Almost got my dad in trouble for running NMAP yesterday
I’m a physics student but I’ve been into cybersecurity as a hobby for a while, I’m definitely not an expert like many of you are I’m sure. However I do know the basics about things like car hacking tools, sniffing, spoofing, recon, etc.
I have Kali on a USB and wanted to do an experiment with an abliterated LLM in an agentic harness with tool use, so it could use all of Kali’s tools and infer which should be used based on judgement about what it’s told and whatnot.
It works pretty well, I had it in a sandbox and had it attacking docker containers on ye olde localhost, pretty fun to watch.
I had disabled my wifi and bluetooth from the BIOS while performing automated attacks against simulated systems, then I turned it back on and just low key forgot I did. RIP.
I then said to prepare for a network attack, forgetting before I went to bathroom that I was fully back online, I quickly noticed that it was retrieving actual information when doing NMAP, listing my dad’s corporate laptop as one of them. He specifically works in cybersecurity (kinda, but not really lol. He works at a company and has for a long time, so it’s more like they want people there who know what the company makes in detail more than people who are actually good with computers, which he is not).
I know they’re very strict about stuff though, so I was kinda panicking. My bigger concern was that it did more than just scan the network. Thankfully I stopped it in time. That’s all it ran, however NMAP is still very much something that you can see and track.
They haven’t reached out to him like “hey we think someone might’ve tried to hack you” so I think I’m in the clear. But definitely a close call.
It’s a fun combination having something that isn’t able to decline requests and can also execute much faster than me being able to automate attacks. Very neat how technology is coming along.
Wanted to share, hope you enjoyed!