The MADBugs work is solid, but what's sticking with me is the autonomy angle — not just finding a vuln but chaining multiple bugs into a working remote exploit without a human in the loop. FreeBSD kernel security research has always been thinner on the ground than Linux, which makes this feel both more impressive and harder to put in context. What's the actual blast radius here — is this realistically exploitable on…
FTA, top: > Attack surface: NFS server with kgssapi.ko loaded (port 2049/TCP) Not sure who would run an internet exposed NFS server. Shodan would know.
Claude wrote a full FreeBSD remote kernel RCE with root shell
71–80 of 128 posts
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#72Earlier quoted context omitted.
You might want to watch this: https://www.youtube.com/watch?v=1sd26pWhfmg Claude is already able to find CVEs on expert level.
Claude is already able to find CVEs on expert level. Does it fix them as fast as it finds them? Bonus if it adds snarky code comments
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#73Thanks for sharing the prompts: https://github.com/califio/publications/blob/main/MADBugs/CV...
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#74This is what Claude is meant to be able to do.
Preventing it doing so is just security theater.
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#75Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…
It found the bug man. You didn't even read the advisory. It was credited to "Nicholas Carlini using Claude, Anthropic".
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#76This requires an SSH to be available? Is it possible to pwn without SSH listening?
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#77Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#78Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…
[flagged]
Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#79Re: Claude wrote a full FreeBSD remote kernel RCE with root shell
#80Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…
You might want to watch this: https://www.youtube.com/watch?v=1sd26pWhfmg Claude is already able to find CVEs on expert level.