@whoareme33 i totally agree! ive been using mine as a “jarvis” assistant versus letting it run fully autonomously. it’d be cool to find a true autonomous workflow that works but so far manual with “jarvis” has been producing results for me.
the meta exploits just goes to show that incorporating AI, even in massive companies, blows the door wide open for vulnerabilities..
i feel like this is just the beginning of what’s to come. I mean who thinks to trick AI using blank characters, not the developers obviously.. 😂
@yamuradotdev@Hacker0x01 remain consistent! as long as you remain consistent with practicing and hunting you WILL find a real bug! I recommend PortSwigger labs for sure and use AI to build labs and attempt to solve them!
@dennis_malware@Hacker0x01 yes, in a way. i discovered HTMLi that i then asked my ai assistant to help find regex bypasses to bypass a filter into XSS!
actually quite impressive.. someone prompt injected grok and stole $200k of $DRB from Groks wallet to themselves. He had been trying since 2025 if you C search the wallet address.
found this within a day of setting up a personalized claude code environment based on my H1 findings and other findings i have stored, i asked it for a program to manually review.. reviewed and found a html injection in signup that i used cc to help upgrade it to stored xss.
stored xss on main domain, feels good :) they dropped severity cuz the payload i submitted "required user interaction" but i replied saying i can get it to fire w/o user interaction, will see what is said.
"User interaction is required. Clicking a button. Scope is not changed."