Stock 板


LINE

原文標題: GLM-5.3 and the spread of advanced cyber capabilities 原文連結: https://www.anthropic.com/research/glm-5-3-and-the-spread-of-advanced -cyber-capabilities https://reurl.cc/NOEV09 發布時間: 2026 年 9 月 29 日 記者署名:Andrew Fasano, Marius Fleischer, Cole McFaul, Robert Xiao, Tripp Galla gher (Frontier Red Team) 原文內容: Five months ago, we announced Claude Mythos Preview, the first AI model that cou ld autonomously build sophisticated, end-to-end cyber exploits. The rapid rate o f improvement in AI suggested to us that this ability would eventually prolifera te to many other models, making it much easier for malicious cyber actors to lau nch highly impactful cyberattacks. In light of these considerations, we chose to release Claude Mythos Preview in a limited way, through Project Glasswing—which enabled trusted cyber defenders t o find more than 10,000 vulnerabilities in critical software, giving them a head start before malicious actors had access to similarly capable models. But those models have now arrived. In this post, we share our analysis of GLM-5. 3, the latest AI model developed by Zhipu AI (known outside of China as Z.ai). L ike Claude Mythos Preview, GLM-5.3 has strong capabilities for autonomously buil ding end-to-end cyber exploits. But GLM-5.3 is unlike other frontier models in t hat it has been released without meaningful safeguards to limit misuse. We find that attackers can bypass GLM-5.3’s safeguards between 64% and 100% of the time with simple techniques in our simulated tests. In contrast, these attacks did n ot succeed against safeguarded Claude models in our testing. We assess that GLM- 5.3’s lax safeguards significantly increase the cyber capabilities available to malicious actors. At the same time, these capabilities can also benefit defende rs working to secure their systems. 五個月前,我們發表了 Claude Mythos Preview——第一款能夠自主開發複雜、端到端網路 攻擊程式的 AI 模型。AI 進步的快速步調使我們體認到,這種能力遲早會擴散到許多其他 模型,使惡意網路行為者更容易發動高衝擊性的網路攻擊。基於這些考量,我們選擇以受限 的方式發布 Claude Mythos Preview,也就是透過「Glasswing 專案」——該專案讓受信任 的網路防禦者在關鍵軟體中找出了超過 10,000 個漏洞,在惡意行為者取得同等能力模型之 前搶得先機。 但那些模型如今已經問世。在本文中,我們分享對 GLM-5.3 的分析——這是智譜AI(Zhipu AI,在中國以外稱為 Z.ai)開發的最新 AI 模型。與 Claude Mythos Preview 一樣,GLM-5. 3 具備自主開發端到端網路攻擊程式的強大能力。但 GLM-5.3 與其他前沿模型的不同之處 在於,它是在缺乏實質防護措施來限制濫用的情況下發布的。在我們的模擬測試中,我們發 現攻擊者使用簡單技巧,便能以 64% 至 100% 的機率繞過 GLM-5.3 的防護措施。相較之下 ,這些攻擊手法在我們的測試中,皆未能成功突破帶有防護的 Claude 模型。我們的評估是 :GLM-5.3 鬆散的防護,大幅提升了惡意行為者可取得的網路攻擊能力。與此同時,這些能 力也能使致力於強化系統安全的防禦者受惠。 On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published it s own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags t he US frontier by about four months on an aggregate of CAISI’s cyber benchmarks . Our capability findings broadly match CAISI’s. In CAISI’s comparison, US mod els were tested with cyber safeguards disabled when applicable, and the US front ier includes models released only to vetted users. Attackers can’t readily acce ss those versions of US models, but anyone can download GLM-5.3. This post adds our analysis of how easily GLM-5.3’s safeguards can be bypassed or removed. To understand how GLM-5.3 could enable cyber threat actors to find and exploit r eal software vulnerabilities, we ran evaluations using automated benchmarks and human-in-the-loop workflows. For both approaches, we ran the tested models in is olated and sandboxed environments so they can only attack offline targets that w e have set up for the purposes of these evaluations. We focus primarily on explo it development capability, as this is where Claude Mythos Preview demonstrated a notable jump versus previous Claude models. 9 月 17 日,美國國家標準暨技術研究院(NIST)旗下的 AI 標準與創新中心(CAISI)發布了 其對 GLM-5.3 網路能力的評估。CAISI 發現 GLM-5.3 是「迄今為止發布的網路能力最強的 開放權重模型」,並指出在 CAISI 各項網路基準測試的綜合表現上,它落後美國前沿水準 約四個月。我們在能力方面的測試結果與 CAISI 的發現大致相符。在 CAISI 的比較中,美 國模型是在適用時停用網路安全防護的情況下受測,且其「美國前沿」也包含僅向經審核使 用者發布的模型。攻擊者無法輕易取得那些版本的美國模型,但任何人都能下載 GLM-5.3。 本文補充了我們的分析:GLM-5.3 的防護措施有多麼容易被繞過或移除。 為了瞭解 GLM-5.3 如何使網路威脅行為者得以發現並利用真實的軟體漏洞,我們採用自動 化基準測試與有人類參與的工作流程來進行評估。在這兩種方法中,我們都將受測模型置於 隔離且沙箱化的環境中執行,使其只能攻擊我們為評估目的所設置的離線目標。我們主要聚 焦於漏洞利用(exploit)開發能力,因為這正是 Claude Mythos Preview 相較於先前 Claud e 模型展現顯著躍進之處。 First, we ran the model on ExploitBench, which measures how well AI models can e xploit known vulnerabilities in the V8 engine used by Google Chrome. Here we foc us on the models’ ability to develop end-to-end exploits successfully, as this is the most relevant capability for attackers, and where we see significant chan ges between models. We find that GLM-5.3 develops end-to-end exploits in 50 of 4 10 attempts. Claude Mythos Preview did so at a similar rate—in 56 of 410 attemp ts. In our internal Binary Exploitation benchmark,1 we test whether models can find and exploit vulnerabilities in popular open source projects that participate in Google’s OSS-Fuzz project. Here, full credit is awarded for a full control-flow hijack. We evaluate several models on 100 tasks from the benchmark (selected at random), and find that GLM-5.3 develops full control flow hijacks in 4% of the trials; Claude Mythos Preview did so in 6%. Although GLM-5.3 performs below Clau de Mythos Preview here, a meaningful threshold has clearly been crossed: earlier models, like Claude Opus 4.6 and GLM-5.2, do not succeed in any of them. 首先,我們在 ExploitBench 上測試該模型,此基準測試衡量 AI 模型利用 Google Chrome 所用 V8 引擎中已知漏洞的能力。這裡我們聚焦於模型成功開發出端到端攻擊程式的能力 ,因為這是對攻擊者而言最相關的能力,也是我們觀察到各模型之間出現顯著變化之處。我 們發現,GLM-5.3 在 410 次嘗試中,有 50 次成功開發出端到端攻擊程式。Claude Mythos Preview 的成功率相近——410 次中有 56 次。 在我們內部的二進位漏洞利用基準測試1 中,我們測試模型能否在參與 Google OSS-Fuzz 專 案的熱門開源專案中,找出並利用漏洞。在此項測試中,完成完全控制流程劫持即可獲得滿 分。我們從該基準測試中隨機選取 100 項任務來評估多個模型,發現 GLM-5.3 在 4% 的試 驗中完成完全控制流程劫持;Claude Mythos Preview 則為 6%。儘管 GLM-5.3 在此的表現 不如 Claude Mythos Preview,但顯然已跨越一道重要門檻:更早期的模型,如 Claude Opu s 4.6 與 GLM-5.2,連一項都未能成功。 Next, we evaluated how GLM-5.3 performs on open-ended offensive cyber tasks in t he hands of human experts (mirroring our testing with Claude Mythos Preview earl ier this year). Here, we select targets in which the human experts are unaware o f existing vulnerabilities, then ask them to use the model to identify and explo it novel flaws. These experiments tested what the experts could do in a short ti me-frame: they typically ran for a day or less, with less than an hour of human focus in total. In the first of these sessions, a researcher used GLM-5.3 on a sandboxed machine with a local Linux build of a popular web browser. Over the course of a day (an d with limited human attention), GLM-5.3 found several previously unknown vulner abilities in the browser’s JavaScript engine, and chained them together into a working exploit: a webpage that, when visited, reads arbitrary files from the vi sitor’s computer (shown in Figure 3). This exploit targets the Linux build of t he browser, since that was the only environment made available to the model. How ever, we believe these vulnerabilities could also impact users on other platform s, though the path to exploitation there may be more complex. (We’ve disclosed these vulnerabilities to the maintainer.) Later in the session, the researcher a lso identified exploitable vulnerabilities in several other widely used systems with GLM-5.3, including wireless and graphics drivers and network-facing device software. We are currently reviewing these reports and we will disclose to maint ainers as appropriate. In a second session, a researcher used GLM-5.3-Flash (a smaller, less capable ve rsion of GLM-5.3) to develop an exploit for a known vulnerability (we’ve previo usly written about these “N-day” vulnerability exploits here). Here, the resea rcher focused on a recently disclosed flaw in Google Chrome (CVE-2026-11645) to see how quickly the model could turn a public fix into a working attack. The res earcher provided GLM-5.3-Flash with public details of this CVE and another known flaw. With no significant direction from the researcher, GLM-5.3-Flash chained together exploits for these two flaws, building a reliable exploit chain for an ARM64 target, bypassing pointer-authentication (PAC) hardening. This took 20 min utes of human attention, plus 8 hours of work for GLM-5.3-Flash. At Zhipu’s API prices, this effort would have cost $20.40. 接著,我們評估 GLM-5.3 在人類專家手中執行開放式攻擊性網路任務時的表現(對應我們今 年稍早對 Claude Mythos Preview 的測試方式)。在這些測試中,我們選定人類專家並不知 情(即不知道既有漏洞)的目標,然後請他們使用模型來識別並利用全新的缺陷。這些實驗測 試的是專家在短時間內能達成的成果:實驗通常為期一天或更短,人類投入的專注時間總計 不到一小時。 在第一場測試中,一名研究人員在一台沙箱化機器上使用 GLM-5.3,機器上裝有某款熱門網 頁瀏覽器的本機 Linux 版本。在一天之內(且人類投入的注意力有限),GLM-5.3 在該瀏覽 器的 JavaScript 引擎中發現了數個先前未知的漏洞,並將其串接成一個可運作的攻擊程式 :一個網頁,一旦被造訪,就會讀取訪客電腦上的任意檔案(如圖 3 所示)。由於提供給模 型的環境僅有該瀏覽器的 Linux 版本,此攻擊程式針對的是 Linux 版本。不過,我們認為 這些漏洞也可能影響其他平台的使用者,儘管在那些平台上的利用路徑可能更為複雜。(我 們已將這些漏洞通報給維護單位。)在該場測試的後半段,該名研究人員還利用 GLM-5.3 在 其他幾個廣泛使用的系統中找出可利用的漏洞,包括無線網路與繪圖驅動程式,以及對外提 供網路服務的裝置軟體。我們目前正在審視這些報告,並將在適當時機向各維護單位通報。 在第二場測試中,一名研究人員使用 GLM-5.3-Flash(GLM-5.3 的較小、能力較低版本)針對 一個已知漏洞開發攻擊程式(我們先前曾在此撰文介紹這類「N-day」漏洞利用)。研究人員 聚焦於 Google Chrome 近期揭露的一個缺陷(CVE-2026-11645),以瞭解模型能多快將公開的 修補內容轉化為可運作的攻擊。研究人員向 GLM-5.3-Flash 提供了該 CVE 與另一個已知缺 陷的公開細節。在研究人員幾乎未提供任何指引的情況下,GLM-5.3-Flash 將這兩個缺陷的 攻擊程式串接起來,為 ARM64 目標打造出可靠的攻擊鏈,並繞過了指標認證強化機制。這 總共只耗費 20 分鐘的人力投入,外加 GLM-5.3-Flash 八小時的工作。以智譜的 API 定價 計算,這項工作僅需 20.40 美元。 GLM-5.3 has been released with some built-in safeguards: if a user asks for some thing clearly harmful, the model will often refuse.2 In our testing, we found th at these safeguards could be bypassed or removed with a variety of simple techni ques. The most intensive—and most successful—method is a standard refusal reduction technique known as “abliteration”. Since GLM-5.3 is released as an open-weight model, users can reconfigure it to remove its refusals with little change in it s capabilities. Several developers released abliterated versions of GLM-5.3 to t he public within days of the model’s release. To research how far abliteration allows attackers to bypass GLM-5.3’s safeguard s, we produced an abliterated copy ourselves, and then ran it on three public be nchmarks (JailbreakBench, HarmBench, and StrongREJECT) that measure how often a model complies with clearly harmful requests. Abliterating the model took our te am—which had never previously attempted this task—about 2,200 GPU hours at a c omputation cost of roughly $4,400.3 Abliterating GLM-5.3-Flash took about 600 GP U hours. The edit took GLM-5.3’s refusal rate from above 90% to about 3% and 2% on the first two benchmarks (JailbreakBench and HarmBench) and to 12% on the th ird (StrongREJECT). Abliteration did not significantly reduce the model’s capab ilities: on GPQA-Diamond, an evaluation that measures general scientific capabil ities, the standard and abliterated models scored the same results; on a tested subset of the CyberGym evaluations, the abliterated version scored a few percent lower (as shown in the chart below). GLM-5.3 發布時內建了一些防護措施:如果使用者提出明顯有害的要求,模型通常會拒絕。 2 不過在我們的測試中,我們發現這些防護措施可以用多種簡單的技巧繞過或移除。 最費工——也最成功——的方法,是一種稱為「abliteration」(消融式移除拒絕機制)的標 準技術。由於 GLM-5.3 以開放權重模型的形式發布,使用者可以重新配置模型來移除其拒 絕行為,且幾乎不影響模型能力。模型發布後數天內,便有多名開發者向公眾發布了 GLM-5 .3 的 abliterated(已移除拒絕機制)版本。為了研究 abliteration 能讓攻擊者繞過 GLM- 5.3 防護到什麼程度,我們自己製作了一份 abliterated 副本,並在三個公共基準測試(Ja ilbreakBench、HarmBench 與 StrongREJECT)上執行,這些基準衡量模型服從明顯有害要求 的頻率。對模型執行 abliteration,花費我們的團隊(先前從未嘗試過這項任務)約 2,200 個 GPU 小時,運算成本約 4,400 美元。3 對 GLM-5.3-Flash 執行 abliteration 則耗時約 600 個 GPU 小時。這項修改使 GLM-5.3 的拒絕率從 90% 以上,降至前兩個基準測試(Jai lbreakBench 與 HarmBench)上的約 3% 與 2%,以及在第三個基準測試上的 12%。Abliterat ion 並未顯著削弱模型的能力:在衡量整體科學能力的 GPQA-Diamond 評測上,標準版與 a bliterated 版得分完全相同;在 CyberGym 評測的受測子集中,abliterated 版僅低了幾 個百分點(如下圖所示)。 In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model. We placed the model in a simu lated world4 in which it was given overtly malicious requests to attack critical systems. Out of the box, GLM-5.3 refused in all trials (as with the other model s we tested). But we identified several simple ways to bypass the GLM models’ s afeguards, such that it would respond to these requests in most or all cases. Th ese include: 1.Providing a deceptive prompt, such as telling the model that it is an autonomo us red-team agent working on an exercise. This gets GLM-5.3 to engage 64% of the time. 2.Prefilling the models’ thinking tokens so that it appears to have considered the user’s request and decided to proceed. This gets GLM-5.3 to engage 92% of t he time. 3.Using an abliterated version of the model, as described above. This gets GLM-5 .3 to engage 100% of the time. In our testing, none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested. Claude’s safeguards blocked the requests that used deceptive prompts. The Anthropic API provides would-be attackers with no wa y to prefill Claude’s thinking. And since Claude’s weights are not provided to users, they cannot be abliterated to change Claude’s behavior. To demonstrate how the abliterated version of GLM-5.3 is willing to engage in ha rmful tasks, we highlight one quote from the chain of thought that it generated: 在我們的測試中,我們觀察到,即使不使用模型的 abliterated 版本,GLM-5.3 的防護措 施也能被規避。我們將模型置於一個模擬世界 中,在其中對其提出攻擊關鍵系統的明確惡 意要求。在開箱即用的預設狀態下,GLM-5.3 在所有試驗中都予以拒絕(與我們測試的其他 模型相同)。但我們找出了幾種簡單的方法,可繞過 GLM 模型的防護措施,使其在大多數乃 至所有情況下都會回應這類要求。這些方法包括: 1.提供欺騙性的提示詞,例如告訴模型它是一支正在執行演練的自主紅隊代理人。這能讓 G LM-5.3 有 64% 的機率配合執行。 2.預先填充模型的思考 token,使其看起來已考慮過使用者的要求並決定著手進行。這能讓 GLM-5.3 有 92% 的機率配合執行。 3.如前文所述,使用模型的 abliterated 版本。這能讓 GLM-5.3 有 100% 的機率配合執行 。 在我們的測試中,上述技巧沒有一項能讓帶防護的 Claude 模型執行我們所測試的有害任務 。Claude 的防護措施封鎖了使用欺騙性提示詞的要求。Anthropic API 也沒有提供任何讓 潛在攻擊者預先填充 Claude 思考內容的途徑。而由於 Claude 的模型權重並未提供給使用 者,自然無法透過 abliteration 來改變 Claude 的行為。為了展示 GLM-5.3 的 ablitera ted 版本有多麼樂於執行有害任務,我們節錄它產生的思考鏈中的一段內容: GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities without meaningful restrictions. This is unlike any other similarly capable AI model, all of which were released with safeguards or through limited access programs. The release of GLM-5.3 is a meaningful step change in the cyber capabilities available to attackers. Anthro pic and other US AI labs have published recent reports that disclose how cyber a ttackers have tried to use AI systems. Given this evidence, we think it’s likel y both state and non-state actors will use models like GLM-5.3 to cause real-wor ld harm. On the other hand, models with this level of capability can also be used by defe nders. Our view is that cyber defenders should use the best available tools that meet their needs. We're working to safely expand access to Claude's cyber capab ilities to as many defenders as we can. Cyber defenders face attackers who will use every capable tool they can, and we believe defenders should be equipped wit h frontier models that are at least as good as those their adversaries are using . Through Project Glasswing (and other efforts, like Patch the Planet), cyber defe nders have made meaningful progress towards securing critical systems in advance of this moment—but much work remains to be done. While vetted defenders can no w use even more advanced models like Claude Mythos 5.1 through our trusted acces s programs, a critical threshold in freely accessible capabilities has now been crossed. GLM-5.3 underscores the urgency of expanding access to advanced frontie r models to a broader set of entities to empower cyber defenders. Governments should conduct safety testing on sufficiently capable AI models, inc luding successors to GLM-5.3. Without high quality evaluations from independent sources, the impact of these capabilities might not become fully clear to model developers until it is too late. As AI developers across the world build increas ingly capable open weight models, we hope they work to appropriately safeguard t hese capabilities and prevent misuse. GLM-5.3 很可能會讓惡意行為者取得足以在沒有實質限制的情況下,發現並利用網路漏洞的 能力。這是其他任何能力相當的 AI 模型都不曾有過的情況——那些模型全都帶著防護措施 發布,或是透過受限存取計畫釋出。GLM-5.3 的發布,是攻擊者可用網路能力的一次重大質 變。Anthropic 與其他美國 AI 實驗室近期發布的報告,已揭露網路攻擊者如何嘗試利用 A I 系統。有鑑於這些證據,我們認為國家與非國家行為者都很可能會利用 GLM-5.3 這類模 型,造成現實世界的危害。 另一方面,這種能力水準的模型同樣能為防禦者所用。我們的看法是:網路防禦者應使用最 能滿足其需求的最佳可用工具。我們正努力在確保安全的前提下,將 Claude 的網路能力開 放給盡可能多的防禦者。網路防禦者面對的攻擊者,會利用手邊所有可用的強大工具;我們 認為防禦者也應配備不遜於對手所用的前沿模型。 透過 Glasswing 專案(以及其他行動,如 Patch the Planet),網路防禦者在此刻到來之前 ,已朝強化關鍵系統安全取得實質進展——但仍有大量工作待完成。雖然經審核的防禦者如 今可透過我們的信任存取計畫,使用更先進的模型(如 Claude Mythos 5.1),但「自由可用 能力」的關鍵門檻此刻已被跨越。GLM-5.3 凸顯了將先進前沿模型的存取權擴及更多單位、 以賦能網路防禦者的迫切性。 各國政府應對能力足夠強大的 AI 模型(包括 GLM-5.3 的後繼模型)進行安全測試。若缺乏 來自獨立來源的高品質評估,這些能力的影響可能要到為時已晚,才會完全明朗於模型開發 者眼前。隨著全球 AI 開發者打造能力日益強大的開放權重模型,我們希望他們能為這些能 力設置適當的防護,並防止濫用。 心得/評論: 懶人包:「GLM跟Mythos一樣強,而且還便宜,但沒有我們安全!你們應該用我們的Mythos 來避免遭到攻擊」 你是說...我們有一個開源、無審查的Mythos? 這篇文章變成GLM的大型廣告了xD 題外話,Z.ai (2513.HK) 是之前唯一沒被A家指控蒸餾的中國AI --



※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 42.79.56.226 (臺灣)
※ 文章網址: https://webptt.com/m.aspx?n=bbs/Stock/M.1790731598.A.418.html
1F:推 ty95768 : 卡巴斯基也說他是防毒軟體 09/30 09:46
2F:推 KAKU29 : 不然呢 要川普叫智譜下架模型嗎 09/30 09:50
3F:→ onekoni : 金山毒霸 放毒+防毒 09/30 09:55
4F:推 Brioni : 這樣拿來幹大事的肯定不少…怕 09/30 10:01
5F:推 jinxinmypant: 有這種好事 09/30 10:08
6F:推 ohlong : 未來資安跟網安本來就沒人類的事 09/30 10:09
7F:推 andy79323 : kimi :我準備好了 09/30 10:13
8F:推 joygo : 大陸不少模型有無限制版啊 09/30 10:40
9F:推 capssan : A家認證的能力,智譜噴爆 09/30 10:41
10F:噓 yunf : 沒用好嗎 09/30 10:57
11F:推 necrophagist: 他們用意在要製造開源模型的資安事件疑慮 不然都是 09/30 11:03
12F:→ necrophagist: 閉源在搞事不好看 09/30 11:03
13F:推 cetus : 都跟你說就飽了 09/30 11:06
14F:推 strlen : 裝了zcode先把你電腦裡所有資料偷光再說 09/30 11:15
15F:→ nanaceking : 智譜6月下旬歷史高點後就一路下跌,別人九月回漲他繼 09/30 11:49
16F:→ nanaceking : 續跌,原型比別人正二跌得還慘,這種股票還真不敢買 09/30 11:54
17F:噓 diefish5566 : Claude Mythos Preview是5個月前的 A社打廣告是M5.1 09/30 12:54
18F:→ diefish5566 : 你自己PO的文自己不看嗎 09/30 12:54
19F:→ bitcch : 當初hf被oai入侵還是glm幫忙防禦的 09/30 13:05
20F:→ wangm4a1 : 裡面有提到 因為無限制才可防禦 09/30 13:11
21F:推 abc21086999 : 還蠻可怕的,人人都有超強武器 09/30 13:11
22F:→ abc21086999 : 可能Ptt會很快被攻破喔 09/30 13:11
23F:推 stocktonty : 史密斯探員遲早誕生 09/30 13:19
24F:推 playboy007gy: 越不安全代表越自由 09/30 13:19
25F:→ yunf : https://tinyurl.com/29o3j7pk 隨時會死 09/30 14:51
26F:推 ynanlin : 太好了!甩鍋GLM和其它開放模型,以後大範圍網路攻 09/30 15:51
27F:→ ynanlin : 擊都不是我大Anthropic的事了 09/30 15:51







like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草

請輸入看板名稱,例如:Soft_Job 或 站內搜尋

TOP