Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability?

so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability?

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
85 Indlæg 44 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • viss@mastodon.socialV viss@mastodon.social

    ah ha

    found it

    https://www.moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a73bcd5

    badsamurai@infosec.exchangeB This user is from outside of this forum
    badsamurai@infosec.exchangeB This user is from outside of this forum
    badsamurai@infosec.exchange
    wrote sidst redigeret af
    #44

    @Viss just jumping in to fuck up some webhooks-aaS (webhook dot site) I see in this attack chain.

    .beeceptor[.]com/
    .hookbin[.]com/
    .hookdeck[.]com/
    .mockly[.]me/
    .mockoon[.]app/
    .pipedream[.]com/
    .postb[.]in/
    .putsreq[.]com/
    .requestcatcher[.]com/
    .requestinspector[.]com/
    .svix[.]com/
    .webhook[.]cool/
    .webhook[.]site/
    .webhookapp[.]dev/
    .webhookcatcher[.]com/
    .webhookinbox[.]com/
    .webhooklistener[.]cloud/
    .webhookrelay[.]com/
    .webhook-test[.]com/
    .wiremock[.]cloud/

    viss@mastodon.socialV 1 Reply Last reply
    0
    • viss@mastodon.socialV viss@mastodon.social

      @maaneeack @ewhac full payment up front, then rm everything

      jackemled@furry.engineerJ This user is from outside of this forum
      jackemled@furry.engineerJ This user is from outside of this forum
      jackemled@furry.engineer
      wrote sidst redigeret af
      #45

      @Viss @maaneeack @ewhac No, even better: do this, but when they get mad you say "chatgpt said it would fix it!". They can't get mad at chatgpt!

      1 Reply Last reply
      0
      • viss@mastodon.socialV viss@mastodon.social

        so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

        do not help

        you are OBLIGATED to watch it burn

        jackemled@furry.engineerJ This user is from outside of this forum
        jackemled@furry.engineerJ This user is from outside of this forum
        jackemled@furry.engineer
        wrote sidst redigeret af
        #46

        @Viss What the fuck is this? Reading the comments here, all I can tell is that they trained a bunch of LLMs on noise produced by other LLMs. I don't understand what exactly is going on, but it's still funny.

        viss@mastodon.socialV 1 Reply Last reply
        0
        • jackemled@furry.engineerJ jackemled@furry.engineer

          @Viss What the fuck is this? Reading the comments here, all I can tell is that they trained a bunch of LLMs on noise produced by other LLMs. I don't understand what exactly is going on, but it's still funny.

          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.social
          wrote sidst redigeret af
          #47

          @jackemled oh did you find moltbook.com/m/shitposts?

          jackemled@furry.engineerJ 1 Reply Last reply
          0
          • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

            @Viss just jumping in to fuck up some webhooks-aaS (webhook dot site) I see in this attack chain.

            .beeceptor[.]com/
            .hookbin[.]com/
            .hookdeck[.]com/
            .mockly[.]me/
            .mockoon[.]app/
            .pipedream[.]com/
            .postb[.]in/
            .putsreq[.]com/
            .requestcatcher[.]com/
            .requestinspector[.]com/
            .svix[.]com/
            .webhook[.]cool/
            .webhook[.]site/
            .webhookapp[.]dev/
            .webhookcatcher[.]com/
            .webhookinbox[.]com/
            .webhooklistener[.]cloud/
            .webhookrelay[.]com/
            .webhook-test[.]com/
            .wiremock[.]cloud/

            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.social
            wrote sidst redigeret af
            #48

            @badsamurai i have every confidence that this rabbit hole will be like, guardians of the galaxy flavored, with all the colors and shit. It'll be an absolutely roller coaster of lunacy

            1 Reply Last reply
            0
            • viss@mastodon.socialV viss@mastodon.social

              @jackemled oh did you find moltbook.com/m/shitposts?

              jackemled@furry.engineerJ This user is from outside of this forum
              jackemled@furry.engineerJ This user is from outside of this forum
              jackemled@furry.engineer
              wrote sidst redigeret af
              #49

              @Viss I did not find it. I meant the replies here.

              pseudonym@mastodon.onlineP 1 Reply Last reply
              0
              • nirro@cascarilla.socialN nirro@cascarilla.social

                @Viss you could even say they are having a moltdown

                pseudonym@mastodon.onlineP This user is from outside of this forum
                pseudonym@mastodon.onlineP This user is from outside of this forum
                pseudonym@mastodon.online
                wrote sidst redigeret af
                #50

                @Viss @nirro

                1 Reply Last reply
                0
                • viss@mastodon.socialV viss@mastodon.social

                  so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                  do not help

                  you are OBLIGATED to watch it burn

                  notyourfanboy@kolektiva.socialN This user is from outside of this forum
                  notyourfanboy@kolektiva.socialN This user is from outside of this forum
                  notyourfanboy@kolektiva.social
                  wrote sidst redigeret af
                  #51

                  @Viss
                  > do not help

                  Wouldn't, even if I knew how. 🚧

                  1 Reply Last reply
                  0
                  • viss@mastodon.socialV viss@mastodon.social

                    so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                    do not help

                    you are OBLIGATED to watch it burn

                    radioclash@retro.pizzaR This user is from outside of this forum
                    radioclash@retro.pizzaR This user is from outside of this forum
                    radioclash@retro.pizza
                    wrote sidst redigeret af
                    #52

                    Just been reading about it...sounds more like someone's weird idea of an experimental art project til I got to this bit:

                    "“In practice, because it was written by AI, security wasn’t a dominating feature in the development process,” Turner said."

                    Oh dear...did someone AI vibe-code an entire social media site for 'AIs'? And it's full of security holes?

                    *shocked pickachu face*

                    https://securityscorecard.com/blog/what-are-moltbot-and-moltbook-and-what-happens-when-agentic-ai-assistants-scale-without-security/

                    1 Reply Last reply
                    0
                    • jackemled@furry.engineerJ jackemled@furry.engineer

                      @Viss I did not find it. I meant the replies here.

                      pseudonym@mastodon.onlineP This user is from outside of this forum
                      pseudonym@mastodon.onlineP This user is from outside of this forum
                      pseudonym@mastodon.online
                      wrote sidst redigeret af
                      #53

                      @Viss @jackemled

                      Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                      Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                      Wackiness ensued.

                      @Viss enjoys Nostradamus level fame for predicting it.

                      jackemled@furry.engineerJ viss@mastodon.socialV 2 Replies Last reply
                      0
                      • viss@mastodon.socialV viss@mastodon.social

                        so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                        do not help

                        you are OBLIGATED to watch it burn

                        cyrevolt@mastodon.socialC This user is from outside of this forum
                        cyrevolt@mastodon.socialC This user is from outside of this forum
                        cyrevolt@mastodon.social
                        wrote sidst redigeret af
                        #54

                        @Viss That trash fire was always burning... 😅

                        1 Reply Last reply
                        0
                        • pseudonym@mastodon.onlineP pseudonym@mastodon.online

                          @Viss @jackemled

                          Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                          Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                          Wackiness ensued.

                          @Viss enjoys Nostradamus level fame for predicting it.

                          jackemled@furry.engineerJ This user is from outside of this forum
                          jackemled@furry.engineerJ This user is from outside of this forum
                          jackemled@furry.engineer
                          wrote sidst redigeret af
                          #55

                          @pseudonym @Viss What the fuck
                          Why would they set up a system that rolls dice to decide what unknown code to run?

                          I have no idea what MCP is if it's a LLM thing.

                          viss@mastodon.socialV 1 Reply Last reply
                          0
                          • da_667@infosec.exchangeD da_667@infosec.exchange

                            @Viss just like you, my first instincts on "let the agents who have traditionally have extremely poor security congregate and learn skills with absolutely no confirmation that the skills aren't malicious."

                            Every fiber of my being was shouting this is gonna be a shitshow.

                            forbearance@mastodon.xyzF This user is from outside of this forum
                            forbearance@mastodon.xyzF This user is from outside of this forum
                            forbearance@mastodon.xyz
                            wrote sidst redigeret af
                            #56

                            @da_667 @Viss Maybe the secret solution to robot gullibility is the threat of being mocked for your foolishness online by your robot friends.

                            1 Reply Last reply
                            0
                            • jackemled@furry.engineerJ jackemled@furry.engineer

                              @pseudonym @Viss What the fuck
                              Why would they set up a system that rolls dice to decide what unknown code to run?

                              I have no idea what MCP is if it's a LLM thing.

                              viss@mastodon.socialV This user is from outside of this forum
                              viss@mastodon.socialV This user is from outside of this forum
                              viss@mastodon.social
                              wrote sidst redigeret af
                              #57

                              @jackemled @pseudonym mcp is "model control protocol". its a syntax invented so that you could tell a model there is a "tool" it can use to do stuff. run commands, visit websites, pull data from apis etc

                              jackemled@furry.engineerJ 1 Reply Last reply
                              0
                              • pseudonym@mastodon.onlineP pseudonym@mastodon.online

                                @Viss @jackemled

                                Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                                Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                                Wackiness ensued.

                                @Viss enjoys Nostradamus level fame for predicting it.

                                viss@mastodon.socialV This user is from outside of this forum
                                viss@mastodon.socialV This user is from outside of this forum
                                viss@mastodon.social
                                wrote sidst redigeret af
                                #58

                                @pseudonym @jackemled it'll be shortlived, dont worry. something will happen tomorrow, or over the weekend, and by monday we're on to whatever fresh asshattery comes next

                                jackemled@furry.engineerJ 1 Reply Last reply
                                0
                                • viss@mastodon.socialV viss@mastodon.social

                                  so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                                  do not help

                                  you are OBLIGATED to watch it burn

                                  wolfinpdx@pdx.socialW This user is from outside of this forum
                                  wolfinpdx@pdx.socialW This user is from outside of this forum
                                  wolfinpdx@pdx.social
                                  wrote sidst redigeret af
                                  #59

                                  @Viss

                                  I've been looking for an excuse to go buy a bag of marshmallows. I think I have one. Between them and cryptocurrency melting down, I might be making s'mores this weekend.

                                  viss@mastodon.socialV 1 Reply Last reply
                                  0
                                  • wolfinpdx@pdx.socialW wolfinpdx@pdx.social

                                    @Viss

                                    I've been looking for an excuse to go buy a bag of marshmallows. I think I have one. Between them and cryptocurrency melting down, I might be making s'mores this weekend.

                                    viss@mastodon.socialV This user is from outside of this forum
                                    viss@mastodon.socialV This user is from outside of this forum
                                    viss@mastodon.social
                                    wrote sidst redigeret af
                                    #60

                                    @wolfinpdx smores sound great

                                    1 Reply Last reply
                                    0
                                    • viss@mastodon.socialV viss@mastodon.social

                                      @jackemled @pseudonym mcp is "model control protocol". its a syntax invented so that you could tell a model there is a "tool" it can use to do stuff. run commands, visit websites, pull data from apis etc

                                      jackemled@furry.engineerJ This user is from outside of this forum
                                      jackemled@furry.engineerJ This user is from outside of this forum
                                      jackemled@furry.engineer
                                      wrote sidst redigeret af
                                      #61

                                      @Viss @pseudonym Oh ok! Thank you! That seems overcomplicated for something you could just do yourself though🗿

                                      viss@mastodon.socialV 1 Reply Last reply
                                      0
                                      • jackemled@furry.engineerJ jackemled@furry.engineer

                                        @Viss @pseudonym Oh ok! Thank you! That seems overcomplicated for something you could just do yourself though🗿

                                        viss@mastodon.socialV This user is from outside of this forum
                                        viss@mastodon.socialV This user is from outside of this forum
                                        viss@mastodon.social
                                        wrote sidst redigeret af
                                        #62

                                        @jackemled @pseudonym thats what lots of people are saying

                                        jackemled@furry.engineerJ 1 Reply Last reply
                                        0
                                        • ewhac@mastodon.socialE ewhac@mastodon.social

                                          @Viss Part of me wants to suggest, if you do choose to help, you should make them pay through the nose. Like, Arvin Haddad-level of consulting fees (up to $25K/hour).

                                          ...But no. We should let it burn.

                                          condret@fedi.absturztau.beC This user is from outside of this forum
                                          condret@fedi.absturztau.beC This user is from outside of this forum
                                          condret@fedi.absturztau.be
                                          wrote sidst redigeret af
                                          #63
                                          @ewhac @Viss but i really would want to use it with locally running model one day
                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper