最後幾天都是隨便聊主題~
今天來講講 AI 在駭客們常用的工具都挖了些什麼恐怖漏洞 XD,比較像一個娛樂性清單
Calif 的大雜燴 Ghidra, radare2, IDA Pro, and Binary Ninja
包含 PDB 裡面做 Command Injection, 精心構造的 Java 反序列化 Chain
https://calif.io/research/security-tools-rce
objdump heap overflow: https://calif.io/research/oobdump
好玩的 Ghidra Server 密碼學洞 - null bypass: https://calif.io/research/ghidra-server
讓 Claude 按照 Phrack 雜誌文章做作業寫 rsync RCE Exploit: https://blog.calif.io/p/mad-bugs-feeding-claude-phrack-articles
[Anthropic] Wireshark BOF: https://red.anthropic.com/2026/cvd/findings/ANT-2026-WT5AMKP5
[Anthropic] Wireshark Heap Overwrite: https://red.anthropic.com/2026/cvd/findings/ANT-2026-05VXN1Y6
[Anthropic] Wireshark Heap Overflow again: https://red.anthropic.com/2026/cvd/findings/ANT-2026-Y5M37QY4
自己作為偵測引擎的 suricata 有很多 UAF
事實證明駭客其實也是很容易被駭的 T^T
跟醫生不能幫自己看病一樣