Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ChALkeR
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
29 ms
·
1.
▲
How I obtained publish access to 13% of npm packages (including popular ones)
(github.com)
5 points
by
ChALkeR
9y ago
|
0 comments
2.
▲
by
ChALkeR
9y ago
The correct figure is 10%.
3.
▲
Stealing Travis secure variables (and Snap CI too)
(github.com)
2 points
by
ChALkeR
10y ago
|
0 comments
4.
▲
Mongoose security update – if you use Buffer schema type, update now
(github.com)
2 points
by
ChALkeR
11y ago
|
0 comments
5.
▲
by
ChALkeR
11y ago
Done: https://news.ycombinator.com/item?id=10909727
6.
▲
by
ChALkeR
11y ago
I tried hard to cover all the possible question. Please, read the post _carefully_ before asking or proposing anything.
7.
▲
Let's Fix Node.js Buffer API
(github.com)
2 points
by
ChALkeR
11y ago
|
1 comments
8.
▲
by
ChALkeR
11y ago
Note: this actually means that everyone should regenerate all their key-pairs after updating.
9.
▲
by
ChALkeR
11y ago
And no, switching Buffer(number) to be zero-filled will bring more harm now, even from the security point of view. The best course of action imo is to deprecate Buffer(number) whatsoever and replace it with two separate methods. More info h
10.
▲
by
ChALkeR
11y ago
This note does not have anything actually new, but I have seen several people who are not aware of that.
11.
▲
Node.js Buffer knows everything – your traffic, sources, keys and configs
(github.com)
5 points
by
ChALkeR
11y ago
|
5 comments
12.
▲
by
ChALkeR
11y ago
Looks like it bundles libavformat internally.
13.
▲
by
ChALkeR
11y ago
By the way, mplayer is also affected, even after installing a fixed version of ffmpeg.
14.
▲
by
ChALkeR
11y ago
It does not, that's covered in the original article.
15.
▲
by
ChALkeR
11y ago
But that code that you linked to does not verify that the file is mp4, moreover, mp4Sig call is commented out.
16.
▲
by
ChALkeR
11y ago
Tell me if I should not have double-posted it here, I will delete one of those posts then.
17.
▲
by
ChALkeR
11y ago
Re-posted as https://news.ycombinator.com/item?id=10895872
18.
▲
by
ChALkeR
11y ago
Short English description: ffmpeg vulnerability allows reading local files and sending them over network using a specially crafted video file. This affects not only file conversion (including thumbnail generation), but also any other operat
19.
▲
by
ChALkeR
11y ago
Previosly posted as https://news.ycombinator.com/item?id=10893301 , but that eneded up in [ask] due to my mistake.
20.
▲
Ffmpeg vulnerability allows the attacker to get files from your server or PC
(translate.google.com)
14 points
by
ChALkeR
11y ago
|
5 comments
21.
▲
by
ChALkeR
11y ago
https://translate.google.com/translate?sl=ru&tl=en&u=http%3A... will work better, I suppose.
22.
▲
by
ChALkeR
11y ago
Should I post this again with a link so it ends up in the news or not?
23.
▲
by
ChALkeR
11y ago
Hm. Why did this end up in [ask]? Perhaps I made a mistake when posting this =).
24.
▲
by
ChALkeR
11y ago
It's «PC» as in «server»/«PC», not as in «mac»/«PC».
25.
▲
Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
69 points
by
ChALkeR
11y ago
|
24 comments
26.
▲
by
ChALkeR
11y ago
It's listed here: https://docs.npmjs.com/misc/developers#keeping-files-out-of-...
27.
▲
by
ChALkeR
11y ago
Sigh… Yet another mention of an automatic tool. I guess that I will update the Q/A section to reflect my opinion on such automatic tools. Edit: done.
28.
▲
by
ChALkeR
11y ago
https://github.com/npm/npm/releases/tag/v2.14.1 > npm will no longer include .npmrc when packing tarballs.
29.
▲
by
ChALkeR
11y ago
You should not trust automatic tools to do that. They will inevitably be subject to both false negatives and false positives, and will most probably just give you a false sense of security but will not protect you from the actual leak. You
30.
▲
by
ChALkeR
11y ago
For spelling/grammar — yes.
More ›