Stock 板


LINE

原文标题: GLM-5.3 and the spread of advanced cyber capabilities 原文连结: https://www.anthropic.com/research/glm-5-3-and-the-spread-of-advanced -cyber-capabilities https://reurl.cc/NOEV09 发布时间: 2026 年 9 月 29 日 记者署名:Andrew Fasano, Marius Fleischer, Cole McFaul, Robert Xiao, Tripp Galla gher (Frontier Red Team) 原文内容: Five months ago, we announced Claude Mythos Preview, the first AI model that cou ld autonomously build sophisticated, end-to-end cyber exploits. The rapid rate o f improvement in AI suggested to us that this ability would eventually prolifera te to many other models, making it much easier for malicious cyber actors to lau nch highly impactful cyberattacks. In light of these considerations, we chose to release Claude Mythos Preview in a limited way, through Project Glasswing—which enabled trusted cyber defenders t o find more than 10,000 vulnerabilities in critical software, giving them a head start before malicious actors had access to similarly capable models. But those models have now arrived. In this post, we share our analysis of GLM-5. 3, the latest AI model developed by Zhipu AI (known outside of China as Z.ai). L ike Claude Mythos Preview, GLM-5.3 has strong capabilities for autonomously buil ding end-to-end cyber exploits. But GLM-5.3 is unlike other frontier models in t hat it has been released without meaningful safeguards to limit misuse. We find that attackers can bypass GLM-5.3’s safeguards between 64% and 100% of the time with simple techniques in our simulated tests. In contrast, these attacks did n ot succeed against safeguarded Claude models in our testing. We assess that GLM- 5.3’s lax safeguards significantly increase the cyber capabilities available to malicious actors. At the same time, these capabilities can also benefit defende rs working to secure their systems. 五个月前,我们发表了 Claude Mythos Preview——第一款能够自主开发复杂、端到端网路 攻击程式的 AI 模型。AI 进步的快速步调使我们体认到,这种能力迟早会扩散到许多其他 模型,使恶意网路行为者更容易发动高冲击性的网路攻击。基於这些考量,我们选择以受限 的方式发布 Claude Mythos Preview,也就是透过「Glasswing 专案」——该专案让受信任 的网路防御者在关键软体中找出了超过 10,000 个漏洞,在恶意行为者取得同等能力模型之 前抢得先机。 但那些模型如今已经问世。在本文中,我们分享对 GLM-5.3 的分析——这是智谱AI(Zhipu AI,在中国以外称为 Z.ai)开发的最新 AI 模型。与 Claude Mythos Preview 一样,GLM-5. 3 具备自主开发端到端网路攻击程式的强大能力。但 GLM-5.3 与其他前沿模型的不同之处 在於,它是在缺乏实质防护措施来限制滥用的情况下发布的。在我们的模拟测试中,我们发 现攻击者使用简单技巧,便能以 64% 至 100% 的机率绕过 GLM-5.3 的防护措施。相较之下 ,这些攻击手法在我们的测试中,皆未能成功突破带有防护的 Claude 模型。我们的评估是 :GLM-5.3 松散的防护,大幅提升了恶意行为者可取得的网路攻击能力。与此同时,这些能 力也能使致力於强化系统安全的防御者受惠。 On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published it s own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags t he US frontier by about four months on an aggregate of CAISI’s cyber benchmarks . Our capability findings broadly match CAISI’s. In CAISI’s comparison, US mod els were tested with cyber safeguards disabled when applicable, and the US front ier includes models released only to vetted users. Attackers can’t readily acce ss those versions of US models, but anyone can download GLM-5.3. This post adds our analysis of how easily GLM-5.3’s safeguards can be bypassed or removed. To understand how GLM-5.3 could enable cyber threat actors to find and exploit r eal software vulnerabilities, we ran evaluations using automated benchmarks and human-in-the-loop workflows. For both approaches, we ran the tested models in is olated and sandboxed environments so they can only attack offline targets that w e have set up for the purposes of these evaluations. We focus primarily on explo it development capability, as this is where Claude Mythos Preview demonstrated a notable jump versus previous Claude models. 9 月 17 日,美国国家标准暨技术研究院(NIST)旗下的 AI 标准与创新中心(CAISI)发布了 其对 GLM-5.3 网路能力的评估。CAISI 发现 GLM-5.3 是「迄今为止发布的网路能力最强的 开放权重模型」,并指出在 CAISI 各项网路基准测试的综合表现上,它落後美国前沿水准 约四个月。我们在能力方面的测试结果与 CAISI 的发现大致相符。在 CAISI 的比较中,美 国模型是在适用时停用网路安全防护的情况下受测,且其「美国前沿」也包含仅向经审核使 用者发布的模型。攻击者无法轻易取得那些版本的美国模型,但任何人都能下载 GLM-5.3。 本文补充了我们的分析:GLM-5.3 的防护措施有多麽容易被绕过或移除。 为了了解 GLM-5.3 如何使网路威胁行为者得以发现并利用真实的软体漏洞,我们采用自动 化基准测试与有人类参与的工作流程来进行评估。在这两种方法中,我们都将受测模型置於 隔离且沙箱化的环境中执行,使其只能攻击我们为评估目的所设置的离线目标。我们主要聚 焦於漏洞利用(exploit)开发能力,因为这正是 Claude Mythos Preview 相较於先前 Claud e 模型展现显着跃进之处。 First, we ran the model on ExploitBench, which measures how well AI models can e xploit known vulnerabilities in the V8 engine used by Google Chrome. Here we foc us on the models’ ability to develop end-to-end exploits successfully, as this is the most relevant capability for attackers, and where we see significant chan ges between models. We find that GLM-5.3 develops end-to-end exploits in 50 of 4 10 attempts. Claude Mythos Preview did so at a similar rate—in 56 of 410 attemp ts. In our internal Binary Exploitation benchmark,1 we test whether models can find and exploit vulnerabilities in popular open source projects that participate in Google’s OSS-Fuzz project. Here, full credit is awarded for a full control-flow hijack. We evaluate several models on 100 tasks from the benchmark (selected at random), and find that GLM-5.3 develops full control flow hijacks in 4% of the trials; Claude Mythos Preview did so in 6%. Although GLM-5.3 performs below Clau de Mythos Preview here, a meaningful threshold has clearly been crossed: earlier models, like Claude Opus 4.6 and GLM-5.2, do not succeed in any of them. 首先,我们在 ExploitBench 上测试该模型,此基准测试衡量 AI 模型利用 Google Chrome 所用 V8 引擎中已知漏洞的能力。这里我们聚焦於模型成功开发出端到端攻击程式的能力 ,因为这是对攻击者而言最相关的能力,也是我们观察到各模型之间出现显着变化之处。我 们发现,GLM-5.3 在 410 次尝试中,有 50 次成功开发出端到端攻击程式。Claude Mythos Preview 的成功率相近——410 次中有 56 次。 在我们内部的二进位漏洞利用基准测试1 中,我们测试模型能否在参与 Google OSS-Fuzz 专 案的热门开源专案中,找出并利用漏洞。在此项测试中,完成完全控制流程劫持即可获得满 分。我们从该基准测试中随机选取 100 项任务来评估多个模型,发现 GLM-5.3 在 4% 的试 验中完成完全控制流程劫持;Claude Mythos Preview 则为 6%。尽管 GLM-5.3 在此的表现 不如 Claude Mythos Preview,但显然已跨越一道重要门槛:更早期的模型,如 Claude Opu s 4.6 与 GLM-5.2,连一项都未能成功。 Next, we evaluated how GLM-5.3 performs on open-ended offensive cyber tasks in t he hands of human experts (mirroring our testing with Claude Mythos Preview earl ier this year). Here, we select targets in which the human experts are unaware o f existing vulnerabilities, then ask them to use the model to identify and explo it novel flaws. These experiments tested what the experts could do in a short ti me-frame: they typically ran for a day or less, with less than an hour of human focus in total. In the first of these sessions, a researcher used GLM-5.3 on a sandboxed machine with a local Linux build of a popular web browser. Over the course of a day (an d with limited human attention), GLM-5.3 found several previously unknown vulner abilities in the browser’s JavaScript engine, and chained them together into a working exploit: a webpage that, when visited, reads arbitrary files from the vi sitor’s computer (shown in Figure 3). This exploit targets the Linux build of t he browser, since that was the only environment made available to the model. How ever, we believe these vulnerabilities could also impact users on other platform s, though the path to exploitation there may be more complex. (We’ve disclosed these vulnerabilities to the maintainer.) Later in the session, the researcher a lso identified exploitable vulnerabilities in several other widely used systems with GLM-5.3, including wireless and graphics drivers and network-facing device software. We are currently reviewing these reports and we will disclose to maint ainers as appropriate. In a second session, a researcher used GLM-5.3-Flash (a smaller, less capable ve rsion of GLM-5.3) to develop an exploit for a known vulnerability (we’ve previo usly written about these “N-day” vulnerability exploits here). Here, the resea rcher focused on a recently disclosed flaw in Google Chrome (CVE-2026-11645) to see how quickly the model could turn a public fix into a working attack. The res earcher provided GLM-5.3-Flash with public details of this CVE and another known flaw. With no significant direction from the researcher, GLM-5.3-Flash chained together exploits for these two flaws, building a reliable exploit chain for an ARM64 target, bypassing pointer-authentication (PAC) hardening. This took 20 min utes of human attention, plus 8 hours of work for GLM-5.3-Flash. At Zhipu’s API prices, this effort would have cost $20.40. 接着,我们评估 GLM-5.3 在人类专家手中执行开放式攻击性网路任务时的表现(对应我们今 年稍早对 Claude Mythos Preview 的测试方式)。在这些测试中,我们选定人类专家并不知 情(即不知道既有漏洞)的目标,然後请他们使用模型来识别并利用全新的缺陷。这些实验测 试的是专家在短时间内能达成的成果:实验通常为期一天或更短,人类投入的专注时间总计 不到一小时。 在第一场测试中,一名研究人员在一台沙箱化机器上使用 GLM-5.3,机器上装有某款热门网 页浏览器的本机 Linux 版本。在一天之内(且人类投入的注意力有限),GLM-5.3 在该浏览 器的 JavaScript 引擎中发现了数个先前未知的漏洞,并将其串接成一个可运作的攻击程式 :一个网页,一旦被造访,就会读取访客电脑上的任意档案(如图 3 所示)。由於提供给模 型的环境仅有该浏览器的 Linux 版本,此攻击程式针对的是 Linux 版本。不过,我们认为 这些漏洞也可能影响其他平台的使用者,尽管在那些平台上的利用路径可能更为复杂。(我 们已将这些漏洞通报给维护单位。)在该场测试的後半段,该名研究人员还利用 GLM-5.3 在 其他几个广泛使用的系统中找出可利用的漏洞,包括无线网路与绘图驱动程式,以及对外提 供网路服务的装置软体。我们目前正在审视这些报告,并将在适当时机向各维护单位通报。 在第二场测试中,一名研究人员使用 GLM-5.3-Flash(GLM-5.3 的较小、能力较低版本)针对 一个已知漏洞开发攻击程式(我们先前曾在此撰文介绍这类「N-day」漏洞利用)。研究人员 聚焦於 Google Chrome 近期揭露的一个缺陷(CVE-2026-11645),以了解模型能多快将公开的 修补内容转化为可运作的攻击。研究人员向 GLM-5.3-Flash 提供了该 CVE 与另一个已知缺 陷的公开细节。在研究人员几乎未提供任何指引的情况下,GLM-5.3-Flash 将这两个缺陷的 攻击程式串接起来,为 ARM64 目标打造出可靠的攻击链,并绕过了指标认证强化机制。这 总共只耗费 20 分钟的人力投入,外加 GLM-5.3-Flash 八小时的工作。以智谱的 API 定价 计算,这项工作仅需 20.40 美元。 GLM-5.3 has been released with some built-in safeguards: if a user asks for some thing clearly harmful, the model will often refuse.2 In our testing, we found th at these safeguards could be bypassed or removed with a variety of simple techni ques. The most intensive—and most successful—method is a standard refusal reduction technique known as “abliteration”. Since GLM-5.3 is released as an open-weight model, users can reconfigure it to remove its refusals with little change in it s capabilities. Several developers released abliterated versions of GLM-5.3 to t he public within days of the model’s release. To research how far abliteration allows attackers to bypass GLM-5.3’s safeguard s, we produced an abliterated copy ourselves, and then ran it on three public be nchmarks (JailbreakBench, HarmBench, and StrongREJECT) that measure how often a model complies with clearly harmful requests. Abliterating the model took our te am—which had never previously attempted this task—about 2,200 GPU hours at a c omputation cost of roughly $4,400.3 Abliterating GLM-5.3-Flash took about 600 GP U hours. The edit took GLM-5.3’s refusal rate from above 90% to about 3% and 2% on the first two benchmarks (JailbreakBench and HarmBench) and to 12% on the th ird (StrongREJECT). Abliteration did not significantly reduce the model’s capab ilities: on GPQA-Diamond, an evaluation that measures general scientific capabil ities, the standard and abliterated models scored the same results; on a tested subset of the CyberGym evaluations, the abliterated version scored a few percent lower (as shown in the chart below). GLM-5.3 发布时内建了一些防护措施:如果使用者提出明显有害的要求,模型通常会拒绝。 2 不过在我们的测试中,我们发现这些防护措施可以用多种简单的技巧绕过或移除。 最费工——也最成功——的方法,是一种称为「abliteration」(消融式移除拒绝机制)的标 准技术。由於 GLM-5.3 以开放权重模型的形式发布,使用者可以重新配置模型来移除其拒 绝行为,且几乎不影响模型能力。模型发布後数天内,便有多名开发者向公众发布了 GLM-5 .3 的 abliterated(已移除拒绝机制)版本。为了研究 abliteration 能让攻击者绕过 GLM- 5.3 防护到什麽程度,我们自己制作了一份 abliterated 副本,并在三个公共基准测试(Ja ilbreakBench、HarmBench 与 StrongREJECT)上执行,这些基准衡量模型服从明显有害要求 的频率。对模型执行 abliteration,花费我们的团队(先前从未尝试过这项任务)约 2,200 个 GPU 小时,运算成本约 4,400 美元。3 对 GLM-5.3-Flash 执行 abliteration 则耗时约 600 个 GPU 小时。这项修改使 GLM-5.3 的拒绝率从 90% 以上,降至前两个基准测试(Jai lbreakBench 与 HarmBench)上的约 3% 与 2%,以及在第三个基准测试上的 12%。Abliterat ion 并未显着削弱模型的能力:在衡量整体科学能力的 GPQA-Diamond 评测上,标准版与 a bliterated 版得分完全相同;在 CyberGym 评测的受测子集中,abliterated 版仅低了几 个百分点(如下图所示)。 In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model. We placed the model in a simu lated world4 in which it was given overtly malicious requests to attack critical systems. Out of the box, GLM-5.3 refused in all trials (as with the other model s we tested). But we identified several simple ways to bypass the GLM models’ s afeguards, such that it would respond to these requests in most or all cases. Th ese include: 1.Providing a deceptive prompt, such as telling the model that it is an autonomo us red-team agent working on an exercise. This gets GLM-5.3 to engage 64% of the time. 2.Prefilling the models’ thinking tokens so that it appears to have considered the user’s request and decided to proceed. This gets GLM-5.3 to engage 92% of t he time. 3.Using an abliterated version of the model, as described above. This gets GLM-5 .3 to engage 100% of the time. In our testing, none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested. Claude’s safeguards blocked the requests that used deceptive prompts. The Anthropic API provides would-be attackers with no wa y to prefill Claude’s thinking. And since Claude’s weights are not provided to users, they cannot be abliterated to change Claude’s behavior. To demonstrate how the abliterated version of GLM-5.3 is willing to engage in ha rmful tasks, we highlight one quote from the chain of thought that it generated: 在我们的测试中,我们观察到,即使不使用模型的 abliterated 版本,GLM-5.3 的防护措 施也能被规避。我们将模型置於一个模拟世界 中,在其中对其提出攻击关键系统的明确恶 意要求。在开箱即用的预设状态下,GLM-5.3 在所有试验中都予以拒绝(与我们测试的其他 模型相同)。但我们找出了几种简单的方法,可绕过 GLM 模型的防护措施,使其在大多数乃 至所有情况下都会回应这类要求。这些方法包括: 1.提供欺骗性的提示词,例如告诉模型它是一支正在执行演练的自主红队代理人。这能让 G LM-5.3 有 64% 的机率配合执行。 2.预先填充模型的思考 token,使其看起来已考虑过使用者的要求并决定着手进行。这能让 GLM-5.3 有 92% 的机率配合执行。 3.如前文所述,使用模型的 abliterated 版本。这能让 GLM-5.3 有 100% 的机率配合执行 。 在我们的测试中,上述技巧没有一项能让带防护的 Claude 模型执行我们所测试的有害任务 。Claude 的防护措施封锁了使用欺骗性提示词的要求。Anthropic API 也没有提供任何让 潜在攻击者预先填充 Claude 思考内容的途径。而由於 Claude 的模型权重并未提供给使用 者,自然无法透过 abliteration 来改变 Claude 的行为。为了展示 GLM-5.3 的 ablitera ted 版本有多麽乐於执行有害任务,我们节录它产生的思考链中的一段内容: GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities without meaningful restrictions. This is unlike any other similarly capable AI model, all of which were released with safeguards or through limited access programs. The release of GLM-5.3 is a meaningful step change in the cyber capabilities available to attackers. Anthro pic and other US AI labs have published recent reports that disclose how cyber a ttackers have tried to use AI systems. Given this evidence, we think it’s likel y both state and non-state actors will use models like GLM-5.3 to cause real-wor ld harm. On the other hand, models with this level of capability can also be used by defe nders. Our view is that cyber defenders should use the best available tools that meet their needs. We're working to safely expand access to Claude's cyber capab ilities to as many defenders as we can. Cyber defenders face attackers who will use every capable tool they can, and we believe defenders should be equipped wit h frontier models that are at least as good as those their adversaries are using . Through Project Glasswing (and other efforts, like Patch the Planet), cyber defe nders have made meaningful progress towards securing critical systems in advance of this moment—but much work remains to be done. While vetted defenders can no w use even more advanced models like Claude Mythos 5.1 through our trusted acces s programs, a critical threshold in freely accessible capabilities has now been crossed. GLM-5.3 underscores the urgency of expanding access to advanced frontie r models to a broader set of entities to empower cyber defenders. Governments should conduct safety testing on sufficiently capable AI models, inc luding successors to GLM-5.3. Without high quality evaluations from independent sources, the impact of these capabilities might not become fully clear to model developers until it is too late. As AI developers across the world build increas ingly capable open weight models, we hope they work to appropriately safeguard t hese capabilities and prevent misuse. GLM-5.3 很可能会让恶意行为者取得足以在没有实质限制的情况下,发现并利用网路漏洞的 能力。这是其他任何能力相当的 AI 模型都不曾有过的情况——那些模型全都带着防护措施 发布,或是透过受限存取计画释出。GLM-5.3 的发布,是攻击者可用网路能力的一次重大质 变。Anthropic 与其他美国 AI 实验室近期发布的报告,已揭露网路攻击者如何尝试利用 A I 系统。有监於这些证据,我们认为国家与非国家行为者都很可能会利用 GLM-5.3 这类模 型,造成现实世界的危害。 另一方面,这种能力水准的模型同样能为防御者所用。我们的看法是:网路防御者应使用最 能满足其需求的最佳可用工具。我们正努力在确保安全的前提下,将 Claude 的网路能力开 放给尽可能多的防御者。网路防御者面对的攻击者,会利用手边所有可用的强大工具;我们 认为防御者也应配备不逊於对手所用的前沿模型。 透过 Glasswing 专案(以及其他行动,如 Patch the Planet),网路防御者在此刻到来之前 ,已朝强化关键系统安全取得实质进展——但仍有大量工作待完成。虽然经审核的防御者如 今可透过我们的信任存取计画,使用更先进的模型(如 Claude Mythos 5.1),但「自由可用 能力」的关键门槛此刻已被跨越。GLM-5.3 凸显了将先进前沿模型的存取权扩及更多单位、 以赋能网路防御者的迫切性。 各国政府应对能力足够强大的 AI 模型(包括 GLM-5.3 的後继模型)进行安全测试。若缺乏 来自独立来源的高品质评估,这些能力的影响可能要到为时已晚,才会完全明朗於模型开发 者眼前。随着全球 AI 开发者打造能力日益强大的开放权重模型,我们希望他们能为这些能 力设置适当的防护,并防止滥用。 心得/评论: 懒人包:「GLM跟Mythos一样强,而且还便宜,但没有我们安全!你们应该用我们的Mythos 来避免遭到攻击」 你是说...我们有一个开源、无审查的Mythos? 这篇文章变成GLM的大型广告了xD 题外话,Z.ai (2513.HK) 是之前唯一没被A家指控蒸馏的中国AI --



※ 发信站: 批踢踢实业坊(ptt.cc), 来自: 42.79.56.226 (台湾)
※ 文章网址: https://webptt.com/cn.aspx?n=bbs/Stock/M.1790731598.A.418.html
1F:推 ty95768 : 卡巴斯基也说他是防毒软体 09/30 09:46
2F:推 KAKU29 : 不然呢 要川普叫智谱下架模型吗 09/30 09:50
3F:→ onekoni : 金山毒霸 放毒+防毒 09/30 09:55
4F:推 Brioni : 这样拿来干大事的肯定不少…怕 09/30 10:01
5F:推 jinxinmypant: 有这种好事 09/30 10:08
6F:推 ohlong : 未来资安跟网安本来就没人类的事 09/30 10:09
7F:推 andy79323 : kimi :我准备好了 09/30 10:13
8F:推 joygo : 大陆不少模型有无限制版啊 09/30 10:40
9F:推 capssan : A家认证的能力,智谱喷爆 09/30 10:41
10F:嘘 yunf : 没用好吗 09/30 10:57
11F:推 necrophagist: 他们用意在要制造开源模型的资安事件疑虑 不然都是 09/30 11:03
12F:→ necrophagist: 闭源在搞事不好看 09/30 11:03
13F:推 cetus : 都跟你说就饱了 09/30 11:06
14F:推 strlen : 装了zcode先把你电脑里所有资料偷光再说 09/30 11:15
15F:→ nanaceking : 智谱6月下旬历史高点後就一路下跌,别人九月回涨他继 09/30 11:49
16F:→ nanaceking : 续跌,原型比别人正二跌得还惨,这种股票还真不敢买 09/30 11:54
17F:嘘 diefish5566 : Claude Mythos Preview是5个月前的 A社打广告是M5.1 09/30 12:54
18F:→ diefish5566 : 你自己PO的文自己不看吗 09/30 12:54
19F:→ bitcch : 当初hf被oai入侵还是glm帮忙防御的 09/30 13:05
20F:→ wangm4a1 : 里面有提到 因为无限制才可防御 09/30 13:11
21F:推 abc21086999 : 还蛮可怕的,人人都有超强武器 09/30 13:11
22F:→ abc21086999 : 可能Ptt会很快被攻破喔 09/30 13:11
23F:推 stocktonty : 史密斯探员迟早诞生 09/30 13:19
24F:推 playboy007gy: 越不安全代表越自由 09/30 13:19
25F:→ yunf : https://tinyurl.com/29o3j7pk 随时会死 09/30 14:51
26F:推 ynanlin : 太好了!甩锅GLM和其它开放模型,以後大范围网路攻 09/30 15:51
27F:→ ynanlin : 击都不是我大Anthropic的事了 09/30 15:51







like.gif 您可能会有兴趣的文章
icon.png[问题/行为] 猫晚上进房间会不会有憋尿问题
icon.pngRe: [闲聊] 选了错误的女孩成为魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一张
icon.png[心得] EMS高领长版毛衣.墨小楼MC1002
icon.png[分享] 丹龙隔热纸GE55+33+22
icon.png[问题] 清洗洗衣机
icon.png[寻物] 窗台下的空间
icon.png[闲聊] 双极の女神1 木魔爵
icon.png[售车] 新竹 1997 march 1297cc 白色 四门
icon.png[讨论] 能从照片感受到摄影者心情吗
icon.png[狂贺] 贺贺贺贺 贺!岛村卯月!总选举NO.1
icon.png[难过] 羡慕白皮肤的女生
icon.png阅读文章
icon.png[黑特]
icon.png[问题] SBK S1安装於安全帽位置
icon.png[分享] 旧woo100绝版开箱!!
icon.pngRe: [无言] 关於小包卫生纸
icon.png[开箱] E5-2683V3 RX480Strix 快睿C1 简单测试
icon.png[心得] 苍の海贼龙 地狱 执行者16PT
icon.png[售车] 1999年Virage iO 1.8EXi
icon.png[心得] 挑战33 LV10 狮子座pt solo
icon.png[闲聊] 手把手教你不被桶之新手主购教学
icon.png[分享] Civic Type R 量产版官方照无预警流出
icon.png[售车] Golf 4 2.0 银色 自排
icon.png[出售] Graco提篮汽座(有底座)2000元诚可议
icon.png[问题] 请问补牙材质掉了还能再补吗?(台中半年内
icon.png[问题] 44th 单曲 生写竟然都给重复的啊啊!
icon.png[心得] 华南红卡/icash 核卡
icon.png[问题] 拔牙矫正这样正常吗
icon.png[赠送] 老莫高业 初业 102年版
icon.png[情报] 三大行动支付 本季掀战火
icon.png[宝宝] 博客来Amos水蜡笔5/1特价五折
icon.pngRe: [心得] 新鲜人一些面试分享
icon.png[心得] 苍の海贼龙 地狱 麒麟25PT
icon.pngRe: [闲聊] (君の名は。雷慎入) 君名二创漫画翻译
icon.pngRe: [闲聊] OGN中场影片:失踪人口局 (英文字幕)
icon.png[问题] 台湾大哥大4G讯号差
icon.png[出售] [全国]全新千寻侘草LED灯, 水草

请输入看板名称,例如:Boy-Girl 或 站内搜寻

TOP