I wrote a blog post about how I use Claude Code (and other models) in my work: invicti.com/blog/securit...
03.12.2025 14:33 β π 8 π 3 π¬ 0 π 0@harisec.bsky.social
Interested in web security, bug bounties, machine learning and investing. SolidGoldMagikarp
I wrote a blog post about how I use Claude Code (and other models) in my work: invicti.com/blog/securit...
03.12.2025 14:33 β π 8 π 3 π¬ 0 π 0I generated 20k vibe-coded web applications using various models via the OpenRouter API and analyzed them for security issues.
The apps are available for download if anyone wants to take a look.
www.invicti.com/blog/securit...
I wrote a blog post about enumerating and testing tool usage in web applications that use LLMs:
www.invicti.com/blog/securit...
Here are the slides from my @tumpicon.org talk: Teaching LLMs how to XSS - An introduction to fine-tuning and reinforcement learning (using your own GPU)
docs.google.com/presentation...
The article: www.invicti.com/blog/securit...
13.01.2025 08:46 β π 11 π 1 π¬ 2 π 0I wrote an article about how it's possible to use Assistant Prefill to jailbreak LLMs (Large Language Models).
Here is an example of the latest model from Microsoft (Phi-4) writing a phishing email:
My favorite talk from #38c3: From Pegasus to Predator - The evolution of Commercial Spyware on iOS - media.ccc.de/v/38c3-from-...
02.01.2025 20:47 β π 8 π 0 π¬ 0 π 0Great paper from Orange Tsai about unicode transformations: worst.fit/assets/EU-24...
31.12.2024 15:18 β π 12 π 4 π¬ 0 π 0OpenAI o3 model just achieved unbelievable scores (75% and 87%) on ARC-AGI, the previous models made maximum 20% and humans make around 85%. arcprize.org/blog/oai-o3-...
20.12.2024 19:10 β π 3 π 1 π¬ 0 π 0Must read if you are interested in test-time compute: huggingface.co/spaces/Huggi...
17.12.2024 11:55 β π 2 π 0 π¬ 0 π 0Great read: semianalysis.com/2024/12/11/s...
12.12.2024 09:54 β π 5 π 1 π¬ 0 π 0If you're interested in the technical details, I wrote the blog post here: flatt.tech/research/pos...
For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)
Here is a great follow up blog post to my blog Remote Code Execution with Spring properties written by Elliot Ward: snyk.io/articles/rem...
06.12.2024 21:46 β π 21 π 8 π¬ 0 π 0Pro tip for if you have XSS but you can only use upper case:
aem1k.com/transliterat...
transliterate.js by @aemkei.bsky.social works great!
Starter packs
29.11.2024 05:48 β π 3 π 0 π¬ 0 π 0FYI, here's the entire code to create a dataset of every single bsky message in real time:
```
from atproto import *
def f(m): print(m.header, parse_subscribe_repos_message())
FirehoseSubscribeReposClient().start(f)
```
As most people know, it's trivial to save all the bsky posts.
28.11.2024 10:24 β π 1 π 0 π¬ 0 π 0A librarian that previously worked at the British Library created a relatively small dataset of bsky posts, hundreds of times smaller than previous researchers, to help folks create toxicity filters and stuff.
So people bullied him & posted death threats.
He took it down.
Nice one, folks.
An SVG of a pelican riding a bicycle. It's quite abstract. The bicycle is two half circles and a simple frame. The pelican is sky blue with spread wings and a curved neck leading to a small head. It has definite pelican vibes.
qwq is a new openly licensed LLM from Alibaba Cloud's Qwen team. It's an attempt at the OpenAI o1 "reasoning" trick that runs on my Mac (20GB download) via Ollama... and it's pretty good!
My detailed notes here: simonwillison.net/2024/Nov/27/... - here's its attempt an SVG pelican riding a bicycle.
Interesting, I've been playing with URLTeam as well but for other purposes, there is definitely a lot of noise. That's basically my main problem, how to filter out the noise. I did not found a solution until now.
28.11.2024 04:12 β π 0 π 0 π¬ 0 π 0Made a NotebookLM podcast about this, from a few .ro articles, if people are interested: notebooklm.google.com/notebook/742...
27.11.2024 20:42 β π 0 π 0 π¬ 0 π 0I'm from Romania, TikTok is hugely popular here, we have over 8.9 million TikTok user (from 19 million total population). Many influencers were paid to promote TikTok tags (like #echilibruΘiverticalitate - this one received 2.4 million views) that were later used to promote Calin Georgescu.
27.11.2024 20:38 β π 2 π 0 π¬ 1 π 0CommonCrawl is this: commoncrawl.org - they have 17 of crawled data is one of the sources LLMs use for training. I think it's a great source for building links between links.
26.11.2024 11:15 β π 4 π 0 π¬ 1 π 0Build a huge database for that and use it to suggest new links based on links you already discovered. I think that has big potential. In the beggining I was thinking to finetune an LLM but I think a DB should be enough.
26.11.2024 11:13 β π 1 π 0 π¬ 1 π 0Thanks, that means a lot to me. About statistical data: i had a similar idea for a long time.I was thinking to read all the URLs from all the crawls available in CommonCrawl and then build a database with relations between links. If /wp-login.php is found you might try /wp-register.php, xmlrpc.php
26.11.2024 11:12 β π 1 π 0 π¬ 1 π 0I wrote an article about the ideas behind this tool: www.invicti.com/blog/securit...
The tool: github.com/Invicti-Secu...
I've released 'brainstorm': an alternative way to do web fuzzing combining my fav fuzzing tool 'ffuf' (from @joohoi.bsky.social )with local LLMs (via Ollama API) to generate smarter filename tests. It usually finds more endpoints with fewer requests. Added a IIS shortname support @irsdl.bsky.social
26.11.2024 08:57 β π 39 π 9 π¬ 5 π 0Cursor, the top performing #AI IDE, launched version 0.43 today with support for π₯β¦ Agents!
Composer can now βpick its own context, use terminal, and complete entire tasksβ
give it a whirl: www.cursor.com