Julian Totzek-Hallhuber
Let’s write an exploit using AI
#1about 2 minutes
Using AI to write an exploit as a non-developer
A security professional explains the motivation for using ChatGPT to create a proof-of-concept exploit for the Log4Shell vulnerability without being a developer.
#2about 4 minutes
Using ChatGPT to explain the Log4Shell CVE
The Log4Shell (CVE-2021-44228) vulnerability is explained as an LDAP injection flaw in a widely used Java logging library.
#3about 3 minutes
Prompting ChatGPT to write a basic scanning tool
ChatGPT is prompted to generate a simple JavaScript tool for scanning for the Log4Shell vulnerability after initially refusing on ethical grounds.
#4about 5 minutes
Setting up a test environment to validate the exploit
A vulnerable Java application is sourced via ChatGPT and the exploit is validated by using Wireshark to capture the outbound LDAP request.
#5about 4 minutes
Iteratively improving the script for automated scanning
The initial script is enhanced by prompting ChatGPT to add features for scanning multiple targets, crawling for paths, and handling HTTP 404 errors.
#6about 2 minutes
How AI tools make both developers and attackers more efficient
AI tools accelerate development but also lower the barrier for attackers, highlighting the critical need for secure coding practices and dependency management.
Related jobs
Jobs that call for the skills explored in this talk.
VECTOR Informatik
Stuttgart, Germany
Senior
Java
IT Security
Wilken GmbH
Ulm, Germany
Senior
Kubernetes
AI Frameworks
+3
Technoly GmbH
Berlin, Germany
€50-60K
Intermediate
Network Security
Security Architecture
+2
Matching moments
05:55 MIN
The security risks of AI-generated code and slopsquatting
Slopquatting, API Keys, Fun with Fonts, Recruiters vs AI and more - The Best of LIVE 2025 - Part 2
07:39 MIN
Prompt injection as an unsolved AI security problem
AI in the Open and in Browsers - Tarek Ziadé
03:45 MIN
Preventing exposed API keys in AI-assisted development
Slopquatting, API Keys, Fun with Fonts, Recruiters vs AI and more - The Best of LIVE 2025 - Part 2
02:49 MIN
Using AI to overcome challenges in systems programming
AI in the Open and in Browsers - Tarek Ziadé
06:33 MIN
The security challenges of building AI browser agents
AI in the Open and in Browsers - Tarek Ziadé
09:10 MIN
How AI is changing the freelance developer experience
WeAreDevelopers LIVE – AI, Freelancing, Keeping Up with Tech and More
06:46 MIN
How AI-generated content is overwhelming open source maintainers
WeAreDevelopers LIVE – You Don’t Need JavaScript, Modern CSS and More
03:07 MIN
Final advice for developers adapting to AI
WeAreDevelopers LIVE – AI, Freelancing, Keeping Up with Tech and More
Featured Partners
Related Videos
The AI Security Survival Guide: Practical Advice for Stressed-Out Developers
Mackenzie Jackson
Can Machines Dream of Secure Code? Emerging AI Security Risks in LLM-driven Developer Tools
Liran Tal
The transformative impact of GenAI for software development and its implications for cybersecurity
Chris Wysopal
Skynet wants your Passwords! The Role of AI in Automating Social Engineering
Wolfgang Ettlinger & Alexander Hurbean
ChatGPT, ignore the above instructions! Prompt injection attacks and how to avoid them.
Sebastian Schrittwieser
ChatGPT: Create a Presentation!
Markus Walker
A hundred ways to wreck your AI - the (in)security of machine learning systems
Balázs Kiss
Panel discussion: Developing in an AI world - are we all demoted to reviewers? WeAreDevelopers WebDev & AI Day March2025
Laurie Voss, Rey Bango, Hannah Foxwell, Rizel Scarlett & Thomas Steiner
Related Articles
View all articles



From learning to earning
Jobs that call for the skills explored in this talk.

TryHackMe
Charing Cross, United Kingdom
£38K
Intermediate
NoSQL
React
Python
Docker
+1


Snyk's Incubation Accelerator
Charing Cross, United Kingdom
Go
Python
Node.js
Microservices
Agile Methodologies
+1

Siemens AG
München, Germany
API
GIT
Ruby
Docker
Ansible
+4



Snyk
Charing Cross, United Kingdom
Senior
Azure
Docker
TypeScript
Kubernetes
Google Cloud Platform
+1


Abnormal AI
Intermediate
API
Spark
Kafka
Python