awful.systems
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
David GerardMA to TechTakesEnglish ·
edit-2
2 years ago

in absolutely the funniest outcome so far, you can send data to an LLM that pops a Remote Code Execution vulnerability

mastodon.social

external-link
message-square
13
link
fedilink
106
external-link

in absolutely the funniest outcome so far, you can send data to an LLM that pops a Remote Code Execution vulnerability

mastodon.social

David GerardMA to TechTakesEnglish ·
edit-2
2 years ago
message-square
13
link
fedilink
Kenn White (@kennwhite@mastodon.social)
mastodon.social
external-link
Attached: 3 images Incredible research at BlackHat Asia today by Tong Liu and team from the Institute of Information Engineering, Chinese Academy of Sciences (在iie.ac.cn 的电子邮件经过验证) A dozen+ RCEs on popular LLM framework libraries like LangChain and LlamaIndex - used in lots of chat-assisted apps including GitHub. These guys got a reverse shell in two prompts, and even managed to exploit SetUID for full root on the underlying VM!

courtesy @self

  • preprint: https://arxiv.org/pdf/2309.02926
  • blackhat abstract: https://www.blackhat.com/asia-24/briefings/schedule/index.html#llmshell-discovering-and-exploiting-rce-vulnerabilities-in-real-world-llm-integrated-frameworks-and-apps-37215
  • Tong Liu’s related research: https://scholar.google.com/citations?hl=en&user=egWPi_IAAAAJ

can’t wait for the crypto spammers to hit every web page with a ChatGPT prompt. AI vs Crypto: whoever loses, we win

  • Ephera@lemmy.ml
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 years ago

    Yeah, that was exactly my intention.

TechTakes

techtakes

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !techtakes@awful.systems

Big brain tech dude got yet another clueless take over at HackerNews etc? Here’s the place to vent. Orange site, VC foolishness, all welcome.

This is not debate club. Unless it’s amusing debate.

For actually-good tech, you want our NotAwfulTech community

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 70 users / day
  • 264 users / week
  • 795 users / month
  • 4.65K users / 6 months
  • 105 local subscribers
  • 2.35K subscribers
  • 1.17K Posts
  • 34K Comments
  • Modlog
  • mods:
  • David Gerard
  • BE: 0.19.12
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org