Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dnet
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
Our Take on Social Engineering
(blog.silentsignal.eu)
1 points
by
dnet
8y ago
|
0 comments
32.
▲
by
dnet
8y ago
Removing leading zeroes doesn't require Python. One easy solution would be sed: $ echo -e '0001\n0010\n0002' | sed 's/^0*//' 1 10 2
33.
▲
My ACME wildcard certificate stack
(techblog.vsza.hu)
1 points
by
dnet
8y ago
|
0 comments
34.
▲
by
dnet
9y ago
That's mostly irrelevant, since that only protects the integrity and confidentiality of that TCP connection. However, you can still exploit the vulnerabilities of all the services listening on the device. Separating voting machine net
35.
▲
by
dnet
9y ago
Sure, the IPv6 address of my server (vsza.hu) is 2a01:270:2016::1, which is 2-A-0-1-colon-2-7-0-colon-2-0-1-6-double-colon-1 over the phone. Many people seem to forget that leading zeroes within 16-bit groups and one contiguous block of zer
36.
▲
by
dnet
9y ago
One example are JSON/XML/HTML responses over HTTP: you need the 8-bit ("binary") data in an ASCII format to fit into JSON/XML/HTML, while HTTP provides gzip (or DEFLATE, Brotli, etc.) compression over the whole
37.
▲
by
dnet
9y ago
> both .png and .jpg are already compressed formats, with "better than gzip" strength FWIW, PNG and gzip both use the DEFLATE algorithm, so I wouldn't call PNG's compression "better than gzip". Source: http
38.
▲
Ham radio vs. hacker communities
(techblog.vsza.hu)
3 points
by
dnet
9y ago
|
0 comments
39.
▲
by
dnet
9y ago
It depends. I wrote a blogpost about the security implications of UUIDs back in February ( https://blog.silentsignal.eu/2017/02/17/not-so-unique-snowfl... ) and it shows that not all standard libraries make sec
40.
▲
GSM signal sniffing for everyone with gr-gsm and Multi-RTL by Piotr Krysik
(youtube.com)
2 points
by
dnet
10y ago
|
0 comments
41.
▲
by
dnet
10y ago
IMHO it's because you learn your first language spoken first, written after -- and most people learn further languages after they learned writing, so they can learn to differentiate between words that sound similar/same.
42.
▲
by
dnet
10y ago
I know little about most of them, since we did penetration testing (simulating what could an attacker over the 'net do) most of the time, as few of our clients have the budgets for a proper source code review. No CMSs were used, we had
43.
▲
by
dnet
10y ago
My company does penetration testing and most of the projects involve web apps. Our clients use PHP, J2EE and .NET, and after 7 years of operation, we clearly see a trend where the number and severity of security issues are highest in PHP ap
44.
▲
by
dnet
11y ago
Actually, Solt is not Middle East, but in Central Europe. (I live ~50 km from it.) But yes, it's 2 MW, and at night, it can be heard using conventional receivers as far as Belgium.
45.
▲
Proxying nonstandard HTTPS traffic
(blog.silentsignal.eu)
8 points
by
dnet
11y ago
|
0 comments
46.
▲
Proxying nonstandard HTTPS traffic
(blog.silentsignal.eu)
2 points
by
dnet
11y ago
|
0 comments
47.
▲
by
dnet
11y ago
You can use SSLH and other similar software to multiplex HTTPS and SSH (along with a few other protocols) on the same port, so if 443/TCP is allowed, you can just use SSH.
48.
▲
by
dnet
11y ago
Done: - https://github.com/gioblu/PJON/issues/12 - https://github.com/gioblu/PJON/issues/13
49.
▲
by
dnet
11y ago
I see that it uses Wiring, but I'd be interested what the minimum requirements are for a compatible implementation. For example, would it be possible to implement it without some serious bit hacking on an ATtiny? (For example, ATtiny23
50.
▲
by
dnet
11y ago
Exrex does the same in Python and much more: - Generating all matching strings - Generating a random matching string - Counting the number of matching strings - Simplification of regular expressions https://githu
51.
▲
by
dnet
11y ago
Same Origin Policy would prevent AJAX requests, CSRF attacks thus usually use hidden forms -- window.open achieves the same, but with the opportunity to send multiple requests.
52.
▲
by
dnet
11y ago
Firefox 38.0.5 / Linux x86_64
53.
▲
by
dnet
11y ago
A friend of mine recently open sourced a similar solution. - Code: https://github.com/simonyiszk/openwebrx - Short intro: http://www.rtl-sdr.com/openwebrx-an-multi-user-rtl-sdr-recei...
54.
▲
CVE-2014-3440 – Symantec Critical System Protection Remote Code Execution
(blog.silentsignal.eu)
3 points
by
dnet
11y ago
|
0 comments
55.
▲
by
dnet
11y ago
I've seen similar projects -- if you told them how pointless spending money on such assessments is, and they still want it, then it shouldn't be your problem. Also, there's still a chance that they have some backup or private
56.
▲
Why GNU grep is fast (2010)
(lists.freebsd.org)
31 points
by
dnet
11y ago
|
5 comments
57.
▲
The story of a pentester recruitment
(blog.silentsignal.eu)
8 points
by
dnet
12y ago
|
0 comments
58.
▲
Retro Computer Puldin – the only Bulgarian 8-bit computer developed from scratch
(olimex.wordpress.com)
2 points
by
dnet
12y ago
|
0 comments
59.
▲
by
dnet
12y ago
> Write a ground-up implementation of (maybe a subset of) RFC 4880, with opinionated choices of default ciphers (a bit like NaCl). That's what PBP does: - Code: https://github.com/stef/pbp - A short (9:03) talk
60.
▲
by
dnet
12y ago
The browser doesn't gzip _requests_ by itself, only the server does so with the _response_ if the user-agent (including browsers) states that it supports such content encoding. Of course you can implement gzip in JavaScript, but if you
More ›