Earlier quoted context omitted.
[flagged]
yeah I removed it. I grew up catholic, went to catholic school, was an altar boy, and spent decades in the church but people reading it don't know this. The point is when you instruct it that it's some kind of god-like expert, this is part of the reason that it keeps doing prompt refusal by redoing mistakes despite every insistence by you to the contrary. After all what do you know, It's the expert here! When you use…
I used o3 to find a remote zeroday in the Linux SMB implementation
91–100 of 232 posts
Re: I used o3 to find a remote zeroday in the Linux SMB implementation
#92Earlier quoted context omitted.
A lot of money is all you need~
A lot of burned coal, is what. The "don't blame the victim" trope is valid in many contexts. This one application might be "hackers are attacking vital infrastructure, so we need to fund vulnerabilities first". And hackers use AI now, likely hacked into and for free, to discover vulnerabilities. So we must use AI! Therefore, the hackers are contributing to global warming. We, dear reader, are innocent.
Re: I used o3 to find a remote zeroday in the Linux SMB implementation
#93Re: I used o3 to find a remote zeroday in the Linux SMB implementation
#94Earlier quoted context omitted.
It's amusing to me how people keep trying to apply engineering principles to an inherently unstable and unpredictable system in order to get a feeling of control. Those prompts should be renamed as hints. Because that's all they are. Every LLM today ignores prompts if they conflict with its sole overarching goal: to give you an answer no matter whether it's true or not.
Are you using 2023 LLMs? o3 and Gemini 2.5 Pro will gladly say no or declare uncertainty in my experience
Re: I used o3 to find a remote zeroday in the Linux SMB implementation
#95I have a presentation here on doing it to target zk bugs https://youtu.be/MN2LJ5XBQS0?si=x3nX1iQy7iex0K66
rest of the link is tracking to my (limited) understanding
Re: I used o3 to find a remote zeroday in the Linux SMB implementation
#96Earlier quoted context omitted.
yeah I removed it. I grew up catholic, went to catholic school, was an altar boy, and spent decades in the church but people reading it don't know this. The point is when you instruct it that it's some kind of god-like expert, this is part of the reason that it keeps doing prompt refusal by redoing mistakes despite every insistence by you to the contrary. After all what do you know, It's the expert here! When you use…
As a former alterboy from before there were altergirls can you uncensor.
Re: I used o3 to find a remote zeroday in the Linux SMB implementation
#97Earlier quoted context omitted.
oh interesting, I somehow survived 42 years and didn't know there were 2 words there. I'll check my prompts and give it a go. Thanks.
I'd be weary of the model doing incorrect things too. Nice prompt though! I'll try it out in Roo soon. Now I wonder how the model reasons between the two words in that black box of theirs.
However, as I was testing it, it would do reckless and irresponsible things. After I changed it, as far as bot communication, to "Do-Ur-Inspection" mode and it became radically better.
None of the words you give it are free from consequences. It didn't just discard the "DUI" name as a mere title and move on. Fascinating lesson.
Re: I used o3 to find a remote zeroday in the Linux SMB implementation
#98A small thing, but I found the author's project-organization practices useful – creating individual .prompt files for system prompt, background information, and auxiliary instructions [1], and then running it through `llm`. It reveals how good LLM use, like any other engineering tool, requires good engineering thinking – methodical, and oriented around thoughtful specifications that balance design constraints – for b…
Re: I used o3 to find a remote zeroday in the Linux SMB implementation
#99Earlier quoted context omitted.
A lot of burned coal, is what. The "don't blame the victim" trope is valid in many contexts. This one application might be "hackers are attacking vital infrastructure, so we need to fund vulnerabilities first". And hackers use AI now, likely hacked into and for free, to discover vulnerabilities. So we must use AI! Therefore, the hackers are contributing to global warming. We, dear reader, are innocent.
So basically running a microwave for about 800 seconds, or a bit more than 13 minutes per model? Oh my god - the world is gonna end. Too bad, we panicked because of exaggerated energy consumption numbers for using an LLM when doing individual work. Yes - when a lot of people do a lot of prompting, these 0ne tenth of a second to 8 seconds of running the microwave per prompt adds up. But I strongly suggest, that we cou…
Because I definitely don't care. Energy expenditure numbers are always used in isolation, lest any one have to deal with anything real about them, and always are content to ignore the abstraction which electricity is - namely, electricity is not coal. It's electricity. Unlike say, driving my petrol powered car, the power for my computers might come from solar panels, coal, nuclear power stations, geothermal power hydro...
Which is to say, if people want to worry about electricity usage: go worry about it by either building more clean energy, or campaigning to raise electricity prices.
Re: I used o3 to find a remote zeroday in the Linux SMB implementation
#100Earlier quoted context omitted.
It's amusing to me how people keep trying to apply engineering principles to an inherently unstable and unpredictable system in order to get a feeling of control. Those prompts should be renamed as hints. Because that's all they are. Every LLM today ignores prompts if they conflict with its sole overarching goal: to give you an answer no matter whether it's true or not.
>people keep trying to apply engineering principles to an inherently unstable and unpredictable system in order to get a feeling of control. What's the alternative?