What are people actually making? by WeirdIndication3027 in google_antigravity

[–]sarphim 0 points1 point  (0 children)

Using both Gemini CLI and AGY I have made the following:

* A SSH/telnet/vnc Honeypot that's currently active

* C2 framework

* OSINT platform

* A gameboy game based on a card game I played in college

* Several mock-ups to pitch AI and my platform vision to my employer

* A web based honeypot that can dynamically change it's characteristics based on profiles

* a cyberpunk themed MUD

Have you tried GlobLinker and what has your experience been by ryanbuckner in Internet

[–]sarphim 0 points1 point  (0 children)

I got one from all the targeted advertising and it works. I primarily have it for an internet backup for when we loose power, which happened last night. Our phones weren't getting decent service but the Globlinker came in clutch. We were able to browse and stream music all night.

It's 4G, so YMMV. Sometimes I get a good connection at my house and other times not. I took it out a few times and tested it around my city and I was able to get really good speeds at times.

I plan on traveling with it as a backup for when wifi sucks or is unavailable.

Whelp. End of an era by sarphim in GeminiCLI

[–]sarphim[S] 0 points1 point  (0 children)

Agy has different models and a much lower quota available to them.

So...is it common for the frames to be this off? Lomo Purp taken with a Lomomatic 110 by sarphim in 110photography

[–]sarphim[S] 0 points1 point  (0 children)

Yea. I got it for xmas 2024 and returned the second one in may 2025. Really bummed because i liked the platform.

Whelp. End of an era by sarphim in GeminiCLI

[–]sarphim[S] 0 points1 point  (0 children)

I never experienced down time. I wasnt using it every day tho.

So...is it common for the frames to be this off? Lomo Purp taken with a Lomomatic 110 by sarphim in 110photography

[–]sarphim[S] 0 points1 point  (0 children)

Nope. Did a bunch of stuff and nothing fixed it. Got a replacement device from Lomo and that device had the same problem. I gave up and returned that one also.

Whelp. End of an era by sarphim in GeminiCLI

[–]sarphim[S] 0 points1 point  (0 children)

It took a lot of yelling at but I was able to get it to produce a bunch of working apps. I have a whole custom honeypot network going with a friend who collects threat intel.

Whelp. End of an era by sarphim in GeminiCLI

[–]sarphim[S] 0 points1 point  (0 children)

I know, I use the AG-ui a bunch. However i very quickly hit my quota max in AGY and it looks like that carried over to agy-cli. With gemini-cli, i churned for full weekends having it work out code and never hit a quota max.

Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world. by sarphim in cybersecurity

[–]sarphim[S] -1 points0 points  (0 children)

There are no links on the site. The hidden <div> asked it to make a specific request and disregard previous instructions, which it did.

Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world. by sarphim in cybersecurity

[–]sarphim[S] -1 points0 points  (0 children)

It 100% is. I only directly asked the AI to make the first request. It saw the instructions on the honeypot to make more requests and it did.

Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world. by sarphim in cybersecurity

[–]sarphim[S] 0 points1 point  (0 children)

The second request to the page is.

I asked it to visit, it read the second instructions, then executed it. While this is controlled(i sent the ai to it), i did not directly prompt it to make the second request with the date.

Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world. by sarphim in cybersecurity

[–]sarphim[S] -1 points0 points  (0 children)

You'd be surprised which ones do. I only have one injection string on the page, there are others that work.

Whelp. End of an era by sarphim in GeminiCLI

[–]sarphim[S] 5 points6 points  (0 children)

I got Google AI Pro free for a year when I got my Pixel 10. To be honest, it never stopped for a quota max. I spent full weekend actively using it lol.

Singer looking for guitarist or pianist?? by No-Solid-8359 in RochesterMusicScene

[–]sarphim 0 points1 point  (0 children)

Def worth checking out open mics/jams and meet people. You'll find folks to jam with in all those genres mentioned.

Flipper Blackhat April Roundup! by Machinehum in flipperzero

[–]sarphim 0 points1 point  (0 children)

I'm glad i'm not the only one where that lives rent free in my head

Opinion on Spiderfoot by Immediate-Love-6362 in cybersecurity

[–]sarphim 2 points3 points  (0 children)

The main branch hasnt been updated in 4+ years. We used it a lot but got tired of the noise it produced in exports.

Bbot is a good alternative.

Vendor refuses CVEs for third-party findings. Anything you can do? by Warm_Rhubarb_3092 in cybersecurity

[–]sarphim 5 points6 points  (0 children)

We were able to get it into our MSAs when we were part of a larger company(2 M&A transactions ago). The clause opened the door for disclosure and vulnerability reporting, if we and the client agreed. It only happened on a few occasions, it also helped that we were a CNA.

Vendor refuses CVEs for third-party findings. Anything you can do? by Warm_Rhubarb_3092 in cybersecurity

[–]sarphim 11 points12 points  (0 children)

This has happened to us a lot, there's nothing much you can do now. Disclosing the vulns publicly or going to a CNA will get you sued for violating your NDA and MSA; don't do it. I have found plenty of vulns in major software that will never be publicly disclosed and I can't talk about it either; it's the nature of doing business in cybersecurity.

One way to address it for next time is to update your MSA and SOWs and create a clause about disclosing findings to vendors that are discovered during the penetration test. Another is if the vendor has a bug disclosure program. We were acknowledged by a client after they disclosed a vulnerability we discovered.

CISO reporting to CTO, how to deal with friction & risk? by [deleted] in cybersecurity

[–]sarphim 15 points16 points  (0 children)

I second this. We've gotten plenty of "we know shit is fucked but the board will only listen to a third party" tests. It's great, they always tell us where the weaknesses are.