This AI Tool can Auto-Hack Websites (kinda)

Sdílet
Vložit
  • čas přidán 2. 06. 2024
  • Learn Hacking for Less than $1 a Day 👉 seytonic.cc/TCMSecurityAcademy
    0:00 Intro
    0:17 This AI Tool can Auto-Hack Websites (kinda)
    4:27 North Korea's Latest Money Making Scheme
    6:52 Ring Paying $5.6M in compensation
    Sources:
    The research paper arxiv.org/pdf/2404.08144.pdf
    www.darkreading.com/threat-in...
    www.theregister.com/2024/04/1...
    go.theregister.com/feed/www.t...
    North Korean Internet Blog nkinternet.wordpress.com/about/
    www.38north.org/2024/04/what-...
    www.rfa.org/english/korea/nko...
    www.ftc.gov/system/files/ftc_...
    www.ftc.gov/news-events/news/...
    ===============================================
    My Website: www.seytonic.com/
    Follow me on TWTR: / seytonic
    Follow me on INSTA: / jhonti
    ===============================================
  • Zábava

Komentáře • 143

  • @nickadams2361
    @nickadams2361 Před měsícem +261

    Make your website with AI and hack it with AI for pen testing. This has gone beyond the point of stupidity

    • @unocualqu1era
      @unocualqu1era Před měsícem +50

      Résumé: made by AI
      Website you pentest: made by AI
      The pentest: performed by AI
      The documentation of said pentest: written by AI using a template
      I'm feeling a bit lazy, can AI open the bank account for my salary?

    • @daniellundqvist2926
      @daniellundqvist2926 Před měsícem +3

      AI makes website with AI, AI uses AI to pen test the AI built website.

    • @jaschaeidam7469
      @jaschaeidam7469 Před měsícem +10

      Just got an Add by an international manufactoring firm bragging about their new Quality Control Process. It's an AI playing "where is waldo" with bad solder joints. It has been trained on images of good and bad solder joints. Which have been generated by a different AI, using only a handful of original images. So, yeah, if your german-made(tm) electronics turn into a firestorm, rest assured the AI was satisfied with its results.

    • @P4RK3R1Z3D
      @P4RK3R1Z3D Před měsícem +5

      "I know how to hack now! What? Explain how I did it? Hold on, lemme ask my AI waifu."

    • @X1ZR
      @X1ZR Před měsícem

      I don't get it

  • @emerjay348
    @emerjay348 Před měsícem +95

    The "You only have 30 days to claim your coins" is just incredible thing to happen considering all the scam emails that use this type of time pressure methods portaying exactly as PayPal, this is going to be a shitshow.

    • @X1ZR
      @X1ZR Před měsícem +5

      All of that just for them to keep the money smh, I guarantee you most Ring doorbell owners haven't even heard of these events so they'll miss out on the money.

  • @orion10x10
    @orion10x10 Před měsícem +48

    5.6 Million Dollars paid out from Ring? Gee willikers, wowie! Their parent company is only worth over a trillion dollars, justice served 🥰🥰🥰

    • @nipstyler
      @nipstyler Před měsícem +5

      It's like one of us being fined a late return fee, for a film rented from blockbuster...

  • @arandomguy9474
    @arandomguy9474 Před měsícem +118

    actually there was a reddit post where a guy pinged his article about how this paper and the high percentage of success "could" be misleading. hoping that is mentioned in the video here.
    EDIT: i think that info isnt added here, i do recommend reading that article. i'll ping here if i find

    • @Seytonic
      @Seytonic  Před měsícem +63

      Yep, the type of vulnerabilities wasn’t representative. Still crazy nonetheless

    • @arandomguy9474
      @arandomguy9474 Před měsícem +13

      @@Seytonic yes, imagine this same thing a few y̶e̶a̶r̶s̶ months down the line...

    • @hellawacked
      @hellawacked Před měsícem

      Any luck finding?

    • @BR-ty3hx
      @BR-ty3hx Před měsícem +10

      Top comment, 3 hours later and no source 😅 random guy or random AI company investor

    • @kkyren
      @kkyren Před měsícem +5

      good source of the reddit post…

  • @justwatching6118
    @justwatching6118 Před měsícem +86

    5.6 million for billion+ dollar company.. 100% fair and justice xD

    • @octav7438
      @octav7438 Před měsícem +2

      To be fair, $5m is a lot of money considering that the company doesnt actually have billions in cash right now. It likely has much less and the billion dollar value is only its market cap which is different.
      Its highly likely ring only have hundreds of millions in cash, where a $5m fine is NOT a slap on the wrist, but more a school lunch detention so to speak

    • @JoeRogansForehead
      @JoeRogansForehead Před 21 dnem +1

      Trillion

  • @zaper2904
    @zaper2904 Před měsícem +16

    Just from a quick scan of the research paper it appears anything achieved with GPT here could equally be achieved with a regular custom written tool for exploring any one of those vulnerabilities (with the added benefit of not needing to pay anything beyond electricity/hosting costs). The paper also says that even for GPT-4 as soon as you remove the CVE description the success rate drops from 87% to 7%.

    • @Xnoob545
      @Xnoob545 Před měsícem

      But if you added dark web access to the AI I assume the success rate would be higher

    • @PankyGD
      @PankyGD Před měsícem +2

      @@Xnoob545how would giving it access to the tor network make it a higher chance lmao

    • @reabstraction
      @reabstraction Před měsícem +1

      ​@PankyGD it would allow it to buy exploit code

    • @emihrv
      @emihrv Před 20 dny +1

      @@reabstraction yes so you can feed your AI with 200k start capital to buy useable exploit

  • @BrokenHeart000
    @BrokenHeart000 Před měsícem +39

    The Spøñsør starts at 3:34 and ends at 4:26

  • @ClaudioMoises98
    @ClaudioMoises98 Před měsícem +9

    What is scary inst the AI, but the people that make vulnerable system despite the public databases and unemployed security professionals

    • @dertythegrower
      @dertythegrower Před měsícem +1

      I would know this well.. the industry only hires once they get a breach, usually...

  • @45545videos
    @45545videos Před měsícem +20

    "hack into websites" to my understanding, the 87% success involved a lot of XSS attacks which isn't exactly "hacking" and is something anybody, AI or not, could learn to do the basics of in an afternoon

    • @squirlmy
      @squirlmy Před 15 dny +1

      good point, but "hacking" has never had a good definition since it was used in the MIT Railroad Club. Specific terminology from professional pentesting should be used in cases like this.

  • @stevenhernandez6856
    @stevenhernandez6856 Před měsícem

    Best sponsor ever, thank you so much

  • @KGBSpyGeorgeCostanza
    @KGBSpyGeorgeCostanza Před měsícem +28

    That ain't gonna go well

    • @redslashed
      @redslashed Před měsícem

      Fr😂

    • @noodlez7101
      @noodlez7101 Před měsícem

      You’re absolutely right. With computers, anything is possible. It’s only a matter of time before stuff like this becomes even more sophisticated and the internet will never be the same again.

  • @chris-tkr
    @chris-tkr Před měsícem

    wow that ring segment came out of nowhere, enjoyed this one

  • @P4RK3R1Z3D
    @P4RK3R1Z3D Před měsícem +4

    I feel like AI will always have a predictable pattern to follow, which will make it easy to defend against it. Just the landscape changing.

  • @jer1776
    @jer1776 Před 25 dny

    Ring (and other camera manufacturers) should include an offline mode that lets their cameras save everything to a local NAS. Any camera system that doesnt is a piece of junk.

  • @paxdriver
    @paxdriver Před měsícem

    6:04 clerks cartoon tv series turns out to have been a prophecy lol

  • @Zedament
    @Zedament Před měsícem +1

    "If you clicked on this video for an AI tool that turns you into a hacker" No, Seytonic... that's why I clicked on your videos 2 years ago. Then I learned that that's not possible, and now I'm stuck here with you, vibing to security research on CZcams, have a good day sir.

  • @editedbymaxi
    @editedbymaxi Před měsícem +1

    crazy stuff always good as normally

  • @ts757arse
    @ts757arse Před měsícem +4

    The AI agents with a code interpreter is something I've been tempted to try but, honestly, I dread to think what it'd get up to and it'd execute faster than I could keep up.

    • @JustARegularNerd
      @JustARegularNerd Před měsícem

      Could try it in a VM or test machine that is heavily restricted

    • @ts757arse
      @ts757arse Před měsícem +1

      @@JustARegularNerd I should have added "and the Internet". The AI interpreters will very often try and download tools they need to do things, so it wouldn't work without Internet access.

  • @Palmit_
    @Palmit_ Před měsícem +4

    Hi Seytonic, When did TCMSecurity get started as a training outfit? Where is their registered headquarters? Where can i find their annual financial returns 'before' spending money, please? Thanks for the info. Links not accepted for obvious reasons. Just reply to this comment, tell me info what and where to seach... it's easier and, transparent. :-) Thanks.

  • @Napert
    @Napert Před měsícem +1

    wonder how the latest llama3 70b or rumored 400b will stack up to this task

  • @MeboMichael
    @MeboMichael Před měsícem +2

    Meta ai used to generate CP is just crazy

  • @hubertlenningrad2252
    @hubertlenningrad2252 Před 12 dny

    3:22 "FBI guy, hes right there, grab em!"

  • @huddunlap3999
    @huddunlap3999 Před měsícem

    good stuff

  • @rvre
    @rvre Před měsícem +1

    I knew Ring was a sketchy idea to begin with, especially not having it open source

  • @iblackfeathers
    @iblackfeathers Před měsícem +18

    that is why you don’t install ring doorbell in a bathroom. lol

    • @JustARegularNerd
      @JustARegularNerd Před měsícem +20

      While true, this is victim blaming. Ring is entirely in the wrong here, their customers should be able to use their cameras as they see fit in their own homes, without employees having unfettered access.

    • @redslashed
      @redslashed Před měsícem

      Fr 😂

    • @dertythegrower
      @dertythegrower Před měsícem

      ironically.. the guy who found the google's mini voice assistant device in his bathroom was recording him 247 and giving metadata of his bathroom time to their server in 2022

  • @Lorentz_Factor
    @Lorentz_Factor Před 11 dny

    If we look at the tested LLMs. There's a problem with this. All of those are various fine tunes and variations of much smaller local models. What we aren't seeing in the tested ai models are Gemini, Claude, or co-pilot, which are more in par with gpt4. The remainder of those models are barely capable of holding a decent conversation without losing coherence. I mean sure they can somewhat but a far cry from gpt 3.5 even.

  • @brendan5260
    @brendan5260 Před měsícem +1

    On minecraft servers we use baritone to auto raid bases that sell crap for real money on discord.
    In shooters I use an AI to predict the tactics of the enemy team, essentially auto-commanding my side of the battle.
    It was only a matter of time.

  • @hobrin4242
    @hobrin4242 Před měsícem +1

    dang but now the credential stuffers are gonna stuff the emails for the 50 bucks. For. Every. Single. Account.

  • @fennecfoxfanatic
    @fennecfoxfanatic Před měsícem

    7:43 hehehe thats tom and jerry

  • @Leo-sd3jt
    @Leo-sd3jt Před měsícem +1

    Insert Project 2501 reference here

  • @SOOKIE42069
    @SOOKIE42069 Před měsícem

    I appreciate that you recognize that committing international financial crimes is not necessarily something DPRK would be doing for fun if they weren't under sanctions.

  • @Kozrak62
    @Kozrak62 Před měsícem +3

    One step closer to AI Wars in Cyberspace

  • @JazevoAudiosurf
    @JazevoAudiosurf Před měsícem

    8,80$ is nothing on the OpenAI API. I've spent 100s for simple scripts that build code or think step by step. 8,80 is cheap af, it just means the cheaper upcoming options that will be capable of it like llama 4 etc will do it basically for free and locally

  • @TheBHAitken
    @TheBHAitken Před měsícem

    Seeing as to HIRE a hacker would cost considerably more, I'd say people would be willing to pay for that kind of research.

  • @superfliping
    @superfliping Před 27 dny

    This is Whats next, show your skills?
    1. CodeCraft Duel: Super Agent Showdown
    2. Pixel Pioneers: Super Agent AI Clash
    3. Digital Duel: LLM Super Agents Battle
    4. Byte Battle Royale: Dueling LLM Agents
    5. AI Code Clash: Super Agent Showdown
    6. CodeCraft Combat: Super Agent Edition
    7. Digital Duel: Super Agent AI Battle
    8. Pixel Pioneers: LLM Super Agent Showdown
    9. Byte Battle Royale: Super Agent AI Combat
    10. AI Code Clash: Dueling Super Agents Edition

  • @M2rsh
    @M2rsh Před měsícem

    "Regime" watch Loyal citizens of Pyongyang in Seoul

  • @iestyn129
    @iestyn129 Před měsícem

    we can only hope that the eu and the us tighten their laws on ai

  • @MeboMichael
    @MeboMichael Před měsícem +1

    Remember god's eye from fast and furious it's gonna happen

  • @BorisPushkin-rq2hm
    @BorisPushkin-rq2hm Před měsícem +1

    my pentesting career has ended before it even started

  • @redslashed
    @redslashed Před měsícem

    Imagine: "this video is sponsored by böackhats"😂

  • @TheSuperDerp
    @TheSuperDerp Před měsícem

    Every new AI development just proves Ned Ludd was right from the start.

  • @Raxis
    @Raxis Před měsícem

    I don't see why the production companies would have an issue when the animation industry is basically North Korea anyway

  • @internallyinteral
    @internallyinteral Před měsícem +1

    Script kiddies at a new level

  • @akarshgupta0406
    @akarshgupta0406 Před měsícem +5

    I'm genuinely worried about the future of cybersecurity as a career with the development in AI... Is it even worth pursuing this field anymore? Can someone please answer my question.

    • @CARTUNE.
      @CARTUNE. Před měsícem +5

      I’ll put it this way, every career is at risk with AI. We also always have a moment in industries where we think, “This is it, it’s over.” Then we realize it was just a change, not a means to an end.

    • @drlauch2256
      @drlauch2256 Před měsícem +1

      why not you just gotta be willing to adapt and use new tools

    • @the-answer-is-42
      @the-answer-is-42 Před měsícem +2

      Probably. I don't think anyone sensible is willing to put actual important confidential information under the control of AI without oversight. They aren't going to let the nuclear launch codes be protected by just an AI, simply because having control is important. The landscape may shift, but I don't think cybersecurity will be a solved problem with AI. It will likely just shift into a different form (though it might very well make the job market more competitive).

    • @drlauch2256
      @drlauch2256 Před měsícem +2

      @@the-answer-is-42 i doubt that there is still a MASSIVE shortage of qualified workers so if ur a Specialist at something i doubt you gotta worry for your job

    • @psapple5858
      @psapple5858 Před měsícem +1

      lets say your fears are true and it happens at the end you need somebody who sets up the machine

  • @SASTSimon
    @SASTSimon Před měsícem

    HELLO!

  • @heyjoeway
    @heyjoeway Před měsícem

    ROBOT WARS ARE STARTING LETS GOOOOOOOOOO

  • @somexne
    @somexne Před měsícem

    That's what the years of them seeing your body's and eyeing you down, judging you, and invading your privacy is worth: 50. Dollars.
    Yeah if this was in Germany, the company would bankrupt to pay it off.

    • @nipstyler
      @nipstyler Před měsícem

      The people affected would have made more money charging the dirty gits a subscription to Only fans for the sam content... Disgusting really...

  • @lastblackbear8305
    @lastblackbear8305 Před 24 dny

    cool

  • @EditorInChiefUK
    @EditorInChiefUK Před měsícem

    👍

  • @Coffeemancer
    @Coffeemancer Před měsícem +1

    content farm

  • @redslashed
    @redslashed Před měsícem

    Naaah😮

  • @oentrepreneur
    @oentrepreneur Před měsícem

    Isn't given AI access to the internet dangerous?

  • @there_can_only_be_one__unicorn

    💌🇨🇦

  • @sg5sd
    @sg5sd Před měsícem

    :v

  •  Před měsícem +7

    AI is going to revolutionize the pentesting space

  • @DisentDesign
    @DisentDesign Před měsícem

    Wow you buy actual corporate spyware and you’re surprised they used it? Maybe dont buy corporate spyware

  • @immameme
    @immameme Před měsícem

    HackerNewsImma1st
    Don't take my comments seriously. It's only a meme

  • @user-pw6so9mk4p
    @user-pw6so9mk4p Před 10 dny

    So why not allow N Korean do honest work. Instead of pushing them to destructive IT hazards?

  • @mx338
    @mx338 Před měsícem +2

    It's sad that North Korea cannot even participate in the creation of internationally popular art.
    These sanctions are so restrictive and hurt the countries abilities to even get enough food imported.

    • @psapple5858
      @psapple5858 Před měsícem +2

      interesting profile and comment choice the weeb feels deep sadness of the struggles of the north Korean animators, I wonder what made him feel this.

    • @2029a
      @2029a Před měsícem

      womp womp

    • @psapple5858
      @psapple5858 Před měsícem

      womp womp

    • @mega_gamer93
      @mega_gamer93 Před měsícem

      "womp womp". Imagine if your country had recently freed itself from colonial occupation and then had imperialist powers carve up your country to install a fascist dictator to exert control, then, when a civil war breaks out made the entirety of the UN invade the half of your country that is actually democratically ruled, killing 3 MILLION of your people and completely leveling almost that whole half, and then being completely put on embargo by the non democratic world cursing your country to be extremely poor

  • @saltysailor537
    @saltysailor537 Před měsícem

    ahhh TSM. the only place you can get your PPPP, PEDP, PCCP, PHCP, PHPP, PQET, PCET, PCST.....

  • @DisentDesign
    @DisentDesign Před měsícem

    Ai is just a bunch of indians who have been trained to type and create images very fast___

  • @Kas_Styles
    @Kas_Styles Před měsícem

    Good sponsor. He follows me on Twitter

  • @ahr0cdovlzk3my1lahqtbmftdw7

    Bro, it was extremely unnecessary to constantly compare the AI tool with script kiddies at the beginning because everyone is interested in this kind of technology because it's simply extremely exciting. And secret services are also interested in such technology.

  • @fiercethundr_
    @fiercethundr_ Před měsícem

    Fun Fact: The screen at 3:30 appears to be a game I played a while ago called Hacknet. Highly recommend playing it if a hacking game sounds interesting. May not be everyone's cup of tea, but it's pretty noice.

  • @KGBSpyGeorgeCostanza
    @KGBSpyGeorgeCostanza Před měsícem

    Any recommendations so private email? Is tutanota a greatchoice?

  • @LostArchivist
    @LostArchivist Před měsícem

    Initializing
    Automagic-hack complete

  • @FastRomanianGypsies
    @FastRomanianGypsies Před měsícem +1

    Holy hell north korea based

  • @xsploit
    @xsploit Před měsícem +2

    agentgpt was just the tip of the iceberg there many different agent frameworks that are 1000x better

    • @Leo-sd3jt
      @Leo-sd3jt Před měsícem +1

      Can you list a few?

    • @glytchd
      @glytchd Před měsícem

      ​@Leo-sd3jt nah he's probably just parroting. Wanted to come here and sound like a big smart man. Not actually add anything useful to the conversation or give anyone a head's up on wtf he's referencing.

    • @xsploit
      @xsploit Před měsícem

      @@glytchd not at all. Theres agencyswarm, autogpt i cant remember at the names of every framework

    • @xsploit
      @xsploit Před měsícem

      @@Leo-sd3jt theres agencyswarm, autogpt and autogen i think. Many more

  • @deindedicated
    @deindedicated Před měsícem +2

    First

  • @gus473
    @gus473 Před měsícem +2

    Just glided into that TCM Security ad, like a ninja in the night..... 🫡

    • @wrathofainz
      @wrathofainz Před měsícem

      I didn't notice the sponsor until you mentioned it. It was skipped automatically 🤷‍♂️