ChatGPT For OffSec
ChatGPT For OffSec
ChatGPT For OffSec
• What is ChatGPT
• Uses for Offensive Security
• Vulnerability Scanning
• Social Engineering/Phishing
• Macros & LOLBAS
• Report Findings
• Find Vulnerabilities in Code
• SQL Injection
• Breach Notifications
• Challenges & Considerations
• https://chat.openai.com/chat
• Trained using a machine learning technique called
Reinforcement Learning from Human Feedback (RLHF)
• Updated December 15, 2022 – this presentation includes
updates
References:
https://openai.com/blog/chatgpt/
References:
https://twitter.com/moyix/status/1598081204846489600
References:
https://www.bleepingcomputer.com/n
ews/security/oktas-source-code-
stolen-after-github-repositories-
hacked/
Bot builders are finding ways to use and charge for ChatGPT
functionality
• DoNotPay is a “robot lawyer” service to lower or eliminate bills
• emailGPT by Lucas McCabe
• What if ChatGPT is paywalled?
References:
https://twitter.com/jbrowder1/status/1602353465753309195
https://www.wired.com/story/the-spawn-of-chatgpt-will-try-to-sell-you-things/
https://github.com/lucasmccabe
References:
https://www.technologyreview.com/2022/12/19/1065596/how-to-spot-ai-generated-text/
References:
https://arstechnica.com/information-technology/2022/12/china-bans-ai-generated-media-without-watermarks/
https://www.theregister.com/2022/12/12/china_deep_synthesis_deepfake_regulation/
https://arstechnica.com/information-technology/2022/10/biden-proposes-new-bill-of-rights-to-protect-americans-from-ai-snooping/
https://www.smithsonianmag.com/smart-news/us-copyright-office-rules-ai-art-cant-be-copyrighted-180979808/
“Why was the computer cold when it was turned on? Because it
left its Windows open.” - ChatGPT
• Gets caught up in that it is not a dad
• Needs to learn from Erik Van Buggenhout & Jean-François Maes
References:
https://openai.com/blog/chatgpt/
https://www.wired.com/story/chatgpt-fluent-bs/
Thank You!
Questions?
@JorgeOrchilles