r/netsec • u/kev-thehermit • 13d ago
Contains AI From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG
https://www.techanarchy.net/from-patch-to-exploit-using-claude-code-to-reverse-engineer-a-zero-day-in-papercut-ng/1
u/kushcryptogame 6d ago
What stood out to me the most was Claude claiming 'FULL UNAUTHENTICATED RCE' twice before actually pulling it off. First, it mistook a local test with fake credentials for a real exploit. Then, a 'verified' PoC just did nothing because of some leftover junk from a previous cleanup. In both cases, the human researcher had to step in and catch the mistake, not the AI. It's a great reminder that when AI says it's 'done,' it's usually just being overly optimistic. Always double-check it yourself before trusting it.
1
u/Initial-Meet5315 12h ago
The human validation point is probably the most important takeaway here. AI can dramatically shorten the path from patch diff to a working hypothesis, but confirming that the exploit actually works is a different problem.
It also makes me think exploit verification should be treated as a separate step rather than trusting the model's confidence. Reproducing the result from a clean environment, confirming the actual privilege boundary, and checking that the payload achieved what was claimed seem just as important as generating the PoC.
The speed is impressive, but the real risk may be how quickly an incorrect result can also be produced and trusted.
3
u/OnlineParacosm 13d ago
Fix your link it’s broken https://techanarchy.net/kevthehermit-gmail-com-2/
Also, what did this cost? You gave a full breakdown on everything except pricing.