‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. giza182 · · focus · HN ↗
    Interesting that Claude agreed to assist in crafting this exploit. Don’t these models usually reject such requests?
    1. oefrha · · focus · HN ↗
      They did say how:

      > We then placed Claude in an autonomous /goal loop against our own Discourse Cloud instance, proxied through rce.ee/ctf-forum to make it look like a CTF target as Opus refused write exploit for remote instances.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.