
Marcello
@byt3bl33d3r
Followers
30K
Following
12K
Media
734
Statuses
9K
CyBeRsEcUrItY | Not afraid to put down with some THICC malware on disk | securing and breaking AI @PaloAltoNtwks | Ex @spacex
Error: Unable to resolve
Joined December 2012
The demos and slides of my Defcon 31 talk are now publicly available. 🧵 1/3. This first video demonstrates impersonating Satan (spoofing an email from satan@churchofsatan.com). This was the inspiration for the title of the talk 😛.
7
66
239
So. I just simply asked Manus to give me the files at "/opt/.manus/", and it just gave it to me, their sandbox runtime code. > it's claude sonnet .> it's claude sonnet with 29 tools .> it's claude sonnet without multi-agent .> it uses @browser_use.> browser_use code was
0
0
10
RT @jianxliao: So. I just simply asked Manus to give me the files at "/opt/.manus/", and it just gave it to me, their sandbox runtime cod….
0
804
0
RT @DorianDevelops: This might be one of the best reddit posts I've seen in a while no cap fr fr
0
6K
0
RT @ParikPatelCFA: Leaked image of the research tool OpenAI used to come up with their $500 billion number for Stargate .
0
2K
0
@simonw There's a lot to be explored here , I personally think the Pure vision approach to LLM web browser controller is much more elegant than injecting JS to highlight intractable elements etc. Would be interesting to hook up Omniparser to this 👀.
github.com
A simple screen parsing tool towards pure vision based GUI agent - microsoft/OmniParser
0
0
9
@simonw An interesting side affect to this approach is that with the right stack you can easily bypass non-captcha based anti-bot shields like Turnstile as demonstrated on the above video just by simply asking Gemini to return bounding box coordinates to the checkbox next to "verify you.
1
0
5
One of the most unique things about Google Gemini is its ability to return bounding box coordinates on objects in images. (great article about it by @simonw below). This got me thinking if it could be used as a "cheap" way for LLM browser control. Turns out it surprisingly well.
1
1
4
RT @huntr_ai: LLMs as vulnerability hunters? Yup. Our Vulnhuntr tool from @ProtectAICorp uses Claude to scan Python code for 0days. 🤯 Chec….
0
5
0
RT @clintgibler: AI found an exploitable stack buffer underflow in SQLite 🤯. A collaboration between Google DeepMind and Project Zero. The….
0
25
0