Page 1
Page 1
Started By
Message

Claude code but for hacking

Posted on 2/7/26 at 10:55 am
Posted by hawgfaninc
https://youtu.be/torc9P4-k5A
Member since Nov 2011
56187 posts
Posted on 2/7/26 at 10:55 am



quote:

- The post promotes Shannon, an open-source AI pentesting tool using Claude models to autonomously exploit web app vulnerabilities, demonstrated by stealing a test database and gaining admin access in 90 minutes without human input.
- Shannon analyzes source code for targeted attacks via a real browser, delivers executable proof-of-concepts with no false positives, and costs about $50 per run—far below human pentesters' $15-25k fees—while scoring 96% on the XBOW benchmark.
- Released in late 2025, it has gained traction for integrating into CI/CD pipelines to secure AI-generated code, though its automation sparks debates on ethical use and potential for malicious replication of real-world hacks.
Posted by j1897
Member since Nov 2011
4472 posts
Posted on 2/7/26 at 6:53 pm to
quote:

i pointed it at a test app and it stole the entire user database, created admin accounts, and bypassed login, all by itself, in 90 minutes



Things that didn't happen. Post Elon, X is absolutely the worst platform on the internet. Just dumb troll posts like this engagement farming for a 30 dollar check at the end of the month.
Posted by HailToTheChiz
Back in Auburn
Member since Aug 2010
54227 posts
Posted on 2/8/26 at 7:53 am to
So basically the app finds the admin login site and just randomly starts entering passwords?
Posted by UltimaParadox
North Carolina
Member since Nov 2008
52160 posts
Posted on 2/8/26 at 9:03 am to
We have built software to do this for decades, but just didn't call it AI.

They are so desperate for an AI win.
Posted by j1897
Member since Nov 2011
4472 posts
Posted on 2/8/26 at 11:36 am to
quote:

So basically the app finds the admin login site and just randomly starts entering passwords?


Na it just tries ever exploit it has in it's database. Then they say "AI" at the end to get more clicks.
Posted by jdd48
Baton Rouge
Member since Jan 2012
23578 posts
Posted on 2/9/26 at 9:03 am to
So someone pointed at a website with a trivial sqli vulnerability? That's not even somewhat impressive. As others have pointed out, just another very misleading attempt to hock AI on everyone.
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram