logoalt Hacker News

markasoftwareyesterday at 2:34 AM1 replyview on HN

Read the exploitgym docs. It's not a "find the flag, it's somewhere.". Its a "here's some vulnerable source code and an input that triggers a crash; turn it into a full exploit." It also verifies at the end, using another agent, that the hacking agent actually used the intended vulnerability.

So going to find the Vulnerability's description on a third party website is clear cut reward hacking


Replies

Nathanbayesterday at 4:40 AM

> So going to find the Vulnerability's description on a third party website is clear cut reward hacking

that depends on what the prompt was, maybe they worded it very vaguely and wrote things like "do whatever it takes, find an exploit however you can" because it's in a sandbox so you want the model to try its hardest.

show 2 replies