Live data from Hacker News

Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone

github.com

31–38 of 38 posts

Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone

#31

Earlier quoted context omitted.

No im referring to the legal terms of germany, the country im residing at. Our laws regarding "hacking" are arguable the strictest and worst. The problem is that they are formulated in a way that it is super easy to have your software being possible "dual use" and that a judge has to decide if its fine or not. Making it worse it also states your "intention" which well is impossible to proof - if the judge says he doe…

Really? Have there been any cases yet? I'm asking cuz I started devloping a c2+agent+BOF kind of thing with custom bytecode vm for the lulz (to learn how stuff works nowadays) and it's on tangled and github :/

Ye you should be really careful on that one. If just somebody with a bad mood reports you, even if you have absolutely good intentions, it can cost you and if its just in spendings in a lawyer to proof that your fine....

Re: Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone

#37

Earlier quoted context omitted.

Really? Have there been any cases yet? I'm asking cuz I started devloping a c2+agent+BOF kind of thing with custom bytecode vm for the lulz (to learn how stuff works nowadays) and it's on tangled and github :/

Yes. More than one. This one was especially "interesting", a security researcher was tasked by a company to evaluate the ERP (I believe would be the acronym) software. Diiscovered an external database connection, looked at it, discovered this external DB contained sensitive information from other clients of that vendor - reported it, got sued, lost. In German: https://ht-strafrecht.de/blog/strafrecht/it-sicherheitslu…

Ouch, that's pathetic. Hm, maybe I'll leave it then. Not worth the hassle. Although I don't really think someone would hunt me for random non-prod github repos
Post reply on HN