Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
TheJH_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
[TLS protocol stuff] True Keyless Content Distribution Network
(true-keyless.thejh.net)
1 points
by
TheJH_
3y ago
|
0 comments
2.
▲
by
TheJH_
3y ago
Re b): Yeah but, like, colloquially "root" means "a process in the init user namespace with all UIDs set to 0 and a full capability mask". Re a): If you are root in that sense (and haven't been blanket-denied the ab
3.
▲
by
TheJH_
3y ago
seccomp does not use the eBPF userspace interface or any of the associated permission checks. seccomp (and also the classic socket filter interface) take cBPF (classic BPF), with no privilege checks; they use completely separate verificatio
4.
▲
by
TheJH_
12y ago
I think that on linux, you ideally don't want /dev/urandom, you want a recent kernel and getrandom(buf, len, 0). From the manpage: If the GRND_RANDOM bit is not set, then the /dev/urandom pool will be used. Unlike
5.
▲
by
TheJH_
12y ago
Aaaactually, if you read the code, you'd see that he XORs the bytes from rand() with bytes from /dev/random. This project is horrible, but that's not one of the completely wrong parts.
6.
▲
by
TheJH_
13y ago
You can embed \x1b (escape) into a webpage. When you copy-and-paste that, it has the same effect as hitting ESC in the editor. So, I'd just have to make you copy "<evil command>#\x1b:wq\n" to also catch the case that yo
7.
▲
by
TheJH_
13y ago
True, and that might also give you access to more traffic than just a random open wifi because people expect a wifi there and look for it.
8.
▲
Want to use my wifi?
(thejh.net)
94 points
by
TheJH_
13y ago
|
56 comments
9.
▲
Unicode Underliner
(thejh.net)
2 points
by
TheJH_
13y ago
|
0 comments
10.
▲
by
TheJH_
13y ago
I initially thought it'd work, but actually, this protection can be circumvented. See the updated version of http://thejh.net/misc/website-terminal-copy-paste .
11.
▲
by
TheJH_
13y ago
Right... for a real attack, you'd have to hide the evil commands near the end of the normal-looking one (the string you see there is truncated). I thought about doing that, but it'd give you a few seconds to react in this example because yo
12.
▲
by
TheJH_
13y ago
Definitely, I didn't even know that command :D - but I had to `apt-get install sl` on my machine first. Maybe just do a telnet to a nonstandard port on my server and then send special characters to do the animation? That could work...
13.
▲
by
TheJH_
13y ago
Maybe... unless you figure out a trick to manipulate the OCR results with invisible, nearly-white gray areas in the image or so.
14.
▲
by
TheJH_
13y ago
You might want to mark the newlines in that command... without those, the attack would be pretty boring.
15.
▲
by
TheJH_
13y ago
I feared someone would do that. :D Well, it'd be easy to work around this if you have JS enabled... without it, it would probably not be so easy to trick you into copying multiple lines.
16.
▲
by
TheJH_
13y ago
That sounds like a really good approach.
17.
▲
by
TheJH_
13y ago
Yes, I got the idea from all the sites that do it using Javascript, but I wanted to post the example to ##security, and half of the people there probably has the browser set to "block JS by default" :D
18.
▲
by
TheJH_
13y ago
Well, if I had really wanted to build a serious attack instead of a harmless PoC, I'd have downloaded a second stage via `curl <url> | sh`, and that script would, for example, set aliases in your shell for `su` and `sudo` that call
19.
▲
by
TheJH_
13y ago
If the shell had a protection against text pasted together with an ending newline (and would just strip that newline), it would help, I think.