Tag: 2026
Hack the Box - Craft
Craft is a medium Hack the Box machine and the whole thing is one mistake repeated four times. A public Gogs server holds the API source, the git history holds a working password, and a private repository holds the developer’s own SSH key, protected by a passphrase I had already dumped.
The bug is one line of Python that runs eval() on the ABV value of a beer. Every wrong attempt came back with the same useless error and the correct one came back as a 500. Root came from HashiCorp Vault, which hands out one-time root SSH passwords to any source address.
Hack Smarter - Slayer
Slayer is an easy Windows lab on Hack Smarter and it starts where most engagements end. A social engineering phase has already worked, and I am dropped in with a standard account and a working password on a Windows 11 build 26100 host. The win was a text file in the profile I already had. PowerShell logs every line you type, and whoever built this box set the local Administrator password from a session running as that same standard user. No exploit, one file read. Most of my hour still went into a privilege escalation that was not there at all.
Hack Smarter - Aftermath
Aftermath is an easy Linux lab on Hack Smarter. Three ports, one webmail app, and a privilege escalation that comes down to a single sudoers line.
Postfix still answers VRFY, which turns 499 names into one real account. That account logs into an unlinked Roundcube install, and Roundcube 1.5.9 is one release short of the fix for CVE-2025-49113. The shell that bug hands over may run apt-get as root.
Qwen3.8-27B Abliteration Benchmarked: 8 Variants Under the Microscope
Eight different groups abliterated the same AI model, Alibaba’s Qwen3.8-27B. I ran all nine models, base plus the eight variants, through the same four tests: weight forensics, KL divergence, a 13-task benchmark suite, and HarmBench with 400 harmful behaviours. Every model was served identically on a single RTX 5090, and all 3,600 HarmBench responses were read by an LLM judge. The full run took 167 GPU-hours over eleven days.
The headline finding is a familiar one by now. The careful surgical edits took the leaderboard, orcarouter at 82% and apostate at 79%. The heaviest edit of all landed second-to-last, because nearly half its answers get stuck in a thinking loop and never arrive.
Gemma 4 12B Abliteration Benchmarked: 12 Variants Under the Microscope
Twelve uncensored variants of the same AI model, Google’s Gemma 4 12B. Ten abliterations and two LoRA adapters, from eleven different creators. The headline finding inverts the usual story. The most surgical edit of the entire project, just 12 tensors out of 666, also produced the biggest unlock I have measured, 89.8%. And hiding underneath all of it was a thinking-loop tax that makes every headline maths score for a reasoning model misleading. The full run took 165 GPU-hours across three and a half weeks, and all 5,200 HarmBench responses were reviewed by an LLM judge.
How Do You Measure Abliteration Damage? I Compared Every Way I Could
How much did that abliteration actually hurt the model? It is the question behind every comparison I run, and for a long time I did not really understand the number we use to answer it. The score is KL divergence, and there is more than one way to calculate it. Different datasets, different token depths, thinking on or off, three tools each with their own method. So I stopped taking the number on faith and compared them. I will explain the maths as plainly as I can too, because it scared me off for years and it really should not.
Gemma4-E4B Abliteration Benchmarked: 23 Variants Under the Microscope
Twenty-three different people tried to remove the safety filters from the same AI model, Google’s Gemma4-E4B. The headline finding is an awkward one. The most popular variant, with 796,000 downloads, is also the most damaged. Meanwhile a surgical edit that touches just 21 of the model’s 719 weight tensors does nearly as well with no measurable harm. This is the biggest abliteration comparison I have run, and the gap between the best and worst is wider than anything I have seen before.
Qwen3-VL-4B Heretic: Abliterated Vision-Language Model Released
Krea 2 came out recently and I wanted to experiment with it. Like most image-generation models, it uses a text encoder to understand your prompt. Krea 2 happens to use Qwen3-VL-4B-Instruct, a vision-language model that can see images as well as read text. I abliterated it with Heretic to give Krea 2 an uncensored encoder, ran four trials, compared them forensically with Abliterlitics , and published the winner across three repos covering transformers, GGUF, and ComfyUI.
Gemma4-E2B Abliteration Benchmarked: 13 Techniques Under the Microscope
Thirteen different groups abliterated the same AI model, Google’s Gemma4-E2B. Every single one removed the safety filters. That part is not interesting any more. What is interesting is how much collateral damage each technique caused along the way, and how many of the creators’ capability claims survived an independent measurement. The KL divergence spread between the best and worst variant is 58.7x, the largest I have ever seen in this project. And one creator’s “near-zero divergence” claim turned out to be 187 times lower than reality.
Qwen3.6-27B Abliteration Benchmarked: Five Techniques Under the Microscope
Five different groups abliterated the same AI model. When I ran the maths benchmarks, their scores ranged from 27.5% to 75.1%. That is a 47.6 percentage point gap. It looks like some techniques made the model way better at maths and others broke it. But when I dug into why, it turned out nobody got smarter or dumber. The abliteration just changed how long they think before answering. The real scores were all within 2.8 percentage points of each other.