frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Shannon Uncontained – generate src for live target, go for the pwn

https://github.com/Steake/shannon-uncontained
1•_steake•1mo ago
The security-industrial complex peddles spreadsheets of vibes. Severity badges. Ritual scans. Then, at the moment of truth, it refuses the simple, adult question: can you actually pwn it?

Shannon said yes. It did the unfashionable thing: try the exploit, ship receipts, or shut up. No exploit, no report. That single sentence wipes out half the ceremony and all of the superstition.

Shannon Uncontained is the fork for people who don’t need a container to run Node, don’t always have source, and don’t swear fealty to a single LLM vendor. It runs natively. It speaks Claude, GPT-4.1, support connecting via GitHub Models, and the locals (Ollama/llama.cpp/LM Studio).

And when all you’ve got is a URL and permission, it crawls, fingerprints, and assembles pseudo‑source—a structured model of routes, inputs, and flows—then hands that to the same exploit-first pipeline. Less incense, more impact.

This is a pentester that behaves like it means it:

If it can’t make the vuln sing—shell, XSS pop, auth bypass, SSRF reach—it doesn’t log it as gospel. It maps your mess to OWASP Top 10, spits SARIF for auditors, JSON/HTML for humans, and keeps an audit trail that’s actually evidence, not a confession.

It slots into CI/CD without container cosplay, because “portable” shouldn’t mean “pretend Linux wrapped around JavaScript.”

Yes, the tone is combative. That’s because the default is complacency. “We ran the scanner” is a lullaby. If your app can be owned, your pipeline should find out before someone less poetic does.

If the idea of pseudo‑source offends you, excellent—show me where it fails. If you think it’s useful, tell me the guardrails you want in CI (timeouts, scope fences, auth flows). Either way, the premise stands: suspicion without a proof-of-concept is astrology with YAML.

Repo: https://github.com/steake/shannon-uncontained

Comments

_steake•1mo ago
BTW: “Black box” doesn’t mean blind thrashing. It means disciplined recon: endpoints, forms, tokens, flows—enough to build a working model and push for exploit.
_steake•1mo ago
To clarify; LLM provider mix: practical wins/losses across Claude/GPT/GitHub/local on code reasoning vs. web exploitation.

AI-powered text correction for macOS

https://taipo.app/
1•neuling•57s ago•1 comments

AppSecMaster – Learn Application Security with hands on challenges

https://www.appsecmaster.net/en
1•aqeisi•1m ago•1 comments

Fibonacci Number Certificates

https://www.johndcook.com/blog/2026/02/05/fibonacci-certificate/
1•y1n0•3m ago•0 comments

AI Overviews are killing the web search, and there's nothing we can do about it

https://www.neowin.net/editorials/ai-overviews-are-killing-the-web-search-and-theres-nothing-we-c...
2•bundie•8m ago•0 comments

City skylines need an upgrade in the face of climate stress

https://theconversation.com/city-skylines-need-an-upgrade-in-the-face-of-climate-stress-267763
3•gnabgib•9m ago•0 comments

1979: The Model World of Robert Symes [video]

https://www.youtube.com/watch?v=HmDxmxhrGDc
1•xqcgrek2•13m ago•0 comments

Satellites Have a Lot of Room

https://www.johndcook.com/blog/2026/02/02/satellites-have-a-lot-of-room/
2•y1n0•14m ago•0 comments

1980s Farm Crisis

https://en.wikipedia.org/wiki/1980s_farm_crisis
3•calebhwin•14m ago•1 comments

Show HN: FSID - Identifier for files and directories (like ISBN for Books)

https://github.com/skorotkiewicz/fsid
1•modinfo•19m ago•0 comments

Show HN: Holy Grail: Open-Source Autonomous Development Agent

https://github.com/dakotalock/holygrailopensource
1•Moriarty2026•27m ago•1 comments

Show HN: Minecraft Creeper meets 90s Tamagotchi

https://github.com/danielbrendel/krepagotchi-game
1•foxiel•34m ago•1 comments

Show HN: Termiteam – Control center for multiple AI agent terminals

https://github.com/NetanelBaruch/termiteam
1•Netanelbaruch•34m ago•0 comments

The only U.S. particle collider shuts down

https://www.sciencenews.org/article/particle-collider-shuts-down-brookhaven
2•rolph•37m ago•1 comments

Ask HN: Why do purchased B2B email lists still have such poor deliverability?

1•solarisos•37m ago•2 comments

Show HN: Remotion directory (videos and prompts)

https://www.remotion.directory/
1•rokbenko•39m ago•0 comments

Portable C Compiler

https://en.wikipedia.org/wiki/Portable_C_Compiler
2•guerrilla•41m ago•0 comments

Show HN: Kokki – A "Dual-Core" System Prompt to Reduce LLM Hallucinations

1•Ginsabo•42m ago•0 comments

Software Engineering Transformation 2026

https://mfranc.com/blog/ai-2026/
1•michal-franc•43m ago•0 comments

Microsoft purges Win11 printer drivers, devices on borrowed time

https://www.tomshardware.com/peripherals/printers/microsoft-stops-distrubitng-legacy-v3-and-v4-pr...
3•rolph•43m ago•1 comments

Lunch with the FT: Tarek Mansour

https://www.ft.com/content/a4cebf4c-c26c-48bb-82c8-5701d8256282
2•hhs•47m ago•0 comments

Old Mexico and her lost provinces (1883)

https://www.gutenberg.org/cache/epub/77881/pg77881-images.html
1•petethomas•50m ago•0 comments

'AI' is a dick move, redux

https://www.baldurbjarnason.com/notes/2026/note-on-debating-llm-fans/
5•cratermoon•51m ago•0 comments

The source code was the moat. But not anymore

https://philipotoole.com/the-source-code-was-the-moat-no-longer/
1•otoolep•51m ago•0 comments

Does anyone else feel like their inbox has become their job?

1•cfata•51m ago•1 comments

An AI model that can read and diagnose a brain MRI in seconds

https://www.michiganmedicine.org/health-lab/ai-model-can-read-and-diagnose-brain-mri-seconds
2•hhs•55m ago•0 comments

Dev with 5 of experience switched to Rails, what should I be careful about?

2•vampiregrey•57m ago•0 comments

AlphaFace: High Fidelity and Real-Time Face Swapper Robust to Facial Pose

https://arxiv.org/abs/2601.16429
1•PaulHoule•58m ago•0 comments

Scientists discover “levitating” time crystals that you can hold in your hand

https://www.nyu.edu/about/news-publications/news/2026/february/scientists-discover--levitating--t...
3•hhs•1h ago•0 comments

Rammstein – Deutschland (C64 Cover, Real SID, 8-bit – 2019) [video]

https://www.youtube.com/watch?v=3VReIuv1GFo
1•erickhill•1h ago•0 comments

Tell HN: Yet Another Round of Zendesk Spam

6•Philpax•1h ago•1 comments