We disclosed this #hackerone report against #curl when someone asked Bard to find a vulnerability, and it hallucinated together something:
curl disclosed on HackerOne: [Critical] Curl CVE-2023-38545...
## Summary: Curl CVE-2023-38545 vulnerability code changes are disclosed on the internet ## Steps To Reproduce: To replicate the issue, I have searched in the Bard about this vulnerability. It...HackerOne
Dylan Van Assche
in reply to daniel:// stenberg:// • • •Kornel
in reply to daniel:// stenberg:// • • •{"error": "too many requests"}
You've hacked hackerone (remote DoS, 9.8 CVSS)
Kevin P. Fleming
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Kevin P. Fleming • • •cohomology is FUN!
in reply to daniel:// stenberg:// • • •derekheld
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to derekheld • • •derekheld
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to derekheld • • •Brodie Robertson
in reply to daniel:// stenberg:// • • •Adam Piggott
in reply to daniel:// stenberg:// • • •Patrick $8
in reply to daniel:// stenberg:// • • •Ingvar
in reply to daniel:// stenberg:// • • •SuperIlu
in reply to daniel:// stenberg:// • • •Andreas Scherbaum
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Andreas Scherbaum • • •Andreas Scherbaum
in reply to daniel:// stenberg:// • • •They pay for your time and effort, not for the Bug report per se.
This invoice can be avoided by adding information what steps the submitter did in order to verify the LLM output.
Andreas Scherbaum
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Andreas Scherbaum • • •daniel:// stenberg://
Unknown parent • • •Dan Bergh Johnsson
in reply to daniel:// stenberg:// • • •Makes me wonder: how off are these hallucinations? Are they anywhere closely resembling the truth? Or partial? Or in the correct region?
Brodie Robertson
in reply to Dan Bergh Johnsson • • •daniel:// stenberg://
in reply to Brodie Robertson • • •Dan Bergh Johnsson
in reply to daniel:// stenberg:// • • •soc
in reply to daniel:// stenberg:// • • •My reply would have certainly contained the phrase "fucking idiot".