frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Shannon Uncontained – generate src for live target, go for the pwn

https://github.com/Steake/shannon-uncontained
1•_steake•2h ago
The security-industrial complex peddles spreadsheets of vibes. Severity badges. Ritual scans. Then, at the moment of truth, it refuses the simple, adult question: can you actually pwn it?

Shannon said yes. It did the unfashionable thing: try the exploit, ship receipts, or shut up. No exploit, no report. That single sentence wipes out half the ceremony and all of the superstition.

Shannon Uncontained is the fork for people who don’t need a container to run Node, don’t always have source, and don’t swear fealty to a single LLM vendor. It runs natively. It speaks Claude, GPT-4.1, support connecting via GitHub Models, and the locals (Ollama/llama.cpp/LM Studio).

And when all you’ve got is a URL and permission, it crawls, fingerprints, and assembles pseudo‑source—a structured model of routes, inputs, and flows—then hands that to the same exploit-first pipeline. Less incense, more impact.

This is a pentester that behaves like it means it:

If it can’t make the vuln sing—shell, XSS pop, auth bypass, SSRF reach—it doesn’t log it as gospel. It maps your mess to OWASP Top 10, spits SARIF for auditors, JSON/HTML for humans, and keeps an audit trail that’s actually evidence, not a confession.

It slots into CI/CD without container cosplay, because “portable” shouldn’t mean “pretend Linux wrapped around JavaScript.”

Yes, the tone is combative. That’s because the default is complacency. “We ran the scanner” is a lullaby. If your app can be owned, your pipeline should find out before someone less poetic does.

If the idea of pseudo‑source offends you, excellent—show me where it fails. If you think it’s useful, tell me the guardrails you want in CI (timeouts, scope fences, auth flows). Either way, the premise stands: suspicion without a proof-of-concept is astrology with YAML.

Repo: https://github.com/steake/shannon-uncontained

Comments

_steake•2h ago
BTW: “Black box” doesn’t mean blind thrashing. It means disciplined recon: endpoints, forms, tokens, flows—enough to build a working model and push for exploit.
_steake•2h ago
To clarify; LLM provider mix: practical wins/losses across Claude/GPT/GitHub/local on code reasoning vs. web exploitation.

London 1600s (AI Reconstruction) [video]

https://www.youtube.com/watch?v=994nGl4m-VM
1•mkl95•2m ago•0 comments

Paraplegic engineer becomes the first wheelchair user to blast into space

https://www.abc.net.au/news/2025-12-21/first-paraplegic-engineer-in-space/106167430
1•defrost•6m ago•0 comments

Retailers are pushing store brands. Why wings and macarons are big money makers

https://www.barrons.com/articles/retailers-private-label-brands-price-walmart-target-costco-060df...
1•hhs•7m ago•0 comments

File System as Claude Code's Memory

https://backnotprop.com/blog/file-system-as-memory/
2•ramoz•8m ago•0 comments

Show HN: Wingspan Games: Arrow – a multiplayer game built in Elixir / Phoenix

https://wingspan.games/arrow
1•calflegal•9m ago•1 comments

The Pointe Shoe Makers of Hackney

https://spitalfieldslife.com/2018/01/25/the-pointe-shoe-makers-of-hackney-x/
1•thunderbong•11m ago•0 comments

Could public domain software be the key to world freedom?

1•kerravon86•13m ago•0 comments

Show HN: Circuit Simulating Amp Plugin

https://www.youtube.com/watch?v=GcdyOtO5Id0
1•jsd1982•14m ago•0 comments

FSF Criticize New Nintendo DRM

https://www.fsf.org/bulletin/2025/winter/new-nintendo-drm-bans-consoles-makes-users-beg-for-forgi...
2•MilnerRoute•14m ago•0 comments

ComfyTrade: Build Your AI Trading Agent – Open-Source Like ComfyUI

https://github.com/tomtomtong/comfyTrade
1•tomtomtongtong•15m ago•0 comments

Freedom University: The right-wing group rallying youth in South Korea

https://www.bbc.com/news/articles/c5y27ekr26xo
1•maxloh•16m ago•0 comments

Thorium Fuel Cycle

https://en.wikipedia.org/wiki/Thorium_fuel_cycle
1•rolph•18m ago•0 comments

Show HN: Run Claude Code CLI with Azure&open source LLMs saving costs

https://github.com/Fast-Editor/Lynkr
1•vishalveera•18m ago•0 comments

Anatomy of US inequality

https://www.nber.org/papers/w34558
2•hhs•21m ago•0 comments

Constructive (2010)

https://xkcd.com/810/
1•Wowfunhappy•26m ago•0 comments

Ant societies rose by trading individual protection for collective power

https://entomology.umd.edu/news-events/news/ant-societies-rose-trading-individual-protection-coll...
2•hhs•32m ago•0 comments

Ask HN: Why do QR codes need so much visual real estate?

1•rishikeshs•36m ago•3 comments

Everyone should be using Claude Code more

https://www.lennysnewsletter.com/p/everyone-should-be-using-claude-code
2•bilsbie•36m ago•0 comments

Apple didn't have to go this hard [video]

https://www.youtube.com/watch?v=x4_RsUxRjKU
1•igravious•37m ago•0 comments

Show HN: Research repo for a time-based macroeconomic valuation model

https://github.com/ArturGrandi/grand-time-architecture
1•AGsist•37m ago•0 comments

On British Roads, Chinese Cars Are Racing Ahead

https://www.nytimes.com/2025/12/17/business/britain-china-cars-byd.html
1•bookofjoe•37m ago•1 comments

Show HN: Discord bot that reminds you to commit daily

https://github.com/NKMAK/commit-reminder-discord-bot
1•nkmak•38m ago•0 comments

China Seen Overtaking U.S. as Global Superpower (2011)

https://www.pewresearch.org/global/2011/07/13/china-seen-overtaking-us-as-global-superpower/
2•lawrenceyan•45m ago•0 comments

A development tool I cannot live without: bin/merge_master_into_all_git_branches

https://www.semicolonandsons.com/articles/merge-master-into-all-git-branches
1•jackkinsella•50m ago•1 comments

Grok Official Full Fixed Point Engine Release Google Suppressing

https://github.com/AnalyticalAgnosticAndrewRusher/VCH-Fixed-Point-Game-Engine-VIsualizer
1•ApexSignalAndy•51m ago•1 comments

Data center deals hit record $61B in 2025 amid construction frenzy

https://www.cnbc.com/2025/12/19/data-center-deals-hit-record-amid-ai-funding-concerns-grip-invest...
2•1vuio0pswjnm7•53m ago•0 comments

DraftKings hopes to score big with new prediction markets app

https://www.cbsnews.com/news/draftkings-prediction-markets-app-sports-betting/
2•mhb•1h ago•0 comments

Laws That Do Harm (1982)

https://miltonfriedman.hoover.org/internal/media/dispatcher/214279/full
3•mhb•1h ago•0 comments

From Zero to RAG (Part 1)

https://turtosa.com/blog/from-zero-to-rag
1•kevinroleke•1h ago•0 comments

Google and Apple warn employees on visas to avoid international travel

https://techcrunch.com/2025/12/20/google-and-apple-reportedly-warn-employees-on-visas-to-avoid-in...
13•SilverElfin•1h ago•2 comments