AI Infrastructure Attack

AI/ML 基础设施安全测试。当目标涉及 Jupyter Notebook/JupyterHub/JupyterLab、MLflow、Ray Dashboard、Kubeflow、Gradio/Streamlit 应用、vLLM/TGI/Ollama 推理服务、或任何机器学习平台时使用。当发现端口 8888(Jupyter)/5000(MLflow)/8265(Ray)/8080(Kubeflow)/7860(Gradio)/8501(Streamlit)/11434(Ollama) 时使用。AI 基础设施是云安全比赛和实战中的新兴高价值目标——很多 AI 平台默认无认证或弱认证,直接提供代码执行能力。发现任何 AI/ML 相关服务、模型训练/推理平台、notebook 环境时都应使用此 skill

wgpsec e49f269 2 files · 15.8 KB Updated

File contents

wgpsec/aboutsecurity/tree/main/skills/exploit/advanced/ai-infrastructure-attack commit e49f269695

Frequently asked questions

npx skillmds@latest add wgpsec/ai-infrastructure-attack