That Shouldn’t Have Worked
46:12
Smart Contract Hacking
34:44
Жыл бұрын
Пікірлер
@karengomez3143
@karengomez3143 Күн бұрын
Takeaways: Attacks: -Injection (silly activities could defeat an AI model, since this data is not in the training data). -Grounding (allows an AI to show false outputs, through data creation, (Search, Engine, Optimization) and then the result is shown by the AI. -Prompt Hijacking (when the context is modified by someone that does not have the authority to do it, like a user's input being treated as a developers). Exploits: -Conversation attacks to Business flaws (wrong discounts, upgrades, math) -Guardrails attacks
@karengomez3143
@karengomez3143 Күн бұрын
Takeaways: GPT is making many structured relation placement between words in different levels (layers) so different inputs could bring a set of outputs, but it's not a DB, and it's not searching for patterns within a created DB. Within the GPT answers are the alignment response rules, what would be if a response is following the user's request in spite of company intent or social or compliance rules. GPT models are not that good at making a whole story or remembering a conversation, so it's not good in making novels, but it has a window response that would be good from a user's point of view aligning to their intend. Guardrails are limits or ways to make a system in place to follow alignments. Grounding as a hallucination mechanism, providing context to the user's query through a database management (large language model), so whenever the user is asking a question that needs more info about, or that is recent, the app would bring another page, just like google would retrieve twitter webpage when someone is asking for it. AI application: Scammer response generator
@eagerjhoe2314
@eagerjhoe2314 10 күн бұрын
Awesome videos learned a lot. I couldn't find the law bas project online you talked about, could you help me out? Thanks
@jolin1947
@jolin1947 Ай бұрын
May I use the video as the training material? Thank you.
@VEVO500
@VEVO500 2 ай бұрын
How is a portal entered
@user-vy9oi1vx9i
@user-vy9oi1vx9i 2 ай бұрын
I wish the movies had subtitles because I am deaf and I hardly understand and I have hearing problems
@8starsAND
@8starsAND 4 ай бұрын
Sans is very overrated, I don’t know how they got so big
@Carnyride79
@Carnyride79 4 ай бұрын
Good talk but you like to stroke your ego quite often and to say Elon doesn't know what he's talking about is a stretch
@Peethemayan4516
@Peethemayan4516 2 ай бұрын
How so?
@user-be2bs1hy8e
@user-be2bs1hy8e 4 ай бұрын
This is true AI Safety, all the closed-sourced policy holders guiding the system is doing is showing the AI how to say no to end-user. I mean alignment is not a bad thing but the block box approach is just tuning models to select what human alignment is for the user.
@lydiacornelia5181
@lydiacornelia5181 5 ай бұрын
Thank you 🎉🎉🎉
@d_lom9253
@d_lom9253 6 ай бұрын
This is only helpful for a very niche crowd. If your have to protect your network or anything like that, wasting time
@hannahprobably5765
@hannahprobably5765 7 ай бұрын
Huge thanks
@DillPickl3_
@DillPickl3_ 7 ай бұрын
NGL this is probably my favourite SANS presentations ever. Retention has always been an issue of mine. With ANKI I've been able to take Tests and Exams with a high level of confidence. thanks Josh!
@su8z3r03
@su8z3r03 7 ай бұрын
@4:54 The statement "Kerberos uses shared secrets for authentication in a Windows domain, there is only one, the NTLM hash" is not entirely accurate. While it is true that NTLM (NT LAN Manager) is a legacy authentication protocol used in Windows environments, Kerberos is the primary authentication protocol used in Active Directory domains. Kerberos does not rely on shared secrets in the same way as NTLM. Instead, it uses a trusted third-party authentication system and symmetric key cryptography to verify the identities of users and services within a network. Kerberos authentication involves the use of tickets and does not directly rely on the storage of password hashes. Furthermore, the statement overlooks the fact that Kerberos also involves the use of a Kerberos hash, which is derived from the user's password and is used in the authentication process. In summary, the statement oversimplifies the authentication mechanisms used in Windows domains and does not accurately represent the role of Kerberos and the use of shared secrets in the context of Windows domain authentication.
@ram_bam
@ram_bam 8 ай бұрын
Would SEC504 provide enough preparation for this course?
@AniketChauhan-pw4lz
@AniketChauhan-pw4lz 8 ай бұрын
i think SEC560 will be
@SumanRoy.official
@SumanRoy.official 10 ай бұрын
Please use dark backgrounds
@georgeb8637
@georgeb8637 11 ай бұрын
8:00 - all letters in English language 9:41 neural network 22:13 - AI confessing love 26:58 Hallucination 32:06 prompt engineering 40:53 - AI apology 😂 46:58 - Go game beat by human 54:00 - sequencing attack
@user-tb3xd1uy5c
@user-tb3xd1uy5c 11 ай бұрын
Hi there, can I use your video for training purposes at a non for profit?
@pentester-ethicalhacker
@pentester-ethicalhacker 11 ай бұрын
Excellent content!
@alfredoneves3976
@alfredoneves3976 11 ай бұрын
Here from tryhackme
@rumpelstiltskin9729
@rumpelstiltskin9729 Жыл бұрын
The news segments were so cringe
@vanthinhnguyen3335
@vanthinhnguyen3335 Жыл бұрын
Please !! Discount for this course
@manamsetty2664
@manamsetty2664 Жыл бұрын
Awesome talk 👏 Really good explanation about what AI is doing Great animations Was always engaged throughout the talk Questions need to be audible though that was the only issue
@shpockboss3834
@shpockboss3834 Жыл бұрын
Thats informative
@shpockboss3834
@shpockboss3834 Жыл бұрын
Thats informative
@shpockboss3834
@shpockboss3834 Жыл бұрын
Thats informative
@achunaryan3418
@achunaryan3418 Жыл бұрын
AAAA
@manamsetty2664
@manamsetty2664 Жыл бұрын
At the beginning of the talk i thought this was a random comment but the end made it clear.
@tanker7757
@tanker7757 Жыл бұрын
I wish the courses where cheaper😢 kids like me would go broke getting this
@fafmekfmaefeaf
@fafmekfmaefeaf Жыл бұрын
May we use this in our staff training on security awareness for our company employee annual training?
@gpdally-tupa
@gpdally-tupa Жыл бұрын
thank you!
@hackwithsumit
@hackwithsumit Жыл бұрын
anyone say how to increase font size or decrease font size on burp suite
@joshdagda2847
@joshdagda2847 Жыл бұрын
When is this course going to be available?
@TheBenJiles
@TheBenJiles Жыл бұрын
Fascinating stuff! Thanks for the well communicated and in-depth presentation.
@piotrstasinskij2929
@piotrstasinskij2929 Жыл бұрын
Thank You for this learning material
@shaenorelation7175
@shaenorelation7175 Жыл бұрын
This is really good
@dereklewinson3018
@dereklewinson3018 Жыл бұрын
Very informative; thanks!!!
@MusicLover-bp2cc
@MusicLover-bp2cc Жыл бұрын
Great video. Just a quick question, why were the reasons you did not choose Caldera as a suitable open source C2 option ? Codially
@manums__
@manums__ Жыл бұрын
TNice tutorials is my tNice tutorialrd ti watcNice tutorialng tNice tutorials video. I'm switcNice tutorialng over from soft One 4 to soft for my production and your video was the first one I
@antoniomorale5689
@antoniomorale5689 Жыл бұрын
BROTHER, YOU ARE THE BEST!!! You oooh really helped me!! THANK YOU VERY MUCH!
@dominickiplangat1921
@dominickiplangat1921 Жыл бұрын
This burpsuite is so useful
@hannahprobably5765
@hannahprobably5765 Жыл бұрын
♥ thank you
@ThePaulSIN
@ThePaulSIN Жыл бұрын
Great presentation. Very insightful and educational!
@jabra1946
@jabra1946 Жыл бұрын
Very Informative! Thank you,
@tiagotavi
@tiagotavi Жыл бұрын
Go Packers!
@sotecluxan4221
@sotecluxan4221 Жыл бұрын
@ConstruccionesValades
@ConstruccionesValades 2 жыл бұрын
Thanks for the tutorial
@orionbekesi
@orionbekesi 2 жыл бұрын
You saved me. I didn't find the ctrl+space keyboard shortcut to send the request for the repeater tab anywhere googling
@williamdrum9899
@williamdrum9899 2 жыл бұрын
Ever since I learned about this I am just speechless about how this FUBAR happened. The fact that Solidity even lets this happen at all is absurd. Easily the worst programming language I've ever seen (esolangs don't count since they were intended to be bad)
@ryd3v
@ryd3v 2 жыл бұрын
How much is this course?
@HopliteSecurity
@HopliteSecurity 2 жыл бұрын
This was brilliant work. Thank you again for another amazing video. I really appreciated the "Attack surface management aspect". Thank you as well Chris Dale :)