logoalt Hacker News

tonyarklesyesterday at 2:05 AM1 replyview on HN

Well… only half of your premise is actually verifiable. We know that no one wrote it up, but we don’t know that no one did. What I can say… even the smaller (like 35B) “abliterated” Qwen models have impressive red-team capabilities for what they are, even without a harness. Just manually giving them a set of facts and asking “What next?” will get you reasonable next steps for trying to find vulnerabilities in webapps. You then manually keep track of the facts you learn and add appropriate detail (blog -> Wordpress -> Wordpress x.y.z with these plugins:…) and just feed it in a loop. Could pretty easily put together a minimal harness to do that.

And that’s all just “from memory” without something like RAG or web search access…


Replies

sillysaurusxyesterday at 2:41 AM

If anyone wants to run the guardrail-free Qwen models, here’s a link to the download plus a script to run it: https://news.ycombinator.com/item?id=49002475