Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
joren485
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
Substack Domain Takeover
(blog.nietaanraken.nl)
2 points
by
joren485
2y ago
|
0 comments
2.
▲
by
joren485
2y ago
Thank you for your feedback! I improved my post (and my carver) by including parsing the program headers as well. Also, thanks for the suggestion of super-strip. An interesting tool that I will play around with.
3.
▲
by
joren485
2y ago
Thanks! I haven't really looked at alternative carvers (but I am aware that many great options exist). I didn't know unblob yet. Thanks for the suggestion! Looking at the code, they use the same methodology as I describe in the po
4.
▲
Carving ELF Files
(blog.nietaanraken.nl)
73 points
by
joren485
2y ago
|
9 comments
5.
▲
Using PANDA to search for F.L.I.R.T. signatures during process execution
(blog.nietaanraken.nl)
2 points
by
joren485
3y ago
|
0 comments
6.
▲
Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories
(blog.nietaanraken.nl)
6 points
by
joren485
3y ago
|
2 comments
7.
▲
Hijacking GitHub Repositories by Deleting and Restoring Them
(blog.nietaanraken.nl)
2 points
by
joren485
4y ago
|
0 comments
8.
▲
by
joren485
4y ago
That is an interesting question! I did a quick search to get a rough answer. Many maintainers/contributors try to obfuscate their email address against this type of parsing, which adds a margin of error. I was able to find 249 expired
9.
▲
Hijacking AUR Packages by Searching for Expired Domains
(blog.nietaanraken.nl)
2 points
by
joren485
4y ago
|
2 comments
10.
▲
Command Injection in the GitHub Pages Build Pipeline
(blog.nietaanraken.nl)
4 points
by
joren485
4y ago
|
0 comments
11.
▲
by
joren485
5y ago
Hybrid (Argon2id) is probably the safest bet if you are unsure. The specific modes are useful dependent on the threat model you are protecting against. Argon2i protects better against timing/side-channel attacks and Argon2d protects be
12.
▲
by
joren485
5y ago
> I'm not sure if bcrypt/blowfish is still the recommended algorithm or there's newer better ones While bcrypt is already much, much better than using MD5 or SHA256, the best practice is to use Argon2. In practice, it is m
13.
▲
by
joren485
5y ago
The (centralized) crypto lending space has been slowly imploding in the past year. Most companies give a promotional rate on the first coin(s), but will pay very little interest on any large amount. A detailed analysis of the various player