Why phone? This cuts out a lot of phones. Why not on a computer?
I used to red team professionally, and it is a lot easier to sneak an unauthorized phone into a facility than a computer.
Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
11–20 of 38 posts
Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
#12The following rant is not against the owner/project - but... What an irony. I cant publish a attack surface mapping / pentesting tool i wrote which runs fully deterministic and really controlable due to "dual use" legal problems - but llm driven tools hit public space...... sorry for the rant....
Metasploit is one example: https://github.com/rapid7/metasploit-framework
Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
#13The following rant is not against the owner/project - but... What an irony. I cant publish a attack surface mapping / pentesting tool i wrote which runs fully deterministic and really controlable due to "dual use" legal problems - but llm driven tools hit public space...... sorry for the rant....
Are you referring to GitHub policies? I haven’t seen issues like that from people publishing security tools before. Metasploit is one example: https://github.com/rapid7/metasploit-framework
The problem is that they are formulated in a way that it is super easy to have your software being possible "dual use" and that a judge has to decide if its fine or not. Making it worse it also states your "intention" which well is impossible to proof - if the judge says he doesn't believe your intentions are only good, you can literally get massively sued.
So ye i could move to another country and than publish it - apart from that i can let it rot on my hdd (which is prolly what will happen).
Edit: Additionally mentioned, it is not just the publishing in germany, even the facilitating already which is why i don't even have an article about it (any more).
Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
#14Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
#15Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
#16Earlier quoted context omitted.
Are you referring to GitHub policies? I haven’t seen issues like that from people publishing security tools before. Metasploit is one example: https://github.com/rapid7/metasploit-framework
No im referring to the legal terms of germany, the country im residing at. Our laws regarding "hacking" are arguable the strictest and worst. The problem is that they are formulated in a way that it is super easy to have your software being possible "dual use" and that a judge has to decide if its fine or not. Making it worse it also states your "intention" which well is impossible to proof - if the judge says he doe…
I'm asking cuz I started devloping a c2+agent+BOF kind of thing with custom bytecode vm for the lulz (to learn how stuff works nowadays) and it's on tangled and github :/
Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
#17Earlier quoted context omitted.
Are you referring to GitHub policies? I haven’t seen issues like that from people publishing security tools before. Metasploit is one example: https://github.com/rapid7/metasploit-framework
No im referring to the legal terms of germany, the country im residing at. Our laws regarding "hacking" are arguable the strictest and worst. The problem is that they are formulated in a way that it is super easy to have your software being possible "dual use" and that a judge has to decide if its fine or not. Making it worse it also states your "intention" which well is impossible to proof - if the judge says he doe…
Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
#18Earlier quoted context omitted.
Are you referring to GitHub policies? I haven’t seen issues like that from people publishing security tools before. Metasploit is one example: https://github.com/rapid7/metasploit-framework
No im referring to the legal terms of germany, the country im residing at. Our laws regarding "hacking" are arguable the strictest and worst. The problem is that they are formulated in a way that it is super easy to have your software being possible "dual use" and that a judge has to decide if its fine or not. Making it worse it also states your "intention" which well is impossible to proof - if the judge says he doe…
Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone
#19The following rant is not against the owner/project - but... What an irony. I cant publish a attack surface mapping / pentesting tool i wrote which runs fully deterministic and really controlable due to "dual use" legal problems - but llm driven tools hit public space...... sorry for the rant....