committee for his brave measure. A much needed investigation if you ask me. “Subject to your office’s investigation, these charges may include the crimes of Libel (Art. 353 RPC), Sedition (Art. 139 RPC), Conspiracy to Commit Sedition (Art. 142 of RPC). Incriminating Innocent Person Act (Art. 363 RPC) and Intriguing Against Honor (Art. 364 RPC) – all in relation to Sec. 6 of the Cybercrime Prevention Act”.

Just

91,128 views • 1 year ago