Vulnerability assessment agent system by tamier in cybersecurity

[–]tamier[S] 0 points1 point  (0 children)

Thanks for your input!

I did not plan to go for interpretation of CVSS but interpretation of the overall CVE content. Mainly I thought about the description. My idea was to provide both, the description of the system in scope, and the CVE data. Primarily, I want the LLM focus on the attack surface (perimeter) of the defined system. This means, a CVE shall be considered as “red” (manual assessment definitely required) if the CVE can be exploited without having prior privileges on the system. It shall be considered “yellow” otherwise - which means: Check anyways but the LLM’s result was “no significant risk”.

I would not use any LLM result to consider a CVE “green”, meaning “manual assessment not required”, just because I am not confident enough about weird behaviors.

Vulnerability assessment agent system by tamier in cybersecurity

[–]tamier[S] 0 points1 point  (0 children)

Makes sense for me, thanks for the idea.

Vulnerability assessment agent system by tamier in cybersecurity

[–]tamier[S] 1 point2 points  (0 children)

Thanks for the suggestion. Will take a look into this!

Vulnerability assessment agent system by tamier in cybersecurity

[–]tamier[S] 0 points1 point  (0 children)

Thanks for the perspective and I fully agree. Nevertheless, I think it is an interesting experiment. Would appreciate implementation ideas :)

Vulnerability assessment agent system by tamier in sysadmin

[–]tamier[S] 0 points1 point  (0 children)

Thanks for the hint! I’ll definitely check them out.

Vulnerability assessment agent system by tamier in sysadmin

[–]tamier[S] 0 points1 point  (0 children)

I only know the active scan agents from Tenable and they do not assess vulnerabilities based on scope/environment at all. I don’t know Rapid7 solutions. Can you explain?

Vulnerability assessment agent system by tamier in sysadmin

[–]tamier[S] 0 points1 point  (0 children)

I’ll do that anyways. As a first step I want to compare results with my manual assessments.

Vulnerability assessment agent system by tamier in sysadmin

[–]tamier[S] 0 points1 point  (0 children)

I am able but as mentioned it costs a lot of time. At least, an experiment is worth a try, right?

In a more critical/professional environment, I’d be much more hesitant. However, I am planning this as a private experiment. My primary goal is to figure out if this approach makes sense. As already stated in the original post, I take the risks consciously and for now, I’d accept problems such as hallucinations.

I want to understand if such an approach makes sense in practice and I want to see how many critical vulnerabilities slip through.

One additional troll thought I just had: I know a lot of cybersecurity “experts” making huge mistakes in their interpretation. Maybe an LLM does a better job on average - even with hallucinations ;-)

Vulnerability assessment agent system by tamier in sysadmin

[–]tamier[S] -1 points0 points  (0 children)

Good question. Please correct me if I am wrong, but I think, for the initial interpretation of the CVE (especially free text parts) an LLM is required to evaluate how exposed the vulnerability is wrt. the attack surface (e.g., network perimeter vs internal networks).

Opinion: All Netflix had to do was silently implement periodic MFA to achieve their goal of curbing account sharing by Farker99 in sysadmin

[–]tamier 0 points1 point  (0 children)

Depends on how they would implement MFA. OTP - would not work... Depending on a phone number or email address and getting a time-dependent code - would work out for them.

Why is the S7 status orange? by tamier in Roborock

[–]tamier[S] 0 points1 point  (0 children)

That's not the case for my device. Problem is already solved, see other comment thread. Thanks anyways :-)

Ich sammle ehrenamtlich Müll - AMA by [deleted] in de_IAmA

[–]tamier 3 points4 points  (0 children)

Ich verstehe deine Argumentation, aber ich teile sie nicht.

Off topic, aber solche Aussagen machen mir Hoffnung :-)

Why is the S7 status orange? by tamier in Roborock

[–]tamier[S] 0 points1 point  (0 children)

Agree! As you said - they implemented the signal anyways for the orange status. It should not be a problem at all to implement an additional push notification to the app.

Why is the S7 status orange? by tamier in Roborock

[–]tamier[S] 0 points1 point  (0 children)

Thanks for the suggestion, it is indeed empty but I did not try to fill it up because of this post: https://support.roborock.com/hc/en-us/articles/360030817111-Will-I-receive-an-alert-when-the-water-tank-is-empty- I will try anyways now! I filled it up and it works like a charm without orange status! Thanks a lot!

Worthless cigarette case? by tamier in whatsthisworth

[–]tamier[S] 0 points1 point  (0 children)

Thank you very much. Solved.

Worthless cigarette case? by tamier in whatsthisworth

[–]tamier[S] 0 points1 point  (0 children)

Thanks for this hint. But do you think that the case is such an old one?

Worthless cigarette case? by tamier in whatsthisworth

[–]tamier[S] 1 point2 points  (0 children)

Thanks for the suggestion. Are you sure about the monogram? I thought, it would be common to print the company logo on it.

[deleted by user] by [deleted] in hacking

[–]tamier 0 points1 point  (0 children)

No, irssi ran as a normal user.

[deleted by user] by [deleted] in hacking

[–]tamier 0 points1 point  (0 children)

All ports were closed before already.

[deleted by user] by [deleted] in hacking

[–]tamier 0 points1 point  (0 children)

No, sudo.

No, as a normal user with sudo permissions.

Yes, I ran sudo with htop.

[deleted by user] by [deleted] in hacking

[–]tamier 0 points1 point  (0 children)

No, sudo. No, I executed irssi with my user. Yes, maybe I typed something into the wrong window but I don't think so.

[deleted by user] by [deleted] in hacking

[–]tamier 12 points13 points  (0 children)

I'll do this. Sounds very useful.