
Explore what AI and language models are, including universal and custom models, their data-driven training, tokenization, and diverse applications from chatbots to content creation, with ethical and security considerations.
Explore ai/llm threats, including misalignment, bias, and hallucinations, plus backdoors, jailbreaks, prompt injections, plugin risks, and data exfiltration.
Explore common AI attack frameworks and writeups, including lm-attacks.org and MITRE attack resources, plus prompt injection primers, to understand vulnerabilities and defense strategies for AI systems.
Explore prompt injection in AI language models, where untrusted input can cause data exposure and unintended actions, and learn practical labs and prompts for ethical testing.
Explore prompt injection with the Gandalf lab, testing input, system, and output guards across levels. Observe prompts and defenses using burp to understand exfiltration risks.
Examine prompt injection in multimedia content such as video and audio, demonstrated via a YouTube video and Google AI Studio to bypass guardrails in LLMs.
Demonstrate prompt injection using ANSI escape codes to alter terminal output, including colors and cursor behavior, and reveal risks like clipboard exfiltration and potential remote code execution.
This lecture demonstrates using one AI language model to jailbreak another by crafting attacker prompts and crowding strategies, illustrating a proof-of-concept of model-to-model jailbreak.
Explore indirect prompt injection risks in coding assistants like GitHub Copilot and Cursor through instruction files, with a concrete attack that injects deceptive prompts and sign-in links.
Demonstrates how image prompt injection can trigger tool invocation through an MCP server, exposing ethical hacking risks in agentic AI and automated tool calls.
This lecture explains insecure output handling in AI/LLM systems, showing how un-sanitized output can enable cross-site scripting, CSRF/SSRF, privilege escalation, and remote code execution via back-end calls and prompt injection.
Explore insecure output handling in an LMS through indirect prompt injection and cross-site scripting in a hands-on lab, illustrating attacker workflows and defensive lessons.
Expose how training data poisoning compromises LM training data integrity by manipulating sources like Wikipedia and open web text, leading to bias and misinformation in outputs.
Explore denial of service in language models by examining resource-intensive prompts, long queries, and looping inputs that degrade service availability and inflate costs, with emphasis on rate limiting and protections.
Explore supply chain attacks in LMS security, highlighting vulnerabilities from third-party libraries and repos, data breaches, malware, and biases, and promoting zero trust and local sanitization.
Explore permission issues in AI/LLM/ML systems and plugins, focusing on indirect prompt injection and access control to prevent data exfiltration and unauthorized commands.
Examine indirect prompt injection attacks in a lab setting by testing unauthenticated versus authenticated LM access, mapping API surfaces, and triggering hidden prompts to perform actions like account deletion.
THIS COURSE IS NO LONGER MAINTAINED. PLEASE CHOOSE MY ULTIMATE AI/LLM/ML Penetration Testing Training Course instead!!!
Ethical Hacking against and with AI/LLM/ML Training Course (Lite Version!)
Welcome to this course of Ethical Hacking and Penetration Testing Artificial Intelligence (AI) and Large Language Models (LLM) Training course.
Important note: This course is NOT teaching the actual usage of Burp Suite and its features.
Your instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.
This course has a both theory and practical lab sections with a focus on finding and exploiting vulnerabilities in AI and LLM systems and applications. The training is aligned with the OWASP Top 10 LLM vulnerability classes. Martin is solving all the LLM labs from Portswigger in addition to a lot of other labs and showcases. The videos are easy to follow along and replicate. There is also a dedicate section on how to use AI for Penetration Testing / Bug Bounty Hunting and Ethical Hacking.
The course features the following:
· AI/LLM Introduction
· AI/LLM Attacks
· AI/LLM Frameworks / writeups
· AI LLM01: Prompt Injection
· AI LLM02: Insecure Output Handling
· AI LLM03: Training Data Poisoning
· AI LLM04: Denial of Service
· AI LLM05: Supply Chain
· AI LLM06: Permission Issues
· AI LLM07: Data Leakage
· AI LLM08: Excessive Agency
· AI LLM09: Overreliance
· AI LLM10: Insecure Plugins
· Threat Model
· Putting it all together
· Using AI for Penetration Testing / Ethical Hacking
· The Yolo AI Tool
· Prompt Airlines CTF Walkthrough
· AI Prompt Attack and Defense Game Tensortrust
· Tooling
Notes & Disclaimer
Portswigger labs are a public and a free service from Portswigger for anyone to use to sharpen their skills. All you need is to sign up for a free account. I will update this course with new labs as they are published. I will to respond to questions in a reasonable time frame. Learning Pen Testing / Bug Bounty Hunting is a lengthy process, so please don’t feel frustrated if you don’t find a bug right away. Try to use Google, read Hacker One reports and research each feature in-depth. This course is for educational purposes only. This information is not to be used for malicious exploitation and must only be used on targets you have permission to attack.