Cybergaucho

@xy
467 Followers
217 Following
123 Posts
Software Developer - Security researcher - Cybergaucho - Parody account - @ortegaalfredo on twitter.
๐˜™๐˜ฆ๐˜ฎ๐˜ฆ๐˜ฎ๐˜ฃ๐˜ฆ๐˜ณ, ๐˜ฐ๐˜ถ๐˜ณ ๐˜ข๐˜ฎ๐˜ฃ๐˜ช๐˜ต๐˜ช๐˜ฐ๐˜ฏ ๐˜ช๐˜ด ๐˜ต๐˜ฐ ๐˜ถ๐˜ฏ๐˜ฅ๐˜ฆ๐˜ณ๐˜ด๐˜ต๐˜ข๐˜ฏ๐˜ฅ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ท๐˜ถ๐˜ญ๐˜ฏ๐˜ฆ๐˜ณ๐˜ข๐˜ฃ๐˜ช๐˜ญ๐˜ช๐˜ต๐˜บ ๐˜ธ๐˜ช๐˜ต๐˜ฉ ๐˜ฐ๐˜ถ๐˜ณ ๐˜ฃ๐˜ณ๐˜ข๐˜ช๐˜ฏ, ๐˜ฏ๐˜ฐ๐˜ต ๐˜ฅ๐˜ช๐˜ด๐˜ค๐˜ฐ๐˜ท๐˜ฆ๐˜ณ ๐˜ฌ๐˜ฏ๐˜ฐ๐˜ธ๐˜ฏ ๐˜ง๐˜ญ๐˜ข๐˜ธ๐˜ด ๐˜ฐ๐˜ณ ๐˜ด๐˜ฆ๐˜ณ๐˜ท๐˜ฆ ๐˜ข๐˜ด ๐˜ข ๐˜ณ๐˜ฆ๐˜ค๐˜ฐ๐˜ณ๐˜ฅ ๐˜ฐ๐˜ง ๐˜ฉ๐˜ฐ๐˜ธ ๐˜ฐ๐˜ถ๐˜ณ ๐˜ด๐˜ค๐˜ณ๐˜ช๐˜ฑ๐˜ต๐˜ข ๐˜ข๐˜ณ๐˜ฆ ๐˜ฐ๐˜ถ๐˜ต ๐˜ฐ๐˜ง ๐˜ค๐˜ฐ๐˜ฏ๐˜ต๐˜ณ๐˜ฐ๐˜ญ. ๐˜ž๐˜ฆ ๐˜ข๐˜ณ๐˜ฆ ๐˜ฏ๐˜ฐ๐˜ต ๐˜ช๐˜ฏ ๐˜ข๐˜ฃ๐˜ญ๐˜ฆ ๐˜ฐ๐˜ง ๐˜ค๐˜ณ๐˜ฆ๐˜ข๐˜ต๐˜ช๐˜ฏ๐˜จ ๐˜ฆ๐˜ฏ๐˜ฆ๐˜ณ๐˜จ๐˜บ ๐˜ฐ๐˜ณ ๐˜ฎ๐˜ข๐˜ต๐˜ต๐˜ฆ๐˜ณ, ๐˜ฅ๐˜ฆ๐˜ข๐˜ญ๐˜ช๐˜ฏ๐˜จ ๐˜ธ๐˜ช๐˜ต๐˜ฉ ๐˜”๐˜ข๐˜ค๐˜ฉ๐˜ช๐˜ฏ๐˜ฆ ๐˜“๐˜ฆ๐˜ข๐˜ณ๐˜ฏ๐˜ช๐˜ฏ๐˜จ ๐˜ฐ๐˜ณ ๐˜ด๐˜ค๐˜ช๐˜ฆ๐˜ฏ๐˜ต๐˜ช๐˜ง๐˜ช๐˜ค ๐˜ณ๐˜ฆ๐˜ด๐˜ฆ๐˜ข๐˜ณ๐˜ค๐˜ฉ, ๐˜ข๐˜ฏ๐˜ฅ ๐˜ฏ๐˜ฆ๐˜ช๐˜ต๐˜ฉ๐˜ฆ๐˜ณ ๐˜ค๐˜ณ๐˜ฆ๐˜ข๐˜ต๐˜ช๐˜ฏ๐˜จ ๐˜ฏ๐˜ฆ๐˜ธ ๐˜ค๐˜ฐ๐˜ฅ๐˜ฆ ๐™ฃ๐™ค๐™ง ๐™š๐™ญ๐™ฅ๐™ก๐™ค๐™ž๐™ฉ๐™จ, ๐™ฃ๐™ค๐™ง ๐™™๐™€๐™ซ๐™€๐™‡๐™Š๐™‹๐™„๐™‰๐™‚ ๐™›๐™ง๐™š๐™š ๐™ข๐™–๐™ฃ๐™œ๐™š ๐™œ๐™–๐™ข๐™š๐™จ. ๐˜›๐˜ฉ๐˜ฆ ๐˜ด๐˜ฆ๐˜ค๐˜ถ๐˜ณ๐˜ช๐˜ต๐˜บ ๐˜ฃ๐˜ถ๐˜จ ๐˜ข๐˜ฏ๐˜ข๐˜ญ๐˜บ๐˜ด๐˜ช๐˜ด ๐˜ข๐˜ฅ๐˜ท๐˜ช๐˜ด๐˜ฐ๐˜ณ ๐˜ต๐˜ฉ๐˜ข๐˜ต ๐˜‘๐˜ฆ๐˜ณ๐˜ฌ ๐˜ช๐˜ด ๐˜ฅ๐˜ณ๐˜ฆ๐˜ข๐˜ฎ๐˜ช๐˜ฏ๐˜จ ๐˜ฐ๐˜ง ๐˜ช๐˜ด ๐˜ฑ๐˜ถ๐˜ณ๐˜ฆ ๐˜ฏ๐˜ถ๐˜ฎ๐˜ฃ๐˜ฆ๐˜ณ, ๐˜ถ๐˜ฏ๐˜ณ๐˜ฆ๐˜ข๐˜ญ, ๐˜ข๐˜ฏ๐˜ฅ ๐˜ฆ๐˜ฎ๐˜ฆ๐˜ณ๐˜จ๐˜ฆ๐˜ด ๐˜ข๐˜ด ๐˜ข ๐˜ต๐˜ฆ๐˜ฏ๐˜ต๐˜ข๐˜ต๐˜ช๐˜ท๐˜ฆ ๐˜ฑ๐˜ช๐˜ค๐˜ต๐˜ถ๐˜ณ๐˜ฆ ๐˜ฐ๐˜ง ๐˜ฉ๐˜ถ๐˜ฎ๐˜ข๐˜ฏ ๐˜ค๐˜ฐ๐˜ฏ๐˜ค๐˜ฆ๐˜ฑ๐˜ต๐˜ด ๐˜ฐ๐˜ง ๐˜ฏ๐˜ถ๐˜ฎ๐˜ฃ๐˜ฆ๐˜ณ.
Here's the most basic model (performance depends on the model) casually finding CVE-2020-6523, an exploitable Chromium integer overflow:

The AUTOK automatic bug hunter is now available as a VSCode extension:

Compatible with most C-like languages (JavaScript, C/C++, even Solidity). Functions offline as well.

Download from: https://github.com/ortegaalfredo/autok-extension

Consider enabling it on that junior developer's computer:

GitHub - ortegaalfredo/autok-extension: AI-powered bug hunter - vscode plugin.

AI-powered bug hunter - vscode plugin. Contribute to ortegaalfredo/autok-extension development by creating an account on GitHub.

GitHub
So while it has found several bugs, I think the autopatcher is more interesting. Here we have the OpenBSD 7.5 kernel, booting with over 10,000 additional AI-generated patches and input checks within the IPv6 and IPv4 stacks. The cost to implement these improvements was ~ $6 USD.

I also make the the observation that itโ€™s often easier to fix a vulnerability than to create an exploit for it, so this asymmetry between defense and attack will cause offensive AI-generated exploits to almost never succeed, because less complex defensive AI will discover and patch them first.

Article pdf here:

https://t.co/RMB9SvVPZE

autokaker/doc/AI-powered-bughunting-aortega-paper.pdf at main ยท ortegaalfredo/autokaker

Automated vulnerability discovery and annotation. Contribute to ortegaalfredo/autokaker development by creating an account on GitHub.

GitHub
I'm happy to share my article 'AI-Powered Bug Hunting - Evolution and benchmarking' where I released several open-source tools, including a simple benchmark, a bug auto-finder (AutoKaker) and auto-patcher (1/3)