Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Onidel Cloud's Thread - Announcements, Feedbacks and Discussions!

1131415161719»

Comments

  • allthemtingsallthemtings Member, Megathread Squad

    @oloke said:
    We launched a public Bug Bounty Program for security researchers and ethical hackers to help us keep our platform secure through responsible disclosure.
    We offer rewards up to $500.

    You can read more about the rules and scope of the program here:
    https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program

    Once your submission gets accepted, you will also be listed on our Hall of Fame page :)

    Hello i would like to report a bug @oloke @onidel

    A while back I won a LET giveaway ($50 onidel credit for pming oloke 'polishfemboy') and PM'd Oloke the keyword but still havent recieved anything several months later. I think there must be a sivir bug in the system !

    I would also like to claim the $500 bug bounty for reporting this issue so more giveaways dont go unclaimed. Could someone please check on both of these for me?

    Thanks and regards

    Thanked by 1admax
  • forestforest Member

    @allthemtings said:

    @oloke said:
    We launched a public Bug Bounty Program for security researchers and ethical hackers to help us keep our platform secure through responsible disclosure.
    We offer rewards up to $500.

    You can read more about the rules and scope of the program here:
    https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program

    Once your submission gets accepted, you will also be listed on our Hall of Fame page :)

    Hello i would like to report a bug @oloke @onidel

    A while back I won a LET giveaway ($50 onidel credit for pming oloke 'polishfemboy') and PM'd Oloke the keyword but still havent recieved anything several months later. I think there must be a sivir bug in the system !

    I would also like to claim the $500 bug bounty for reporting this issue so more giveaways dont go unclaimed. Could someone please check on both of these for me?

    Thanks and regards

    The real bug is that I haven't gotten a VPS with them yet.

    Thanked by 2allthemtings onidel
  • olokeoloke Member, Host Rep

    @forest said: Even if it was succinct and came with a trivial reproducer? It might be better to just say that it'll be ineligible for the bounty rather than saying it'll be rejected (i.e. not fixed) outright. After all, surely you wouldn't refuse to fix a reported and trivially reproducible vulnerability just because an AI generated the report, right? You'd just not consider it eligible for the bounty?

    If an actual vulnerability was discovered by a person, and a way to reproduce was provided, the report would not be rejected.

    I think we should clarify that we meant purely AI generated vulnerability reports here (without any evidence of exploitability or impact). We had a few of those in the past...

  • forestforest Member

    @oloke said: I think we should clarify that we meant purely AI generated vulnerability reports here (without any evidence of exploitability or impact). We had a few of those in the past...

    "Without any evidence of exploitability" should be the key.

    And I can only imagine how frustrating it must be to get loquacious slop reports containing nothing but fluff confidently explaining to you that you're vulnerable because someone with root privileges could make bash setuid lmao

  • rpqurpqu Member

    @forest said:

    @rpqu said:

    @forest said:

    @oloke said: You can read more about the rules and scope of the program here:
    https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program
    Any AI generated reports will be rejected outright without bounty eligibility.

    Even if it was succinct and came with a trivial reproducer? It might be better to just say that it'll be ineligible for the bounty rather than saying it'll be rejected (i.e. not fixed) outright. After all, surely you wouldn't refuse to fix a reported and trivially reproducible vulnerability just because an AI generated the report, right? You'd just not consider it eligible for the bounty?

    :(

    I figure the intent is to avoid AI slop reports. I'm just a nitpicker for language so the phrase "rejected outright" caught my attention. I doubt they'd actually refuse to fix a severe reported vulnerability in any situation, even if the reporter made themselves ineligible for the bounty.

    Right, much of AI slop report is horrible (like many those MJJs badmouthing hosts). However, I personally read the bug report that claude wrote and I think it's not sloppily written. Though, don't know how @crunchbits takes it

  • allthemtingsallthemtings Member, Megathread Squad

    @rpqu said:

    Though, don't know how @crunchbits takes it

    Deep, right up to the balls

  • @oloke said:
    We launched a public Bug Bounty Program for security researchers and ethical hackers to help us keep our platform secure through responsible disclosure.
    We offer rewards up to $500.

    You can read more about the rules and scope of the program here:
    https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program

    Once your submission gets accepted, you will also be listed on our Hall of Fame page :)

    @vitobotta

    Thanked by 1oloke
  • crunchbitscrunchbits Member, Patron Provider, Top Host

    @allthemtings said:

    @rpqu said:

    Though, don't know how @crunchbits takes it

    Deep, right up to the balls

    @rpqu already knew that.

    AI-organized reports are fine. Especially if you're making sure it's harnessed with "brevity" or "be concise". Actually preferable. Often when I write replies I will ramble a bit or be out-of-order. Still send it that way anyways (proof of life) but for documentation/reports/etc organizing it is totally fine. What @oloke is talking about makes perfect sense.

    Thanked by 2oloke rpqu
  • forestforest Member

    I can't imagine directly giving an AI's output as a report. If I ever had to use an AI, I'd only use it as assistance but I'd write the report completely.

  • SmigitSmigit Member

    @oloke said:
    We launched a public Bug Bounty Program....We offer rewards up to $500.

    I’m on the server provision screen and for some reason Canberra isn’t showing up as an available location.

    Thanked by 2oloke onidel
  • @COLBYLICIOUS said:

    @oloke said:
    We launched a public Bug Bounty Program for security researchers and ethical hackers to help us keep our platform secure through responsible disclosure.
    We offer rewards up to $500.

    You can read more about the rules and scope of the program here:
    https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program

    Once your submission gets accepted, you will also be listed on our Hall of Fame page :)

    @vitobotta

    Thanks for the heads up. 500 bucks max is not worth my time though :)

    Thanked by 1COLBYLICIOUS
  • rpqurpqu Member

    @forest said:
    I can't imagine directly giving an AI's output as a report. If I ever had to use an AI, I'd only use it as assistance but I'd write the report completely.

    WADR forest, LLM AI is a tool. It's usefulness depends on your ability.
    Every token you input determines its state and the output. So, if you feed it low quality content, it will produce crappie content (read the report of AI getting brainrot). Also read claude's j-space
    As for myself, I don't micromanage it like what's being thought by prompt engineering. I give it concise guideline, opcode, and evaluation. Perhaps, the motivation to keep the token cost low increase the accuracy because there's less noise on the matrix.

    Thanked by 1admax
  • networknetwork Member

    The following are not eligible for bounty:

    Wordpress instance(s).

    Oh no, would have been some easy money.

    Thanked by 1Smigit
Sign In or Register to comment.