World Congress 2024 Aug 20, 2024 Session details

Let’s write an exploit using AI

Julian Totzek-Hallhuber

A non-developer bypassed ChatGPT's guardrails to build a fully automated Log4Shell exploit. Discover how generative AI is democratizing offensive cyber capabilities, and why your AppSec strategy must adapt.

Pause
Mute Enter Fullscreen
#1 about 3 min

Using generative AI to develop an automated security exploit

Why a non-developer used generative AI to build an automated security testing tool.

#2 about 3 min

Understanding the Log4Shell vulnerability and external impact

How the Log4j vulnerability allows attackers to query external LDAP servers via unvalidated log inputs.

#3 about 2 min

Identifying Log4j vulnerabilities across internal network software applications

Evaluating software composition analysis, vulnerability scanners, and manual inspection to find at-risk applications.

#4 about 2 min

Bypassing AI ethical restrictions to generate exploit tools

How phrasing prompts as internal ethical evaluations circumvents large language model security filters.

#5 about 2 min

Reviewing the AI generated structure of a JavaScript scanner

Examining the initial JavaScript application generated by AI to detect flawed endpoints.

#6 about 4 min

Setting up a vulnerable test application and monitoring environment

Using AI to find a vulnerable Log4j repository and monitoring LDAP requests with Wireshark.

#7 about 2 min

Verifying the basic script payload via packet capture

Monitoring network traffic locally to confirm the script successfully triggers an LDAP payload request.

#8 about 3 min

Automating payload delivery for multiple targets and endpoints

Prompting AI to convert the single-target script into an automated multi-IP network crawler.

#9 about 3 min

Troubleshooting invalid paths and unreachable web application routes

Fixing application structure logic so the crawler targets responsive endpoints instead of generating missing page errors.

#10 about 3 min

The necessity of developer intelligence amidst automated attack generation

Why human engineers remain crucial for secure application logic while mitigating accelerated threats powered by AI.

Matching moments

2:59 min

Building a vulnerable application for security testing

Malte Lantin Malte Lantin +1 · WWC Europe 2026

1:36 min

Misusing AI for malware generation and physical evasion

Balázs Kiss · WWC 2023

1:10 min

Defending against vulnerabilities in AI generated code

Chris Heilmann +2 · LIVE

1:10 min

Identifying emerging security vulnerabilities in generative AI agents

Alejandro Saucedo Alejandro Saucedo · WWC 2025

2:05 min

The impact and risks of AI generated code

Chris Heilmann · LIVE

3:53 min

Analyzing software composition risks and shadow AI vulnerabilities

Matthew Brady Matthew Brady · WWC Europe 2026

Upcoming sessions on this topic

Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

The Broken Rung: How AI is Rebuilding Software Development from the Ground Up

Tomislav Tipurić

Chief Technology Officer, Nephos

Tomislav Tipurić
Open session

World Congress 2026 North America

Building Stuff with GenAI - The Open Minded Workshop beyond OpenAI

Andreas Erben

CTO for Applied AI and Metaverse at daenet

Andreas Erben
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy