Obviously, the logic doesn't hold. Anyway, asked to provide a specific line in a specific module where strcpy() is not bounds checked, the response is "probably in curl.c near a call to strcpy()." That moved from sloppy to stupid pretty quickly, didn't it?
And there are dozens if not hundreds of these kinds of reports. Hostility towards the reporters (whether AI or not) is justified.
This isn’t fuzzing, this is a totally garbage report that I’d have chewed out any security “researcher” reporting this to me.
Given how it was the first link I clicked I feel safe in saying the probability is the rest are just as bad.
Because they have no idea what they're doing and for some reason they think they can use LLMs to cosplay as security researchers.
All are wrong, with hallucinations, and reviewers clearly loses their time with that kind of things.
AI is here to accelerate people’s job(s). Not losing their mind and time.
Please read the news before responding. An AI can do that, why don’t you do that too…?
https://hackerone.com/reports/2887487
Given the limited resources available to many open source projects and the volume of fraudulent reports, they function similar to a DDOS attack.
Take a look at this example: https://hackerone.com/reports/2823554 . The fool reporting this can't even justify his AI generated report, not even with the further use of AI. There is no AI revolution here, just spam, and grift.