Profile for joern

Display name
joernchen :cute_dumpster_fire:
Username
@joern@threatactor.club
Role
admin

About joern

Bio

Your mom's favorite hacker!

My other account is @joernchen

Stats

Joined
Posts
635
Followed by
1120
Following
259

Recent posts

That little string
ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86

(see https://platform.claude.com/docs/en/test-and-evaluate/strengthen-guardrails/handle-streaming-refusals#implementation-guide ) is so much fun. I wonder when Anthropic will regret this and remove it.

Also I obviously wonder what else is there in terms of MAGIC_STRINGs which aren't documented.

Hat tip to @michenriksen for pointing me to this.

How many hours have you personally wasted by disassembling a binary file with the wrong CPU setting?

Poll closed , 21 votes total
  • Option 1, I don’t do reversing
    28.57% , 6 votes
  • Option 2, a few
    33.33% , 7 votes
  • Option 3, a lot
    4.76% , 1 vote
  • Option 4, too much
    33.33% , 7 votes
Katzen & Bass
Toggle visibility

Denkt dran Kinders:

Erst wenn der Subwoofer die Katze inhaliert, fickt der Bass richtig übel!

So the big thing in Bug Bounty now seems to be letting an LLM generate artificial PoCs for "issues" within a trust boundary.

Basically what's submitted as proof would be a snippet of code demonstrating a library "vulnerability" where all further context is left out.

Caffeine done like IDGAF, my 'Zero Fucks Given' cup with a double (maybe triple) Espresso Macchiato and some ice cold Club Mate.

¯\(ツ)

I’m slightly mad….

What stands in my way of having a nice vulnerability is the apparent inability of certain LLMs to emit \r (carriage return). For some reason they keep emitting \n (newline) instead.

I found myself posting this little comic at work A LOT currently.

It's really interesting, especially in the context of (agentic) AI, how features can be bugs or even vulnerabilities and vice versa, depending on whom you ask about it. It's always the context which matters and a lot is personal preference/risk appetite of whoever is using the 'feature'.

I tend to advocate for secure defaults with an option to let anyone choose if they want to take the risk of e.g. AI 'yolo' mode.

So I just met someone in person a few days ago. They said: "Oooh you're busy looking into AI stuff lately? That's good so you wont bother $THING with vuln reports! :P"

Guess where I just found a nice vuln :trollface:

Ich muss sagen ich bin schon ein bisschen beeindruckt wie smooth eine Onlinezulassung für ein Kfz läuft, ABER wenn ein einfaches & in den Eingabedaten so eine Fehlermeldung auslöst triggert mich das ein bisschen zu sehr ;). :cute_dumpster_fire:

Ich hab dann aber mal nicht an dem Ast gesägt auf dem ich saß.

Today I have a more serious topic than usual, please consider reposting for reach:

My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder (myoclonus and/or spasms) to finally find a cause and, above all, an effective therapy. The symptoms are bothering our son ever since he’s born, now for more than nine years, seriously affecting his sleep. The usual processes and medical contact points have failed us unfortunately and he seems stuck in this condition.

We’re based in Berlin, Germany but really any contact with a specialist who would be willing to take on this case we’d be grateful for!

To reach use you can DM me or contact us via Email at unclear.condition@gmail.com