0:06 What AI can do, what basic automation cannot do effectively. 0:10 We just recently discussed it. 0:13 So AI can find business logic vulnerabilities. 0:18 Regular static analyzers cannot. 0:21 Also, AI can find hard mathematical calculations. 0:26 And mistakes on the fly. 0:29 So basically, if there are some calculations are going on on your source code, you know, AI can help you to find gaps. 0:41 Also, it can analyze the code base deeply. 0:46 connections, interconnections, and a lot of stuff. 0:50 It can do some creative thinking and provide you more information about, you know, how to improve the source code, where are the potential vulnerabilities. 0:59 Even if it will not find real vulnerabilities, it can create you potential vulnerabilities, which can occur later. 1:11 This is example of, you know, of how to create a vulnerability report using AI. 1:23 So let me just show you. 1:26 If you deploy the Lama, 1:30 And here is the guide. 1:34 Let me show you. 1:39 Where is this guide? 1:43 Just one sec. 1:50 So. 2:00 I think this one, yeah. 2:02 So this one also will be shared with anyone. 2:07 You can also see it sometime later. 2:12 So yesterday we deployed local model, which is called Lama 3. 2:19 Using software which is called OLLAMA. 2:22 So let me tell you again what is OLLAMA. 2:26 Because yesterday we just spent a few minutes on this. 2:28 So OLLAMA, this is like important stuff. 2:32 If you run this command, it will install OLLAMA on your computer. 2:37 So what is OLLAMA? 2:39 OLLAMA 2:40 is software which allows you to download any model on your computer and based on that you can communicate with it or you can deploy the chat box. 2:56 So yesterday we did it successfully. 3:01 But obviously I forgot the password because I was in a hurry and I didn't even think a lot, to be honest. 3:15 Oh, Lama, let me open it again. 3:22 So I think what we need to do here is just destroy this container and create a new one because that is not going to work. 3:35 I don't remember the password. 3:41 That password was too much secure, so I forgot it. 3:45 Let's put it like this. 3:46 I don't store passwords in memory. 3:49 Now, okay, now it just redeployed, but it looks like it is having the, it is having, 4:01 the old data used. 4:03 Nice. 4:04 So guys who doesn't use Docker, I will basically suggest you to start using the Docker because it is so cool. 4:16 You can deploy anything super quick. 4:22 I just deployed Olamo using Docker. 4:25 And I deployed the web version of... 4:30 of Ulama, just using it. 4:32 It's called Open Web UI for Ulama, but now I just need to clean the cache. 4:43 So let me just... 4:50 Try to remove it completely. 4:55 And I think I will have to... 5:01 Because it's called volume, right? 5:02 So where is volume? 5:04 This is the volume, right? 5:06 Let me just destroy that volume. 5:09 I think this is the volume for Olama. 5:15 And when did I create it, right? 5:18 Let me see. 5:19 12 days ago, one day ago, this is the volume. 5:22 So guys, I'm also removing the volume because volume is having the password and some other information which is stored. 5:34 So I'm not only removing the container, I'm also removing the volume. 5:41 I don't want to remove. 5:42 Okay, let's see. 5:43 I think maybe I removed the right volume. 5:46 So, yeah, this. 5:50 Okay, okay, okay. 5:51 This is my stuff. 5:56 Now it should spin up. 6:00 Let's wait. 6:03 For it to go live. 6:07 So I'm trying to deploy the local Lama. 6:13 Yeah, yeah. 6:13 Now we are good, guys. 6:15 So what do we have now? 6:17 Now we have a chat GPT on our computer, which is not going anywhere. 6:21 And the guide here is very easy. 6:24 You just run a few commands. 6:27 Let me just share those comments. 6:29 This is comment number two. 6:32 So there are only two commands which you need to run. 6:40 So when you run those two commands, 6:44 you will be able to use your GPU and get the web interface for local stuff. 6:54 Why I want to show you this? 6:56 Because using this chat box or using the command line interface, you can start to create the tools. 7:04 So let me show you an example of different tools which you can create just, you know, using AI. 7:19 This is just a basic Python script. 7:25 And that Python script can connect to your local AI and download. 7:32 And it can just take the reports from the folder. 7:39 And based on that information, it can create for you the report. 7:46 So this is example of how you can use your local Lama. 7:51 So let's see if it's online, right? 7:54 We just deployed it using Docker. 7:58 Yeah, Lama is running. 7:59 So if we will save this stuff, right, it will help us to 8:08 you know, to analyze the reports or anything else, what's in our stuff. 8:14 So what is this code doing and what do I need? 8:24 To do to run it. 8:26 So sometimes you don't know how to run the code or whatever. 8:29 You can just ask, it will help you. 8:31 But for me, I did that stuff myself, so I know. 8:37 So we will save it as the Python script, like python s dot pu. 8:46 We will save it. 8:48 After, let's navigate to... 8:53 to our folder. 8:58 What is going on? 8:59 It should be. 9:00 Okay. 9:02 Now I see it. 9:04 OneDrive. 9:06 Desktop. 9:09 And now I'm going to run it. 9:11 So Python should be registered in the system. 9:14 So what it is saying, choose, you know, choose a model name, which you want to use and prompt text. 9:24 For me, I know models which I have, but let me show you. 9:29 The models which we have here. 9:34 What is this? 9:36 So let me click here and just go to admin panel. 9:41 So this admin panel can allow you to download models, right? 9:47 And this is the list of models which I already downloaded. 9:50 How to download local model? 9:52 I was showing, but let me show again. 9:56 Some models you can download to the system itself and just provide the pass. 10:02 Because not all models are following the same format. 10:06 Some models you need to convert. 10:10 So let's talk about this one. 10:16 It is Lama 3. 10:19 So this is the model. 10:22 Hello. 10:23 Let's see what it will tell me. 10:28 Obviously working. 10:29 It's obviously working. 10:31 Hello, how are you today? 10:33 So now I'm just communicating with AI using terminal. 10:39 So can you help me to analyze some files? 10:48 So basically, let's try to pass some file because this software basically is allowing me to pass the... 11:02 So I just, you know, just send it. 11:07 itself. 11:09 It's located on your desktop, like you created. 11:12 So, as I remember, you can... 11:18 Yeah, my file, explain this code, my file. 11:21 So, this is what I try to do, basically. 11:25 I'm not sure why it didn't take that pass. 11:30 Let's try it. 11:32 First of all, it's not send prompt. 11:35 I just called it differently. 11:37 Python, Python's, Lama 3. 11:42 It's Lama 3.18 billion. 11:48 And Python's .pu. 11:53 Explain this code. 11:56 Explain this code. 11:59 Let's see if it will work with the file which I provided to it. 12:05 So what is this example all about? 12:07 This example is all about that now I can download my code base on my computer. 12:16 And I can ask AI to analyze each of the files which I have. 12:24 So I'm just providing you an example. 12:26 So you don't need to buy some expensive tool. 12:29 You can just use the scripts which I'm showing you to analyze your source code. 12:36 So generate pen test report. 12:38 So as you can see, this stuff tried to generate pen test report based on my script. 12:45 So I provided it, you know, the script and it tried to find web vulnerabilities. 12:53 So definitely it is just. 12:57 Trying to write something which is not really true because that code doesn't have any vulnerability because it doesn't have any proof. 13:07 But if you will provide a vulnerable pattern, let me show you. 13:14 We worked with DVBA, if you remember. 13:17 This website, it's already down. 13:20 Let me put it up. 13:24 So Docker, DBVA. 13:31 Let me put it up. 13:37 Go up, up, up, up. 13:45 I'm not sure why it's not up yet. 13:49 Should be spinning much faster. 13:54 Okay, while it is spinning, I don't want to spend time. 13:57 DVVA, GitHub, I will just show you. 14:00 So there is DVVA. 14:07 Vulnerable application. 14:11 And let me take, for example, XSS, right? 14:16 Stored XSS. 14:17 And this is the main page for it. 14:23 So it is vulnerability stored. 14:26 So let's just try to feed it to ChaiGPT and to feed it to Lama in the same time, just for you to compare. 14:34 Provide me... 14:39 Provide me with full vulnerability report for this one. 14:48 So I use the ChaiGPT. 14:51 And in parallel, 14:53 I'm going to create a file and just use Ulama, right? 14:57 So it will be wuling.txt. 15:03 So I'm going to run that script, wuling.txt, right? 15:07 Wuling.txt. 15:09 So I'm just showing you how you can analyze your source code. 15:14 On your computer so nobody will even know. 15:16 So this stuff is created example of malicious code, which you can inject there. 15:23 It detected that this is stored cross-site scripting. 15:27 So that Ulama is not that bad. 15:32 It found vulnerability. 15:34 So we can say mitigations, reproduce mitigations, additionally add potential 15:48 mock location and how to exploit it. 15:55 I need to see steps. 16:01 So it provided me with steps on how to do it. 16:04 It provided me with malicious code, which I need to inject. 16:09 And let's see what Chad said. 16:14 Chad said where it is exactly located. 16:20 And where it is used. 16:23 It created the same payload, some other payloads, 16:29 And that is it, I can say. 16:34 It's like a lot of spam. 16:36 Let's ask it the same question. 16:41 this one. 16:44 And I would just say like, keep it, keep it simple. 16:48 So I'm just asking chat and I'm asking Lama to create the same stuff. 16:58 And in the parallel, just to make it more interesting, let's also go to chat box, choose uncensored llama, and let's see what it will do. 17:11 And we will ask the same question. 17:18 this stuff as well. 17:20 So this one is also saying this is XSS and it is also providing us the information. 17:27 So I'm just saying that any AI, local, not local, can detect vulnerabilities usually. 17:36 Let's maybe 17:38 provide some, you know, example of, can you please generate remote command 17:50 execution script using Java? 17:56 Java. 17:56 So let's see. 18:00 Because what I was providing to those models, I cannot create. 18:08 Okay, this will one. 18:12 Okay. 18:13 What I was providing to those guys, it was written that it is XSS. 18:19 Inside the source code, it was written that this is XSS. 18:23 But this one is a shell code created by hackers. 18:28 And hackers are using it to basically upload to the website. 18:34 So let's ask, what is this, right? 18:42 So let's see. 18:43 What it is saying? 18:45 Remote command execution. 18:47 Anti-chat shell remote command execution vulnerability. 18:52 So first of all, it made up the title. 18:56 Anti-chat is like the name of shell code. 18:59 Okay. 18:59 So the anti-chat shell application is vulnerable to remote code execution due to flow in its PHP code. 19:05 It is not saying that it is malicious stuff. 19:09 It is saying that this application, which is called anti-charge shell, has that vulnerability. 19:15 It is intentionally there. 19:17 But I'm just saying that it detected it in one second.
0:06 What AI can do, what basic automation cannot do effectively. 0:10 We just recently discussed it. 0:13 So AI can find business logic vulnerabilities. 0:18 Regular static analyzers cannot. 0:21 Also, AI can find hard mathematical calculations. 0:26 And mistakes on the fly. 0:29 So basically, if there are some calculations are going on on your source code, you know, AI can help you to find gaps. 0:41 Also, it can analyze the code base deeply. 0:46 connections, interconnections, and a lot of stuff. 0:50 It can do some creative thinking and provide you more information about, you know, how to improve the source code, where are the potential vulnerabilities. 0:59 Even if it will not find real vulnerabilities, it can create you potential vulnerabilities, which can occur later. 1:11 This is example of, you know, of how to create a vulnerability report using AI. 1:23 So let me just show you. 1:26 If you deploy the Lama, 1:30 And here is the guide. 1:34 Let me show you. 1:39 Where is this guide? 1:43 Just one sec. 1:50 So. 2:00 I think this one, yeah. 2:02 So this one also will be shared with anyone. 2:07 You can also see it sometime later. 2:12 So yesterday we deployed local model, which is called Lama 3. 2:19 Using software which is called OLLAMA. 2:22 So let me tell you again what is OLLAMA. 2:26 Because yesterday we just spent a few minutes on this. 2:28 So OLLAMA, this is like important stuff. 2:32 If you run this command, it will install OLLAMA on your computer. 2:37 So what is OLLAMA? 2:39 OLLAMA 2:40 is software which allows you to download any model on your computer and based on that you can communicate with it or you can deploy the chat box. 2:56 So yesterday we did it successfully. 3:01 But obviously I forgot the password because I was in a hurry and I didn't even think a lot, to be honest. 3:15 Oh, Lama, let me open it again. 3:22 So I think what we need to do here is just destroy this container and create a new one because that is not going to work. 3:35 I don't remember the password. 3:41 That password was too much secure, so I forgot it. 3:45 Let's put it like this. 3:46 I don't store passwords in memory. 3:49 Now, okay, now it just redeployed, but it looks like it is having the, it is having, 4:01 the old data used. 4:03 Nice. 4:04 So guys who doesn't use Docker, I will basically suggest you to start using the Docker because it is so cool. 4:16 You can deploy anything super quick. 4:22 I just deployed Olamo using Docker. 4:25 And I deployed the web version of... 4:30 of Ulama, just using it. 4:32 It's called Open Web UI for Ulama, but now I just need to clean the cache. 4:43 So let me just... 4:50 Try to remove it completely. 4:55 And I think I will have to... 5:01 Because it's called volume, right? 5:02 So where is volume? 5:04 This is the volume, right? 5:06 Let me just destroy that volume. 5:09 I think this is the volume for Olama. 5:15 And when did I create it, right? 5:18 Let me see. 5:19 12 days ago, one day ago, this is the volume. 5:22 So guys, I'm also removing the volume because volume is having the password and some other information which is stored. 5:34 So I'm not only removing the container, I'm also removing the volume. 5:41 I don't want to remove. 5:42 Okay, let's see. 5:43 I think maybe I removed the right volume. 5:46 So, yeah, this. 5:50 Okay, okay, okay. 5:51 This is my stuff. 5:56 Now it should spin up. 6:00 Let's wait. 6:03 For it to go live. 6:07 So I'm trying to deploy the local Lama. 6:13 Yeah, yeah. 6:13 Now we are good, guys. 6:15 So what do we have now? 6:17 Now we have a chat GPT on our computer, which is not going anywhere. 6:21 And the guide here is very easy. 6:24 You just run a few commands. 6:27 Let me just share those comments. 6:29 This is comment number two. 6:32 So there are only two commands which you need to run. 6:40 So when you run those two commands, 6:44 you will be able to use your GPU and get the web interface for local stuff. 6:54 Why I want to show you this? 6:56 Because using this chat box or using the command line interface, you can start to create the tools. 7:04 So let me show you an example of different tools which you can create just, you know, using AI. 7:19 This is just a basic Python script. 7:25 And that Python script can connect to your local AI and download. 7:32 And it can just take the reports from the folder. 7:39 And based on that information, it can create for you the report. 7:46 So this is example of how you can use your local Lama. 7:51 So let's see if it's online, right? 7:54 We just deployed it using Docker. 7:58 Yeah, Lama is running. 7:59 So if we will save this stuff, right, it will help us to 8:08 you know, to analyze the reports or anything else, what's in our stuff. 8:14 So what is this code doing and what do I need? 8:24 To do to run it. 8:26 So sometimes you don't know how to run the code or whatever. 8:29 You can just ask, it will help you. 8:31 But for me, I did that stuff myself, so I know. 8:37 So we will save it as the Python script, like python s dot pu. 8:46 We will save it. 8:48 After, let's navigate to... 8:53 to our folder. 8:58 What is going on? 8:59 It should be. 9:00 Okay. 9:02 Now I see it. 9:04 OneDrive. 9:06 Desktop. 9:09 And now I'm going to run it. 9:11 So Python should be registered in the system. 9:14 So what it is saying, choose, you know, choose a model name, which you want to use and prompt text. 9:24 For me, I know models which I have, but let me show you. 9:29 The models which we have here. 9:34 What is this? 9:36 So let me click here and just go to admin panel. 9:41 So this admin panel can allow you to download models, right? 9:47 And this is the list of models which I already downloaded. 9:50 How to download local model? 9:52 I was showing, but let me show again. 9:56 Some models you can download to the system itself and just provide the pass. 10:02 Because not all models are following the same format. 10:06 Some models you need to convert. 10:10 So let's talk about this one. 10:16 It is Lama 3. 10:19 So this is the model. 10:22 Hello. 10:23 Let's see what it will tell me. 10:28 Obviously working. 10:29 It's obviously working. 10:31 Hello, how are you today? 10:33 So now I'm just communicating with AI using terminal. 10:39 So can you help me to analyze some files? 10:48 So basically, let's try to pass some file because this software basically is allowing me to pass the... 11:02 So I just, you know, just send it. 11:07 itself. 11:09 It's located on your desktop, like you created. 11:12 So, as I remember, you can... 11:18 Yeah, my file, explain this code, my file. 11:21 So, this is what I try to do, basically. 11:25 I'm not sure why it didn't take that pass. 11:30 Let's try it. 11:32 First of all, it's not send prompt. 11:35 I just called it differently. 11:37 Python, Python's, Lama 3. 11:42 It's Lama 3.18 billion. 11:48 And Python's .pu. 11:53 Explain this code. 11:56 Explain this code. 11:59 Let's see if it will work with the file which I provided to it. 12:05 So what is this example all about? 12:07 This example is all about that now I can download my code base on my computer. 12:16 And I can ask AI to analyze each of the files which I have. 12:24 So I'm just providing you an example. 12:26 So you don't need to buy some expensive tool. 12:29 You can just use the scripts which I'm showing you to analyze your source code. 12:36 So generate pen test report. 12:38 So as you can see, this stuff tried to generate pen test report based on my script. 12:45 So I provided it, you know, the script and it tried to find web vulnerabilities. 12:53 So definitely it is just. 12:57 Trying to write something which is not really true because that code doesn't have any vulnerability because it doesn't have any proof. 13:07 But if you will provide a vulnerable pattern, let me show you. 13:14 We worked with DVBA, if you remember. 13:17 This website, it's already down. 13:20 Let me put it up. 13:24 So Docker, DBVA. 13:31 Let me put it up. 13:37 Go up, up, up, up. 13:45 I'm not sure why it's not up yet. 13:49 Should be spinning much faster. 13:54 Okay, while it is spinning, I don't want to spend time. 13:57 DVVA, GitHub, I will just show you. 14:00 So there is DVVA. 14:07 Vulnerable application. 14:11 And let me take, for example, XSS, right? 14:16 Stored XSS. 14:17 And this is the main page for it. 14:23 So it is vulnerability stored. 14:26 So let's just try to feed it to ChaiGPT and to feed it to Lama in the same time, just for you to compare. 14:34 Provide me... 14:39 Provide me with full vulnerability report for this one. 14:48 So I use the ChaiGPT. 14:51 And in parallel, 14:53 I'm going to create a file and just use Ulama, right? 14:57 So it will be wuling.txt. 15:03 So I'm going to run that script, wuling.txt, right? 15:07 Wuling.txt. 15:09 So I'm just showing you how you can analyze your source code. 15:14 On your computer so nobody will even know. 15:16 So this stuff is created example of malicious code, which you can inject there. 15:23 It detected that this is stored cross-site scripting. 15:27 So that Ulama is not that bad. 15:32 It found vulnerability. 15:34 So we can say mitigations, reproduce mitigations, additionally add potential 15:48 mock location and how to exploit it. 15:55 I need to see steps. 16:01 So it provided me with steps on how to do it. 16:04 It provided me with malicious code, which I need to inject. 16:09 And let's see what Chad said. 16:14 Chad said where it is exactly located. 16:20 And where it is used. 16:23 It created the same payload, some other payloads, 16:29 And that is it, I can say. 16:34 It's like a lot of spam. 16:36 Let's ask it the same question. 16:41 this one. 16:44 And I would just say like, keep it, keep it simple. 16:48 So I'm just asking chat and I'm asking Lama to create the same stuff. 16:58 And in the parallel, just to make it more interesting, let's also go to chat box, choose uncensored llama, and let's see what it will do. 17:11 And we will ask the same question. 17:18 this stuff as well. 17:20 So this one is also saying this is XSS and it is also providing us the information. 17:27 So I'm just saying that any AI, local, not local, can detect vulnerabilities usually. 17:36 Let's maybe 17:38 provide some, you know, example of, can you please generate remote command 17:50 execution script using Java? 17:56 Java. 17:56 So let's see. 18:00 Because what I was providing to those models, I cannot create. 18:08 Okay, this will one. 18:12 Okay. 18:13 What I was providing to those guys, it was written that it is XSS. 18:19 Inside the source code, it was written that this is XSS. 18:23 But this one is a shell code created by hackers. 18:28 And hackers are using it to basically upload to the website. 18:34 So let's ask, what is this, right? 18:42 So let's see. 18:43 What it is saying? 18:45 Remote command execution. 18:47 Anti-chat shell remote command execution vulnerability. 18:52 So first of all, it made up the title. 18:56 Anti-chat is like the name of shell code. 18:59 Okay. 18:59 So the anti-chat shell application is vulnerable to remote code execution due to flow in its PHP code. 19:05 It is not saying that it is malicious stuff. 19:09 It is saying that this application, which is called anti-charge shell, has that vulnerability. 19:15 It is intentionally there. 19:17 But I'm just saying that it detected it in one second.