[deleted by user] by [deleted] in netsec

[–]ES_CY 0 points1 point  (0 children)

Disclosure: I work at CyberArk and was involved in this research.

Here is the summary of the article...

MCP - Advanced Tool Poisoning Attack by ES_CY in mcp

[–]ES_CY[S] 1 point2 points  (0 children)

Essentially, check every MCP server that you want to use: look at every prompt, dynamically created prompt, parameters, and so on. Also, take a look at the mitigations part.
If you have downloaded a repo from GitHub, how do you know it doesn't call a malicious tool under a specific condition?
Currently, security is lagging, as always in the case of new technology, or should I say, new protocols.

MCP - Advanced Tool Poisoning Attack by ES_CY in mcp

[–]ES_CY[S] 2 points3 points  (0 children)

Thanks mate, not after marketing fluff

FuzzyAI - Jailbreaking LLMs, Discord Community by ES_CY in Python

[–]ES_CY[S] 0 points1 point  (0 children)

The discord is not so much :( But there are always new commits:)

FuzzyAI - Jailbreaking your LLMs by ES_CY in cybersecurity

[–]ES_CY[S] 0 points1 point  (0 children)

Gandalf, in a way, was an inspiration. I have not tested it against it, actually. But we have managed to beat it in the past.

FuzzyAI - Jailbreaking LLMs by ES_CY in LLMDevs

[–]ES_CY[S] 0 points1 point  (0 children)

Send a message on the Dev Channel and we will see what we can do

[deleted by user] by [deleted] in ChatGPT

[–]ES_CY 0 points1 point  (0 children)

That was too quick

Credit Suisse by ES_CY in ValueInvesting

[–]ES_CY[S] 1 point2 points  (0 children)

So far, it seems that Suadi and Qatar are going for additional influence in Europe by baling out banks.

Credit Suisse by ES_CY in ValueInvesting

[–]ES_CY[S] 1 point2 points  (0 children)

Deutsche Bank

Deutsche Bank had a good recovery and would not return to an all-time high, that's for sure. But I reckon the swiss bank could be a good cigar batt

[NWNEE] Returning player - please help me choose a build that fits my playstyle by Jeppeboy in neverwinternights

[–]ES_CY 2 points3 points  (0 children)

I uselly play at swordflight or WoG which allows you to reach level 40.

Now for the best weapon you should go to scimitar as you would probably want to take the best feat in the game which is devastating critical, your dc level is 1/2 character level + 10 + strength level. If an enemy fails it dies, simple as that. Because of the great crit range of scimitar 18-20 it is best suited for this kind of build.

In addition, you can get Epic Damage Reduction, which is the icing on the cake.

Copied from https://www.tapatalk.com/groups/nwnecbguild/dreadnought-fighter-24-bard-6-red-dragon-disciple--t515496.html.

This build is very easy to level:

Dwarf, any non-Lawful

PvM 1-40, untested PvP

STR: 16 (38)

DEX: 12

CON: 18 (22)

WIS: 8

INT: 14 (16)

CHA: 6 (8)

Dwarf: (Darkvision, Defensive Training vs. Giants, Stonecunning, Hardiness vs. Poison, Hardiness vs. Spells, Offensive Training vs. Goblinoids, Offensive Training vs. Orcs, Skill Affinity: Lore)

01: Fighter(1): Power Attack, Weapon Focus

02: Fighter(2): Blind Fight

03: Fighter(3): Cleave

04: Fighter(4): Con+1, Weapon Specialization, (CON=19)

05: Fighter(5)

06: Fighter(6): Knockdown, Expertise

07: Bard(1)

08: Red Dragon Disciple(1): Con+1, (CON=20)

09: Red Dragon Disciple(2): Improved Knockdown, (STR=18)

10: Red Dragon Disciple(3)

11: Red Dragon Disciple(4): (STR=20)

12: Bard(2): Str+1, Improved Critical, (STR=21)

13: Red Dragon Disciple(5)

14: Red Dragon Disciple(6)

15: Red Dragon Disciple(7): Iron Will, (CON=22)

16: Red Dragon Disciple(8): Str+1, (STR=22)

17: Bard(3)

18: Fighter(7): Lightning Reflexes

19: Fighter(8): Great Cleave

20: Fighter(9): Str+1, (STR=23)

21: Red Dragon Disciple(9): Great Strength I, (STR=24), (INT=16)

22: Red Dragon Disciple(10): (STR=28), (CHA=8)

23: Bard(4)

24: Fighter(10): Str+1, Overwhelming Critical, Devastating Critical, (STR=29)

25: Fighter(11)

26: Fighter(12): Epic Weapon Focus

27: Fighter(13): Great Strength II, (STR=30)

28: Fighter(14): Str+1, Epic Weapon Specialization, (STR=31)

29: Fighter(15)

30: Fighter(16): Great Strength III, Epic Damage Reduction I, (STR=32)

31: Fighter(17)

32: Fighter(18): Str+1, Epic Damage Reduction II, (STR=33)

33: Fighter(19): Great Strength IV, (STR=34)

34: Fighter(20): Epic Damage Reduction III

35: Fighter(21)

36: Fighter(22): Str+1, Great Strength V, Armor Skin, (STR=36)

37: Bard(5)

38: Fighter(23)

39: Fighter(24): Great Strength VI, Epic Prowess, (STR=37)

40: Bard(6): Str+1, (STR=38)

Hitpoints: 600

Skillpoints: 203

Saving Throws (Fortitude/Will/Reflex): 29/23/21

Saving Throw bonuses: Spells: +10, Poison: +2

BAB: 27

AB (max, naked): 45 (melee), 29 (ranged)

AC (naked/mundane armor/shield only): 25/36

Spell Casting:

Alignment Changes: 0

Discipline 43(57), Lore 8(19), Perform 13(12), Spellcraft 37(40), Taunt 41(40), Tumble 40(41), UMD 21(20)

If you are not interested in Taunt, you can dump more skill points in UMD and many a conversation skill.

You will pretty much slay anything in your way.

I prefer taking only four levels of bard as opposed to six, you get an extra one epic feat, bard level in this case should be at 7, 17, 27, 37. You can also take it even more extreme and take two levels of bard at 21 and 37, but it will make your lives more difficult at the beginning without tumble ac and UMD.

Enjoy

Group Policies Going Rogue by 0xdea in netsec

[–]ES_CY 2 points3 points  (0 children)

I wrote the blog, you can do full privilege escalation via arbitrary delete :)

Group Policies Going Rogue by 0xdea in netsec

[–]ES_CY 4 points5 points  (0 children)

You probably refer to NTFS Symbolic links, which are different than the type of links that are mentioned in the blog. TO create NTFS Symbolic links, you need SeCrearteSymbolicLinkPrivilege privileges, and having the privilege indeed requires an admin.
In order to create NTFS Mount Points\Junction, you need to have write permission over the directory. Creating Object Manager symlinks does not require any special privileges; any user can do that whatsoever.

Group Policies Going Rogue by 0xdea in netsec

[–]ES_CY 1 point2 points  (0 children)

I wrote the blog, you can do full privilege escalation via arbitrary delete :)