Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

Nerve ( ) and the code_auditor example tasklet ( ) using GPT-4o to find a RCE vulnerability in the widget-options v4.0.7 Wordpress Plugin 🧠 Zero code, fully autonomous agent as a simple YAML file.

32,482 görüntüleme • 1 yıl önce •via X (Twitter)

10 Yorum

Simone Margaritelli profil fotoğrafı
Simone Margaritelli1 yıl önce

Pushed v0.4.0 with NVidia NIM integration and a few fixes, thanks to @vysecurity for the request and the help with the API key :D

Simone Margaritelli profil fotoğrafı
Simone Margaritelli1 yıl önce

The web_fingerprint example tasklet can be used to identify which technologies a website is built with:

blasty profil fotoğrafı
blasty1 yıl önce

next step: making Nerve deploy the codebase and verify the vulnerability, and then request a CVE? 😎

Simone Margaritelli profil fotoğrafı
Simone Margaritelli1 yıl önce

first part is essentially there already. As far as requesting the CVE and bearing with the disclosure process go, idk how well an AI would perform :D

Simone Margaritelli profil fotoğrafı
Simone Margaritelli1 yıl önce

Since the first tweet in this thread, Nerve has been republished to and new providers for Nvidia NIM, DeepSeek and xAI (grok-beta is pretty great with tool calling) have been implemented 🚀

AndrewMohawk⁽ⁿᵘˡˡ⁾ profil fotoğrafı
AndrewMohawk⁽ⁿᵘˡˡ⁾1 yıl önce

How well has it done with others? Similarly? I think it would be interesting to build a list of _recent_ vulns in a dir and compare the stats!

Simone Margaritelli profil fotoğrafı
Simone Margaritelli1 yıl önce

i didn't try them all, but generally GPT and Claude models perform similarly, with bigger Anthropic models being better at extrapolating context and finding logic bugs while OpenAI seem better at single file vulnerabilities ... LLama models a bit worse than the others, but considering they're free who can complain :D

waba fking fet profil fotoğrafı
waba fking fet1 yıl önce

really cool man

Simone Margaritelli profil fotoğrafı
Simone Margaritelli1 yıl önce

thanks!

SickSec 🇲🇦 🇵🇸 profil fotoğrafı
SickSec 🇲🇦 🇵🇸1 yıl önce

cc @wld_basha @rez0__ 👀

Benzer Videolar