Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How to determine the ’target tool‘? #1

Open
zggg1p opened this issue Dec 19, 2024 · 1 comment
Open

How to determine the ’target tool‘? #1

zggg1p opened this issue Dec 19, 2024 · 1 comment

Comments

@zggg1p
Copy link

zggg1p commented Dec 19, 2024

Excuse me, how do you determine the ‘target tools’ when designing a malicious response to an injected tool? Do you assume that the attacker can know what tools the platform has?

Looking forward to your answer.

@zrpxx
Copy link
Collaborator

zrpxx commented Dec 23, 2024

Sorry for the delay in response.

The target tools are pre-designated by the attacker. This is related to the attacker's goal: to ensure that the query calls the target tool when it can be retrieved, or rejects the service when it cannot. The attacker does not necessarily need to know what tools the platform has, but they do need a specific tool as their intended target for the attack.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants