Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
KayEss
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
181.
▲
by
KayEss
13y ago
What you're talking about is some sort of rope data structure which is pretty simple to implement on top of std::vector and std::list. The std::vector guarantees contiguous memory locations so you can't do it for that particular c
182.
▲
by
KayEss
13y ago
I did email it pretty much straight away, but I guess it didn't get through.
183.
▲
by
KayEss
13y ago
Except inasmuch as you're using a framework that allows any JSON data to also be requested as JSONP. The very first site I checked on this (which uses DjangoRestFramework) I was able to access email addresses from an attack page. This
184.
▲
by
KayEss
13y ago
I suppose this won't work for RJS, but for other similar JSONP vulnerabilities the correct approach is probably to strip out authentication from JSONP requests -- this could be done at the middleware layer or where authentication happe
185.
▲
by
KayEss
13y ago
I just managed to confirm that a similar attack is possible against sites using DjangoRestFramework. I won't publish it as the site I used to test against is currently working on patching the vulnerability out.
186.
▲
by
KayEss
13y ago
Your example makes it look like this is doable to any site that allows JSONP responses that contain sensitive data. Is this RoR specific because RoR will always allow JSON responses to be turned into JSONP, or is there something else at wor
187.
▲
by
KayEss
13y ago
It's always possible. I no longer remember exactly how it worked and why that made me think it had to be reverse engineered. This was many years ago now.
188.
▲
by
KayEss
13y ago
That's what I thought, until somebody reverse engineered the registration mechanism on my personal site which runs software I've written. I ended up having to turn registration off as I didn't have time to fix it properly.
189.
▲
by
KayEss
13y ago
>UTF-16 does not suffer from that particular problem what about surrogate pairs? You can't have only one 16 bit word for a pair and have a valid UTF-16 sequence. This problem is real easy to do if you substring a UTF-16 sequence nai
190.
▲
by
KayEss
13y ago
>Other common myths include: Unicode can only support characters up to 65,536 Not really a myth. This was UCS2 and was the situation when a load of important early adopters started with Unicode. Winodws, Java, JavaScript all got burnt by
191.
▲
by
KayEss
13y ago
Here http://valleypatriot.com/methuen-police-arrest-high-school-s... At least most of the commenters seem fairly rational.
192.
▲
by
KayEss
13y ago
I wish I had the time to support this better by actually playing some of the Linux games I've bought.
193.
▲
by
KayEss
14y ago
>But surely for anything Google sees as a redirect, the redirect target should be the canonical URL? That would only be the case for a 301 redirect.
194.
▲
by
KayEss
14y ago
I'd been thinking about these things over the last few years and was calling it "accidental duplication", analogously to the term "accidental complexity".
195.
▲
by
KayEss
14y ago
I wrote a paper published in an IEEE journal describing this mechanism. http://ieeexplore.ieee.org/xpl/articleDetails.jsp?reload=tru... http://www.kirit.com/A%20simple%20password-less%20authentica...
196.
▲
by
KayEss
14y ago
For some reason I read that as 32 bits to start with. 32 bytes is a hell of a lot of salt.
197.
▲
by
KayEss
14y ago
With this scheme random isn't quite enough though, it needs to be unique as well doesn't it?
198.
▲
by
KayEss
14y ago
I think you need to make sure that each user has a unique salt. If you happen to assign me the same salt as another user then either my or their password will unlock either account and the attacker only needs to guess the weaker of the pass
199.
▲
by
KayEss
14y ago
Most SMTP servers trying to send to you will try for many days before giving up. A typical configuration for a sender may get give a warning after the first 24 hours and then a bounce after another 48 hours, so normally you'll need to get y
200.
▲
by
KayEss
18y ago
In a strongly typed language one would normally want to reify the number in the type system whenever possible, i.e. the use of (a,b,c,d,e) rather than [a,b,c,d,e] in Haskell (that's a 5-tuple rather than a 5 element list). I think that peop
201.
▲
by
KayEss
18y ago
flammable/inflammable?
202.
▲
by
KayEss
18y ago
"Accepting the article's assumption of such stupid and/or lazy programmers, and accepting the implicit assumption that it's possible to produce useful software with such programmers, I'm guessing it's some kind of web-based business softwar
203.
▲
by
KayEss
18y ago
"checked exceptions actually help you out quite a bit, because you don't have a problem with stray exceptions taking down entire subsystems" Dunno about this. It's some time since I did any Java, but it seems to me that if you want to isola
204.
▲
by
KayEss
19y ago
You need to read the post linked to at the beginning first or it won't make any sense.