I think the page is just a lie. It's an add for vivgrid. The next-page button doesn't work. Many of the Chinese entries have emojis in their names, which seems to me an unrealistic amount of whimsy (I suspect instead that the data is manufactured, and the AI ~helpfully~ included emojis for the webapp owner's easier understanding). Almost every entry with latin text is named just "Assistant" (wow what a coincidence!).…
OpenClaw Exposure Watchboard
21–30 of 32 posts
Re: OpenClaw Exposure Watchboard
#22Does publicly documenting and direct linking vulnerable AI agents (that have goodness-knows-how-much access to sensitive user data) for anyone to exploit feel like responsible disclosure? This could really ruin some people's day. A private message left on their agents to tip people off that their agents are vulnerable feels a lot less destructive.
Shodan has existed for at least a decade and you can't create a cloud instance anywhere these days without it getting immediately crawled. Literally, I was setting up a VPS last week and within 5 minutes of caddy getting a cert from lets encrypt (which then adds the hostname to the certificate transparency log) the access log lit up with dozens of requests per second, all requesting paths like `/wp-admin` and `/admin…
Re: OpenClaw Exposure Watchboard
#23I think the page is just a lie. It's an add for vivgrid. The next-page button doesn't work. Many of the Chinese entries have emojis in their names, which seems to me an unrealistic amount of whimsy (I suspect instead that the data is manufactured, and the AI ~helpfully~ included emojis for the webapp owner's easier understanding). Almost every entry with latin text is named just "Assistant" (wow what a coincidence!).…
Yes, there is some kind of network of bot accounts that upvote AI slop onto the front page.
Re: OpenClaw Exposure Watchboard
#24Re: OpenClaw Exposure Watchboard
#25Does publicly documenting and direct linking vulnerable AI agents (that have goodness-knows-how-much access to sensitive user data) for anyone to exploit feel like responsible disclosure? This could really ruin some people's day. A private message left on their agents to tip people off that their agents are vulnerable feels a lot less destructive.
Be the change you want to see… it’s not like this being public changes much, anyone who wanted to exploit this could do it without this site
Re: OpenClaw Exposure Watchboard
#26page 2 doesn't work
Re: OpenClaw Exposure Watchboard
#27Re: OpenClaw Exposure Watchboard
#28Can somebody explain what it means that an openclaw instance is exposed? Is this some specific http server or website that is running?