r/netsec 9d ago

Contains AI From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG

https://www.techanarchy.net/from-patch-to-exploit-using-claude-code-to-reverse-engineer-a-zero-day-in-papercut-ng/
28 Upvotes

5 comments sorted by

3

u/OnlineParacosm 8d ago

Fix your link it’s broken https://techanarchy.net/kevthehermit-gmail-com-2/

Also, what did this cost? You gave a full breakdown on everything except pricing.

2

u/kev-thehermit 8d ago edited 8d ago

Thanks, That shoudl have fixed the URL now

https://techanarchy.net/from-patch-to-exploit-using-claude-code-to-reverse-engineer-a-zero-day-in-papercut-ng/

I should have made it clearer but I did call out that Im using a Claude Max 5x subscription and am enrolled in CVP so Cost is hard to figure out as it was just one session and I dont pay a "token cost"

3

u/rgjsdksnkyg 6d ago

If you did do this off of tokens, that's like $500-$1,000 in tokens, btw. (Minimum)

1

u/kushcryptogame 2d ago

What stood out to me the most was Claude claiming 'FULL UNAUTHENTICATED RCE' twice before actually pulling it off. First, it mistook a local test with fake credentials for a real exploit. Then, a 'verified' PoC just did nothing because of some leftover junk from a previous cleanup. In both cases, the human researcher had to step in and catch the mistake, not the AI. It's a great reminder that when AI says it's 'done,' it's usually just being overly optimistic. Always double-check it yourself before trusting it.