Live data from Hacker News

We got admin access to Baseten's production GitHub

strix.ai

31–40 of 202 posts

Re: We got admin access to Baseten's production GitHub

#31
post #16
post #4

> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…

Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…

Yeah companies need to quickly understand that having good actors try and hack you is a good thing - those hacks get reported and another door gets sealed shut for bad actors.

This is more true today than ever before as the bar for a successful attack has never been lower. We’ll see a resurgence of the script-kiddie, or shall I say, vibe-kiddie :-/

Re: We got admin access to Baseten's production GitHub

#32
post #21

I wonder what model was used for this. Also as far as I know Baseten does not have any abliterated models in their repertoire.

Either Mythos 5.1 or GPT 5.6 Cyber (aka. GPT Daybreak Red)

The writing sounds like Claude to me

Re: We got admin access to Baseten's production GitHub

#33
post #19

Earlier quoted context omitted.

Let us know if you have any feedback!

If I enter an address to "Start testing", I expect at least a preview of the report rather than being dumped on the signup page.

Yeah understood — we need to make sure you own the domain first though

Re: We got admin access to Baseten's production GitHub

#34
> We build Strix, an autonomous hacking again.

> But... we're a security company.

> So... we pointed Strix at *.baseten.co and let it run without credentials or source code.

lawyers wet dream. and a perfect case. A security company who KNOWS the law unleashed an AI agent to violate the laws

Re: We got admin access to Baseten's production GitHub

#37
post #21

I wonder what model was used for this. Also as far as I know Baseten does not have any abliterated models in their repertoire.

The bot snippets talk claudish. I'd say Opus 5. But they must be Cyber Verification Program approved by Anthropic I suppose for the LLM not to block them.

Re: We got admin access to Baseten's production GitHub

#38
post #21

I wonder what model was used for this. Also as far as I know Baseten does not have any abliterated models in their repertoire.

Either Mythos 5.1 or GPT 5.6 Cyber (aka. GPT Daybreak Red)

Even something like Qwen 3.8 27b could do this.

Lookup certificate transparency and continue from there https://crt.sh/?Identity=baseten.co&exclude=expired&match=IL...

Re: We got admin access to Baseten's production GitHub

#39
post #16
post #4

> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…

Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…

Swag packages like these are a token of appreciation not a reward.

The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature .

Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet .

Grateful owners may buy you a beer that doesn’t make them cheap , not everything is evaluated in purely money terms, and that is a good thing ?

Re: We got admin access to Baseten's production GitHub

#40

Just signed up for strix, is it common for these type of products to want access to my Github repo's? Shouldn't the attack surface be outside them?

You can also just do an external pentest -- Github is for continuous CI/CD coverage
Post reply on HN