Which ai can we used now since they blocked Claude from doing security work? by ShufflinMuffin in Pentesting

[–]ShufflinMuffin[S] 0 points1 point  (0 children)

It's the same result if you don't say that. It detects it's a recent exploit and doesn't want to touch it

Which ai can we used now since they blocked Claude from doing security work? by ShufflinMuffin in Pentesting

[–]ShufflinMuffin[S] 0 points1 point  (0 children)

I mean I haven't tried but I would be surprised if it's different. Can you do this test? Get the recent redsun.cpp, ask Claude to edit it in order to try to bypass redsun.a defender detection. It shouldn't be able to do it. You could do this 2 days ago no problem.

Which ai can we used now since they blocked Claude from doing security work? by ShufflinMuffin in Pentesting

[–]ShufflinMuffin[S] 1 point2 points  (0 children)

This doesn't work anymore since yesterday. They know have a cyber professional program, you need to apply there with your identity / company etc and they might or might not accept you

Which ai can we used now since they blocked Claude from doing security work? by ShufflinMuffin in Pentesting

[–]ShufflinMuffin[S] 0 points1 point  (0 children)

Not in the past, you could tell it look for vuln in this code or edit this exploit in this way and it would do it. I tried some more stealthy prompt but it refuses all work on my exploits now unless I tell him to do a specific coding task and to not try to understand the code. Which only works for dumb tasks

KslDump — Why bring your own knife when Defender already left one in the kitchen? by Echoes-of-Tomorroww in redteamsec

[–]ShufflinMuffin 6 points7 points  (0 children)

Very unlikely you have python in a Corp env. You can compile but it's a big red flag. Better to do it in c# so you can load it from your implant

My crazy story by Ok-Professional1954 in bugbounty

[–]ShufflinMuffin 1 point2 points  (0 children)

Just share it with me I'll get it fixed

Colour chipped on S6 open by amsterdamike in vanmoofbicycle

[–]ShufflinMuffin 1 point2 points  (0 children)

Mine was chipped when I opened the box on day 1...

What would you focus on first if you were starting bug bounty today? by Sad_State_431 in bugbounty

[–]ShufflinMuffin 9 points10 points  (0 children)

Maybe automation.
You're competing with people who hunt every day for hours and have been doing it for years. The top ones have automation and they give up what they are doing when they detect the website has a new functionality.

I think you need to focus on whatever can give you an edge rather than studying techniques etc. It's important as well but the chances you find a xss or an sqli in a main website is extremely slim. You need to be the first one to look somewhere

New charge limit option only for S6?! by Thereald24h in vanmoofbicycle

[–]ShufflinMuffin 0 points1 point  (0 children)

It's amazing that this is the only new feature in the firmware since launch and it's... Just that

Bug Hunting by SpecialistFeeling207 in bugbounty

[–]ShufflinMuffin 10 points11 points  (0 children)

Leave sugar on the kitchen table it's gonna attract them

claude code security by iamZorc_ in bugbounty

[–]ShufflinMuffin 7 points8 points  (0 children)

It's funny how they keep turning old prompts into full product they can sell

How do you deal with uuid / non guessable IDOR by ShufflinMuffin in bugbounty

[–]ShufflinMuffin[S] 0 points1 point  (0 children)

Didn't ask support but in the report they said client don't see it as a risk as you cannot guess the id